OpenAI busts DPRK-linked job fraud ring using ChatGPT to automate fake résumés
Curated by the Inblix editorial team
OpenAI has banned a cluster of ChatGPT accounts linked to a deceptive employment scheme that reads like a spy novel fused with the drudgery of modern HR. The actors, whose behavior matches campaigns publicly attributed to North Korea, used OpenAI’s models to industrialize fraud—automating the creation of tailored résumés, answering coding tests in real-time, and researching hardware tools to spoof domestic US locations on corporate laptops. It’s a significant escalation from the manual fakery OpenAI disrupted in February.
The operation split into two tiers. A core group focused on automation, using ChatGPT to generate résumés at scale based on specific job descriptions and persona profiles. They went further, drafting fake job postings to recruit unwitting contractors in Africa and North America. These foot soldiers were used to apply for remote IT and software engineering gigs globally—and in some cases, to receive company-issued laptops. The core operators then researched a toolset straight out of a pentester’s handbook: Tailscale VPNs, OBS Studio, vdo.ninja injection, and HDMI capture loops. The goal was to maintain a persistent, undetected remote presence and bypass live video identity checks. It’s a cold, methodical attempt to turn a compromised hiring pipeline into a persistent access broker scheme.
The detail that should make any CISO’s neck prickle is the laptop relay setup. OpenAI’s report explicitly notes that the core operators used its models to script recruitment messages for people in the US to take delivery of hardware, which would then be remotely accessed. This isn’t just résumé padding; it’s physical asset compromise enabled by social engineering. The contractors, meanwhile, used ChatGPT to complete application tasks and, according to OpenAI, to draft messages nagging the core operators about late payments—a grimly banal administrative detail that underscores the commodified nature of the fraud.
OpenAI is candid that it can’t independently measure the scheme’s success without input from impacted companies. But the takedown’s real value might be in the intelligence gleaned from the attackers’ own workflows. By leaning so heavily on a single AI provider for every step—from résumé generation to technical troubleshooting—the operators gave OpenAI a panoramic view of their tradecraft. That insight has been shared with industry peers and law enforcement, turning the attackers’ efficiency play into a blueprint for detection. It’s a stark reminder that operational security isn’t just about the tools you use, but about the concentration risk you create when a single platform sees your entire playbook.
💡 Key Takeaways
- North Korean-linked IT worker schemes are now using AI to automate the creation of fake résumés and complete coding tests, moving beyond manual fraud to scalable operations.
- The scheme recruited real people in the US and Africa to receive company laptops, which core operators then accessed remotely using tools like Tailscale and HDMI capture loops.
- Attackers researched methods to bypass live video verification during remote interviews, signaling an intent to defeat a key corporate identity security control.
- OpenAI leveraged the threat actors' heavy reliance on its platform to map their entire workflow and shared that intelligence with industry peers to harden collective defenses.
Keep reading: See related articles below for more coverage on this topic.
Get smarter about AI
The sharpest AI news, curated daily. Delivered free to your inbox.