Refolk
September 15, 2026·9 min read

41% of Enterprises Hired a Fake. The 73:1 Sourcer Gap Is Why.

DPRK operatives ran 21,000 interviews for 76 offers. Inbound funnels lose on volume. Outbound sourcing is the structural fix, and here is the math.

North Korean IT worker fraudfake candidates hiringdeepfake interview detectioncandidate fraud recruitersoutbound sourcing
41% of Enterprises Hired a Fake. The 73:1 Sourcer Gap Is Why.

GetReal Security's December 2025 benchmark, built from 668 enterprise security leaders, says 41% of enterprises have already hired and onboarded a fraudulent candidate. The inbound applicant funnel is not a funnel anymore. It is an adversarial channel, and the org charts of most talent teams were not designed for that.

The inbound funnel became an attack surface

Any channel that accepts unsolicited applications at scale can be beaten by an adversary with more volume than you have screeners, and DPRK-linked operators have vastly more volume than you have screeners.

Nisos tracked 22 DPRK operatives who submitted 166,893 job applications and secured 21,000+ interviews between April and September 2025, converting 76 offers. That is a sub-1% offer rate, and it worked because the top of the funnel was effectively infinite. Okta Threat Intelligence linked just 130 DPRK-affiliated identities to 6,500 interviews at 5,000 distinct companies from 2021 through mid-2025, and Okta called that "only a small sample." CrowdStrike's 2026 Global Threat Report clocked DPRK-linked incidents up more than 130% year over year, with FAMOUS CHOLLIMA activity doubling and AI-enabled adversary activity up 89% overall.

Amazon's CSO Steve Schmidt told WSJ his team has blocked 2,900+ suspected DPRK operatives since April 2024 and that DPRK-affiliated applications were growing roughly 27% quarter over quarter as of December 2025. Compounding attack volume, static screening budget. You do the arithmetic.

166,893
Job applications from 22 DPRK operatives in 6 months
Nisos tracked the cluster from April to September 2025. Sub-1% offer rate, but 76 offers landed.

Why deepfake detection alone will not save you

Deepfake interview detection is a real category now, and you should probably buy some. But detection is a downstream patch on an upstream problem. If the adversary can spin up new identities faster than you can flag them, you are playing whack-a-mole with a state actor whose day job is generating moles. The WSJ's August 12, 2026 investigation "Infiltrated" documented one tracked group applying to 1,000+ companies in three months using AI at "nearly every stage": cover letters, resumes, interview prep, and real-time face substitution.

What 41% actually means

41% of enterprises reporting a confirmed fraudulent hire is the floor, not the ceiling: Gartner projects 1 in 4 candidate profiles will be fake by 2028 and 81% of recruiters have already experienced some form of candidate fraud.

The gap inside the GetReal survey is the story. 41% have onboarded a fraud. Only 35% list fake candidates as a primary concern. ERE's recent piece "Nobody Wants to Own Candidate Fraud" nailed the org-chart problem: HR treats it as a security issue, security treats it as an HR issue, and the risk sits in the hallway between them. Sourcing is the function that structurally lives in that hallway, and nobody is staffing it.

MetricValueSource
US professionals titled Sourcer or Technical Sourcer1,284Refolk's index, current-title filter
US professionals titled Recruiter or Talent Acquisition93,385Refolk's index, current-title filter
Ratio of inbound recruiters to outbound sourcers~73:1Derived
Enterprises that onboarded a fraudulent candidate41%GetReal Security, Dec 2025, n=668
DPRK identities to interviews to companies, 2021 to mid-2025130 to 6,500 to 5,000Okta Threat Intelligence, Sept 2025
DPRK offer conversion, Apr to Sept 202576 of 21,000+ (<1%)Nisos
YoY change in DPRK-linked incidents+130%CrowdStrike 2026 GTR

The 73:1 sourcer gap

In Refolk's index of professional profiles, there are roughly 1,284 people in the US currently titled "Sourcer" or "Technical Sourcer" versus roughly 93,385 with "Recruiter" or "Talent Acquisition" in their current title. That 73:1 imbalance leaves almost every hiring org structurally dependent on the exact channel that is being attacked.

