In May 2025, multiple news outlets reported on an alarming new tactic: North Korean operatives successfully posed as remote developers at U.S. tech companies, using AI-generated avatars, deep fake interview techniques, and stolen credentials to infiltrate corporate systems and siphon data back to the regime. These bad actors exploited weak identity verification and remote onboarding processes –gaps many organizations still overlook.[1][2]
Real-time credential validation and associating the credential with the right Identity has become a challenge for many organizations with untrusted users. Online transactions rely on various stored credentials but sometimes lack the biometric validation at the time of an access verification event, opening the door to helpdesk spoofing, employment fraud, and more.
This is not a hypothetical scenario. It’s happening now. And it underscores just how vulnerable our identity infrastructure remains in a remote-first, cloud-connected world.
Microsoft Entra Verified ID provides a standards-based, decentralized identity platform that allows trusted organizations to issue, verify, and manage Verifiable Credentials (VCs) – cryptographically signed, tamper-evident, and privacy-respecting digital identity proofs.
With Face Check, organizations can require a live selfie match against the image embedded in a VC, creating a critical real-time safeguard against impersonation, deep fakes, and synthetic identities.
Granting consultant or third-party contractors access to sensitive systems, like source code or financial records, requires more than just an NDA and good intentions.
With Microsoft Entra Verified ID:
This delivers granular, just-in-time access control, supports Zero Trust security models, and eliminates manual access reviews bottlenecks.
Account lockouts are costly, averaging $50 per support call. Yet most don’t require human assistance.
With Microsoft Entra Verified ID:
Result: Lower costs, faster resolution, and happier end-users.
Universities manage tens of thousands of identity records - students, applicants, and alumni, resulting in operational complexity.
With Microsoft Entra Verified ID:
Students and alumni appreciate the speed and simplicity, while universities benefit from lower IT overhead, reduction in fraud, and improved regulatory compliance.
The North Korean scam exposed in Wired was a wake-up call: static identity checks, PDFs, and webcam interviews are no match for modern deception technology.
With Verifiable Credentials and Face Check:
Together, these tools help organizations reduce fraud, cut onboarding risk, automate access decisions, and ensure compliance in an increasingly hostile threat landscape.
Even with Microsoft Entra Verified ID, there’s still a challenge: How do you issue a VC to someone you’ve never seen in person?
Remote onboarding has replaced in-office document checks, creating an opening for bad actors
That’s why MajorKey developed IDProof+ – a rapidly deployable identity verification solution that integrates Microsoft Entra Verified ID, Face Check and authID’s Proof technology to establish high-assurance identity verification, transforming your identity systems into a strategic line of defense.
How does IDProof+ work?
This enables continuous, high-assurance identity validation – without meeting the individual in person.
Whether you're securing privileged access, enabling self-service recovery, or modernizing large-scale identity management, MajorKey’s IDProof+, Microsoft Entra Verified ID, and authID provide a proven defense against fraud and identity-based threats.
Strong identity assurance isn’t just a security measure — it’s the foundation for confident collaboration in a digital, remote-first world. With continuous, verifiable identity checks, you can be certain you know who’s on the other side of every interaction.
Trust is no longer static. It must be verifiable. Start building true digital trust today. Contact MajorKey to see IDProof+ in action – and give your organization the confidence to move faster, work smarter, and stay secure.
[1]Tech companies have a big remote worker problem: North Korean operatives - POLITICO
Principal Architect
Based out of the New York Metro/Northeast Region, Frank has 25+ years in the IT industry. Frank provides strategic architecture and consulting to organizations looking to improve security and achieve Zero Trust in their environments. His extensive experience in identity and access management, governance, compliance, and risk management allow him to understand a client’s business needs and how to properly implement the right technology to solve specific identity challenges.