technology 5 min read

North Korea’s AI Double Agent Just Walked Into a Japanese Interview

A Japanese firm caught what appears to be a deepfake candidate in a job interview — misnaming the company, lagging on replies, refusing to break character. Experts say it matches a North Korean infiltration playbook now targeting employment systems worldwide.

  • North Korea
  • Cyber Security
  • AI Deepfake
  • Recruitment
  • Social Engineering

A Candidate Who Wouldn’t Stop Talking

The interview started normally enough. A applicant on the right side of the video call began reciting their motivation for joining KOWRO, a Tokyo-based AI entertainment company. On the left, the interviewer — CEO Yuji Harada — rested his chin on his hand and frowned.

Something was wrong almost immediately.

First, the candidate kept pronouncing the company’s name as “COLO” instead of KOWRO. Harada, whose company builds AI tools for entertainment, recognized the error pattern instantly: it was the kind of phonetic stumble you get when a language model misreads a proper noun as a familiar string. The candidate never corrected it. They just kept talking.

“I led large-scale web service design and development,” the candidate said, listing TypeScript, React, and Node.js. Harada interrupted. The candidate didn’t stop. He tried again. Same result — a flat, uninterrupted monologue that barely registered his questions.

There was a visible lag between Harada’s prompts and the candidate’s responses, a delay his team understood well given their work in AI. And when Harada finally asked directly whether the person was using AI, the candidate answered with stiff, unnatural Japanese: “No, I am not using AI. ‘Yourself’ am speaking directly.”

Harada hung up.

“Using AI to deceive people is not okay,” he said afterward. “I’ve lost time too.”

What This Looks Like When You Know the Pattern

IT journalist Hiroyuki Mikami says cases of AI-facilitated impersonation in online interviews have surfaced worldwide over the past two to three years. The KOWRO incident fits a specific mold — one that points to North Korea.

Mikami’s assessment: North Korean operatives have been using generative AI to mask their identities while applying for IT development jobs at companies around the world. The fake candidate presents a realistic video avatar, passes initial screening, and once hired, performs actual software development work. The earnings flow back to North Korea. In some cases, the operatives are also positioned to steal corporate intelligence.

This is not a speculative theory. The Japanese Foreign Ministry has issued public warnings about the tactic on its website, treating it as an established threat vector. The ministry’s involvement gives the attribution institutional weight — this is no longer just a tech story. It is a national security one.

Why Recruitment Is the New Frontier

Previous North Korean cyber operations focused on financial theft: cryptocurrency exchange hacks, ransomware, direct fraud. The shift toward employment-based infiltration is significant because it trades short-term extraction for long-term access.

A stolen wallet can be drained in hours. An insider at a company can sit there for months or years — writing code, understanding systems, building trust, gaining credentials. The payout is slower but far more durable. And as generative AI makes it cheaper and easier to sustain a convincing video persona, the barrier to entry for this kind of operation drops dramatically.

Japan is not alone. Remote work acceleration after the pandemic normalized video-first hiring across the globe. Companies in Europe, North America, and Southeast Asia are running the same screening pipelines. The KOWRO interview is one data point in a much wider pattern.

Who Wins and Who Loses

The short-term winner is anyone running cheap, AI-generated labor at scale. North Korean operatives using this method cost employers a fraction of local salaries and require no visa sponsorship. If the disguise holds, they extract both labor value and information with minimal risk to the sponsoring state.

The loser is the employer who wastes hours in a fake interview, and the legitimate job seeker who gets crowded out of a process someone has already rigged. But the deeper loss is institutional: every company that falls for this erodes trust in remote hiring mechanisms that billions of workers now depend on.

What Happens Next

The likely trajectory is escalation, not retreat. AI video synthesis is improving exponentially. Current flaws — lip-sync drift, response lag, odd pronoun choices — will narrow. Harada’s red flags were obvious to someone who works with AI daily. Average hiring managers will not catch them as quickly.

Companies need to adapt their screening processes. Video interview verification should include real-time interactive tasks — not just Q&A, but live coding exercises, spontaneous problem-solving, and behavioral probes that resist scripted responses. Some firms are already experimenting with multi-layer identity verification, including live photo checks and biometric consistency audits.

The Japanese government’s Foreign Ministry warning is a signal that this is being tracked at the policy level. Expect similar advisories from other governments. The question is whether recruitment teams will treat it as relevant to their daily work.

The Bigger Picture

The KOWRO interview is funny in a disturbing way. A robot applying for a job at a robotics company, unable to say the company’s name correctly, won’t let you cut it off. It’s almost cartoonish.

But the cartoon is getting more realistic. What happened at KOWRO is an early warning shot — a probe of Japan’s hiring infrastructure using the same tools that will underpin the next generation of state-sponsored economic warfare. The technology is not the hard part. North Korea has been building AI capabilities for years. The hard part is that no one is watching the recruitment pipeline with the same intensity they watch the financial one.

Until they do, the next “candidate” may not make the same mistakes.