Skip to Content
logologo
AI Incident Database
Open TwitterOpen RSS FeedOpen FacebookOpen LinkedInOpen GitHub
Open Menu
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse
Entities

IRS

Incidents Harmed By

Incident 111837 Report
Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

2021-01-01

North Korean operatives have reportedly used AI-generated identities to secure remote jobs or impersonate employers in order to infiltrate companies. These tactics allegedly support sanctions evasion through wage theft, credential exfiltration, and malware deployment. Workers reportedly use fake resumes, VPNs, and face-altering tools; some deploy malware like OtterCookie after embedding, while others lure targets via spoofed job interviews. AI systems are reportedly used to generate fake resumes, alter profile photos, and assist in real-time responses during video interviews.

More

Incident 9911 Report
Alleged AI-Generated IRS Scam Websites Used to Defraud U.S. Taxpayers

2025-03-14

Scammers have allegedly been using AI-generated imposter websites and phishing emails to impersonate the IRS. They have reportedly been tricking taxpayers into providing personal and financial information. There has been a reported surge in tax-related AI scams leading up to Tax Day 2025, with fraudulent domains mimicking IRS services, along with fake websites, emails, and text messages. The IRS has warned taxpayers to verify official sites and avoid unsolicited links.

More

Related Entities
Other entities that are related to the same incident. For example, if the developer of an incident is this entity but the deployer is another entity, they are marked as related entities.
 

Entity

scammers

Incidents involved as Deployer
  • Incident 991
    1 Report

    Alleged AI-Generated IRS Scam Websites Used to Defraud U.S. Taxpayers

More
Entity

Fraudsters

Incidents involved as Deployer
  • Incident 991
    1 Report

    Alleged AI-Generated IRS Scam Websites Used to Defraud U.S. Taxpayers

More
Entity

Phishers

Incidents involved as Deployer
  • Incident 991
    1 Report

    Alleged AI-Generated IRS Scam Websites Used to Defraud U.S. Taxpayers

More
Entity

Scammers impersonating the IRS

Incidents involved as Deployer
  • Incident 991
    1 Report

    Alleged AI-Generated IRS Scam Websites Used to Defraud U.S. Taxpayers

More
Entity

Cyber criminals

Incidents involved as Deployer
  • Incident 991
    1 Report

    Alleged AI-Generated IRS Scam Websites Used to Defraud U.S. Taxpayers

More
Entity

Unknown generative AI developers

Incidents involved as Developer
  • Incident 991
    1 Report

    Alleged AI-Generated IRS Scam Websites Used to Defraud U.S. Taxpayers

More
Entity

Black-box AI developers

Incidents involved as Developer
  • Incident 991
    1 Report

    Alleged AI-Generated IRS Scam Websites Used to Defraud U.S. Taxpayers

More
Entity

Generative AI fraud tools

Incidents involved as Developer
  • Incident 991
    1 Report

    Alleged AI-Generated IRS Scam Websites Used to Defraud U.S. Taxpayers

More
Entity

Taxpayers in the United States

Incidents Harmed By
  • Incident 991
    1 Report

    Alleged AI-Generated IRS Scam Websites Used to Defraud U.S. Taxpayers

More
Entity

General public of the United States

Incidents Harmed By
  • Incident 991
    1 Report

    Alleged AI-Generated IRS Scam Websites Used to Defraud U.S. Taxpayers

More
Entity

U.S. citizens

Incidents Harmed By
  • Incident 991
    1 Report

    Alleged AI-Generated IRS Scam Websites Used to Defraud U.S. Taxpayers

More
Entity

Identity theft victims

Incidents Harmed By
  • Incident 991
    1 Report

    Alleged AI-Generated IRS Scam Websites Used to Defraud U.S. Taxpayers

More
Entity

AI-powered phishing kits

Incidents implicated systems
  • Incident 991
    1 Report

    Alleged AI-Generated IRS Scam Websites Used to Defraud U.S. Taxpayers

More
Entity

SMS phishing networks

Incidents implicated systems
  • Incident 991
    1 Report

    Alleged AI-Generated IRS Scam Websites Used to Defraud U.S. Taxpayers

More
Entity

Reconnaissance General Bureau

Incidents involved as Deployer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Lazarus Group

Incidents involved as Deployer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Government of North Korea

Incidents involved as Deployer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Department 53

Incidents involved as Deployer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

North Korean threat actors

Incidents involved as Deployer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Famous Chollima

Incidents involved as Deployer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

