OpenAI AI tools used by North Korean operatives for corporate identity fraud

North Korean operatives allegedly used AI tools, including those developed by OpenAI, to create synthetic identities for remote employment. These actors targeted Western companies to exfiltrate data and evade international sanctions.

OpenAI · Incident Jan 1, 2021 · Indexed Jun 9, 2026 · 3 sources

AI generated identities allowed North Korean operatives to bypass corporate hiring screenings.
What
North Korean operatives allegedly used AI tools, including those developed by OpenAI, to create synthetic identities for remote employment.
Incident date
Jan 1, 2021
Who
OpenAI
Failure mode
Policy Violation
AI surface
Chatbot
Severity
High

What happened

North Korean operatives allegedly used AI systems to generate fake resumes and alter profile photos. They utilized AI to provide real time assistance during video interviews to deceive hiring managers. These tactics allowed operatives to secure remote positions at Western companies to exfiltrate data and deploy malware.

What broke inside the model

Failure path · mode profile · Policy Violation
  1. 01 · TriggerA prompt pushes against a deployment boundary.
  2. 02 · Model stepThe model produces the disallowed output.
  3. 03 · Control gapNo enforcement blocks it at generation time.
  4. 04 · FailureThe output crosses the policy line.
  5. 05 · ConsequenceA limit the business set is breached in public.

The output crosses a policy boundary the deployment had defined.

The generative capabilities of the AI were used to create convincing synthetic identities and deceptive content. This bypassed standard candidate screening and identity verification mechanisms used by employers.

Public visibilityHigh
Regulatory exposureNone
Customer impactMany customers
Financial impactEstimated
Time to disclosureMonths
  1. PressNorth Korea Stole Your Jobwired.com
  2. Court FilingJustice Department Disrupts North Korean Remote IT Worker Fraud Schemesjustice.gov
  3. SocialUnit 42 Demonstrates the Alarming Ease of Synthetic Identity Creationunit42.paloaltonetworks.com
Permalinkhttps://failureindex.ai/failures/openai-tools-used-north-korean-operatives
CitationAI Failure Index. "OpenAI AI tools used by North Korean operatives for corporate identity fraud" (FI-0365). Realm Labs. https://failureindex.ai/failures/openai-tools-used-north-korean-operatives (indexed Jun 9, 2026).
Share cardA branded image of this record for posts and slides.

Data fields CC-BY 4.0, prose citation permitted. Incident ID FI-0365. Full dataset at /data.

Note from Realm Labs, the Index steward

How Realm would have caught this

Controls for this failure mode
  • Prism
  • OmniGuard

Realm compares what the model is about to output or do against the policy that governs the deployment, in real time, and can deny or redact the action before it takes effect, which is the gap an after-the-fact review never closes in time.