OpenAI Disrupts AI-Assisted Deceptive Employment Scheme
OpenAI has banned dozens of accounts used to facilitate a deceptive employment scheme where actors used generative AI to fraudulently obtain positions at Western companies. This activity aligns with tactics, techniques, and procedures (TTPs) previously attributed by Microsoft and Google to IT worker schemes potentially connected to North Korea.
AI-Driven Deception Across the Recruitment Lifecycle
Actors used OpenAI models to generate mutually supporting deceptive content across every stage of the hiring process. The scheme operated through four primary vectors:
1. Fabrication of Candidate Identities
Operators generated personal documentation for fictitious job applicants, including resumés, online job profiles, and cover letters. These documents were frequently tailored to specific job listings to increase the likelihood of appearing as highly qualified candidates.
2. Creation of Support Personas
Beyond the primary applicants, the actors created "support" personas. These personas were used to provide fraudulent reference checks and refer the fictitious applicants for employment opportunities.
3. Recruitment of Unknowing Accomplices
The actors crafted social media posts to recruit real individuals to support the scheme. These recruits were sought for specific purposes, such as receiving and hosting corporate laptops at their homes or lending their identities to help applicants pass background checks.
4. Interview and Employment Support
AI models were used during interviews to generate plausible responses to technical and behavioral questions. Once employed, the actors used the models to perform job-related tasks—including writing code, troubleshooting, and communicating with coworkers—and to devise cover stories to explain suspicious behaviors, such as avoiding video calls or accessing systems from unauthorized countries.
Operational Infrastructure and Tactics
To mask their origins and maintain the appearance of being based in the United States, the actors employed several technical tools:
- Network Masking: Virtual private networks (VPNs) were used to hide actual locations.
- Remote Access: Tools such as AnyDesk were utilized for system access.
- VOIP: Voice over IP phones were used to maintain a U.S.-based appearance.
OpenAI identified that some of the generated content was posted to LinkedIn, though the company noted limited visibility into how all content was distributed.
Impact and Response
OpenAI stated that its policies strictly prohibit the use of its tools for fraud or scams. In response to this discovery, OpenAI banned the identified accounts and shared intelligence regarding the fraudulent networks with industry peers and relevant authorities to improve collective detection and prevention of such threats.