Police and the NCSC: check who your remote IT contractor really is
On 1 October the National Cyber Security Centre and New Zealand Police published a joint advisory on North Korean IT workers trying to get hired by New Zealand organisations. The background is blunt. North Korea has sent thousands of skilled IT workers out into the world to look for work in software development, website design, graphic design and IT services, and the money they earn goes back to the regime, including to its nuclear weapon and ballistic missile programmes. The advisory says there have been instances of these workers attempting, and succeeding, in getting work in New Zealand and overseas. One of them was in the NCSC’s Cyber Threat Report 2026: a large New Zealand business hired a remote IT contractor who was later identified as North Korean, and who, once let go, claimed to hold commercially sensitive information and demanded payment.
The method is a false identity, built carefully. The advisory lists stolen or purchased identities, including doctored New Zealand driver licences and passports, fabricated CVs and references, fake business email addresses set up to pass referee checks, and deepfake or AI-assisted interview answers. The workers operate mainly from China, Laos and Russia, hiding their location behind VPNs and remote-desktop tools. New Zealanders have been drawn in without knowing it: letting their address be used to receive a company laptop, logging in and setting up remote access so the work appears to come from New Zealand, or receiving payments into their own bank account and passing them on. The workers are also known to go through recruitment agencies to look more legitimate, which is why the advisory says not to rely on an agency to do your identity checks for you.