PurpleBravo

Incidents involved as Deployer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

WaterPlum

Incidents involved as Deployer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Minh Phuong Ngoc Vong

Incidents involved as Deployer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Sim Hyon-Sop

Incidents involved as Deployer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Kim Sang Man

Incidents involved as Deployer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Christina Chapman

Incidents involved as Deployer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Wagemole

Incidents involved as Deployer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

UNC5267

Incidents involved as Deployer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Void Dokkaebi

Incidents involved as Deployer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Contagious Interview

Incidents involved as Deployer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Gwisin Gang

Incidents involved as Deployer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Matthew Isaac Knoot

Incidents involved as Deployer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Yang Di

Incidents involved as Deployer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Jong Song Hwa

Incidents involved as Deployer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Kim Ryu Song

Incidents involved as Deployer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Ri Kyong Sik

Incidents involved as Deployer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Rim Un Chol

Incidents involved as Deployer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Kim Mu Rim

Incidents involved as Deployer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Cho Chung Pom

Incidents involved as Deployer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Hyon Chol Song

Incidents involved as Deployer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Son Un Chol

Incidents involved as Deployer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Sok Kwang Hyok

Incidents involved as Deployer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Choe Jong Yong

Incidents involved as Deployer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Ko Chung Sok

Incidents involved as Deployer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Kim Ye Won

Incidents involved as Deployer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Jong Kyong Chol

Incidents involved as Deployer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Jang Chol Myong

Incidents involved as Deployer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Unknown large language model developers

Incidents involved as Developer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Unknown deepfake technology developers

Incidents involved as Developer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

OpenAI

Incidents involved as Developer
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Western companies

Incidents Harmed By
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Companies in the United States

Incidents Harmed By
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Employers

Incidents Harmed By
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Cryptocurrency platforms

Incidents Harmed By
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Developers

Incidents Harmed By
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Interviewees

Incidents Harmed By
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

macOS users

Incidents Harmed By
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Recruitment teams

Incidents Harmed By
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Hiring managers

Incidents Harmed By
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Human resources staff

Incidents Harmed By
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Web3

Incidents Harmed By
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Blockchain projects

Incidents Harmed By
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Internal Revenue Service

Incidents Harmed By
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Social Security Administration

Incidents Harmed By
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

SSA

Incidents Harmed By
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Andrew M.

Incidents Harmed By
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Oleksandr Didenko

Incidents Harmed By
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Jiho Han

Incidents Harmed By
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Haoran Xu

Incidents Harmed By
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Chunji Jin

Incidents Harmed By
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Video interview platforms

Incidents implicated systems
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Unknown large language models

Incidents implicated systems
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Unknown deepfake technology

Incidents implicated systems
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Freelance platforms

Incidents implicated systems
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Document verification systems

Incidents implicated systems
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Digital identity verification services

Incidents implicated systems
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

ChatGPT

Incidents implicated systems
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Laptop farms

Incidents implicated systems
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

BYOD (Bring Your Own Device)

Incidents implicated systems
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Flashpoint-detected info-stealing malware

Incidents implicated systems
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Zoom

Incidents implicated systems
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

WebSocket-based C2

Incidents implicated systems
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

ARP packet signaling

Incidents implicated systems
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Raspberry Pi Zero

Incidents implicated systems
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

OtterCookie

Incidents implicated systems
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

OtterCookie v3

Incidents implicated systems
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

OtterCookie v4

Incidents implicated systems
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

BeaverTail

Incidents implicated systems
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

InvisibleFerret

Incidents implicated systems
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

AgencyHill99

Incidents implicated systems
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

GitHub

Incidents implicated systems
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Astrill VPN

Incidents implicated systems
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

FTP exfiltration

Incidents implicated systems
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Remote admin tools

Incidents implicated systems
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Job boards

Incidents implicated systems
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Upwork

Incidents implicated systems
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

remote3

Incidents implicated systems
  • Incident 1118
    37 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More

Research

  • Defining an “AI Incident”
  • Defining an “AI Incident Response”
  • Database Roadmap
  • Related Work
  • Download Complete Database

Project and Community

  • About
  • Contact and Follow
  • Apps and Summaries
  • Editor’s Guide

Incidents

  • All Incidents in List Form
  • Flagged Incidents
  • Submission Queue
  • Classifications View
  • Taxonomies

2024 - AI Incident Database

  • Terms of use
  • Privacy Policy
  • Open twitterOpen githubOpen rssOpen facebookOpen linkedin
  • a9df9cf