That number should stop you. Outbound sourcing - starting from a verifiable footprint and reaching out to a specific human - is a rounding error inside talent acquisition. The companies with mature technical-sourcing benches are a short list concentrated in the Bay Area: Pinterest, Rippling, MongoDB, Verkada, Anthropic, and Zoox. Everyone else runs on inbound, which means everyone else runs on trust in whoever fills out the form.

The recruiter picks the identity before the candidate picks the job. That single reversal is the whole defense.

Why outbound inverts the trust model

Outbound sourcing is a channel where the recruiter selects the candidate from a public footprint - GitHub history, LinkedIn work graph, conference talks, papers, open-source maintainership - and then initiates contact. Compare that to inbound, where the candidate selects themselves into your ATS and you spend the interview trying to verify who they actually are.

Two things follow from the reversal:

  1. The adversary loses the volume lever. They can generate infinite personas, but they cannot make you decide to reach out to a persona. The top of your funnel is bounded by your sourcer's shortlist, not the attacker's throughput.
  2. The verification surface expands from minutes to years. A resume is a text field. A GitHub graph with years of commits and a maintainer role on a widely used package is not a text field. Anthropic reported in August 2025 that DPRK operators showed "complete dependency" on Claude to code, debug, and communicate. They can pass a 45-minute interview. They cannot retroactively fabricate years of merged PRs into projects other real humans reviewed.

This is the exact gap Refolk closes: you describe the person you want in plain English ("senior Rust engineer with sustained open-source contributions since 2020, based in the EU, worked at a database or infra company") and get a ranked shortlist grounded in GitHub, LinkedIn, and open-web signals you can click through and verify. The identity is the input, not the output.

The attack has crossed into non-engineering roles

Huntress and Recorded Future's Insikt Group, tracking the "PurpleDelta" cluster across 1,100+ companies, have documented DPRK-linked hires moving into sales, marketing, and healthcare. The "we don't hire remote engineers" defense is retired.

An Australian healthcare firm found three "employees" who turned out to be DPRK impersonators, caught via Astrill VPN and IPRoyal Proxy telemetry patterns. The Christina Chapman laptop farm in Arizona - 90 laptops, 68 stolen US identities, 300+ companies infiltrated including Nike, which paid $75,000+ to a DPRK worker, $17M generated before her 8+ year federal sentence - was never engineering-only.

This is where outbound gets harder and more important at the same time. A senior SRE has a rich open-web footprint. A regional sales manager or an oncology nurse practitioner does not always. Outbound sourcing for non-technical roles leans on:

  • Verified employment continuity across LinkedIn, industry directories, and licensure boards
  • Named references from prior colleagues you can independently contact
  • Conference attendance, panel appearances, association memberships
  • Local presence signals: a real license number, a real hospital privileges record, a real property tax record where relevant

None of those signals are perfect. All of them are harder to fabricate than a resume PDF.

Where the demand actually is

Hiring is not slowing down while this happens, which is why the pressure to accept the inbound funnel as-is keeps winning inside talent teams that already have too much to do.

The companies building mature sourcing benches - Pinterest, Rippling, MongoDB, Verkada, Anthropic, Zoox - are treating outbound as a first-class hiring channel rather than a specialty. Those benches are concentrated in the Bay Area for a reason: it is where the highest-value engineering hires already live and where inbound funnels are the most polluted. If you are staffing your first outbound sourcer role right now, you are competing with those benches for talent that barely exists.

A practical playbook for the next 90 days

Rebalance the mix, do not tear out the funnel. Inbound is not going away. It is just no longer the sole channel you can trust for high-risk hires.

  1. Pick your high-risk roles. Remote-first, high-privilege, and IC engineering roles are the top of the DPRK target list. Rank them and mark which ones move to outbound-first.
  2. Hire or contract one technical sourcer per 10 open engineering reqs. The 73:1 ratio in Refolk's index tells you where the market currently sits. You will feel this ratio inside a month.
  3. Verify at the footprint layer, not the interview layer. Require a public work sample - commits, papers, patents, deals closed with named references - that predates the application by at least 24 months. AI-augmented personas struggle at multi-year time horizons.
  4. Instrument the inbound funnel for adversarial signals. VPN and proxy fingerprints, resume duplication clusters, and interview scheduling patterns are the Amazon-style controls that scale. Buy or build detection, but do not rely on it as the only line.
  5. Assign an owner. The ERE piece is right. Fraud with no owner is fraud that grows. Sourcing is the natural home because it already spans HR and security concerns.

Instead of asking your sourcer to spend a week rebuilding a LinkedIn Recruiter boolean every time a threat report drops, Refolk lets you describe the person in plain English (including negative constraints like "no accounts created after 2023" or "public commit history predates 2022") and returns a shortlist grounded in verifiable footprint across GitHub, LinkedIn, and the open web. A single-source shortlist is a single-source failure mode, which is the whole lesson of the last 18 months.

FAQ

Is outbound sourcing actually immune to DPRK-style fraud?

No, and anyone selling it that way is wrong. A well-funded adversary can plant a footprint over years, and there are documented cases of long-running open-source contributor accounts turning out to be sock puppets. What outbound does is raise the cost of a successful impersonation from "one AI-generated resume" to "years of coherent public artifacts across multiple platforms," which changes the funnel math in your favor. Combine outbound with proof-of-work exercises and reference checks against people you contacted independently.

How do I detect a deepfake interview if I already have a full inbound pipeline?

Live detection tools help, but the higher-leverage moves are procedural. Require candidates to perform a live task that involves moving their head, occluding their face with their hands, and typing on a physical keyboard visible in frame. Cross-check IP geolocation against claimed residence. Ask about local specifics (a nearby coffee shop, a state tax quirk, a commute) that a script cannot easily anticipate. Route any candidate you cannot geolocate consistently to a second, in-person or notarized-ID verification step before an offer.

What is the org-chart fix for "nobody owns candidate fraud"?

Put it under a named executive with a dotted line to both the CHRO and the CISO, and give that person a budget for tooling and a headcount for sourcing. The ERE reporting captures the failure mode: neither function wants the pager. The GetReal survey shows the cost of leaving it unowned at 41% onboarded. Naming an owner and moving even 20% of high-risk hiring from inbound to outbound is the single biggest lever most orgs have not yet pulled.

Why is the 73:1 sourcer-to-recruiter ratio the number to watch?

It is the mechanical explanation for why the industry keeps losing. Inbound recruiting is a 93,000-person profession in the US. Outbound sourcing is a 1,300-person specialty. When the attack surface shifts from job boards to identities, the profession that reads identities has to scale, and today it cannot. Every org that moves even one recruiter seat to a sourcer seat is bending the ratio, and the orgs that do it first will be the ones still trusting their hires in 2027.

Try it on the search you came here for

Stop building boolean strings. Just describe the person.

Type one sentence. I plan the search, read GitHub, public LinkedIn and Crunchbase records, and the open web as it is right now, and hand back a ranked list with the reason next to every name.

  1. 01Describe them

    One plain sentence. Role, city, stack, stage, whatever matters to you.

  2. 02I read the web live

    GitHub, public LinkedIn and Crunchbase records, the open web. Not a database that went stale last quarter.

  3. 03You read the shortlist

    Ranked, with the reasoning under every name. Open a profile, ask a follow-up, narrow it down.

  • No boolean, no filters, no seat to buy. One box.
  • Read at search time, so a profile updated yesterday counts today.
  • Every step visible as it runs, every name with its reason.

500 free credits on sign-up. No card, no demo call. See real searches.

Read next