Platforms sold hiring at scale without identity verification, and will now sell you the surveillance that purports to fix it.

Eleven governments put their names to a joint alert on Friday about North Korean IT workers funneling contract income to Kim Jong Un’s nuclear and ballistic-missile programs. South Korea, the United States, Japan, Britain, Australia, Canada, France, Germany, Italy, the Netherlands, and New Zealand coordinated the document. The alert names a real and well-documented threat: contractors operating under stolen or fabricated identities on platforms like Upwork and Fiverr, remitting salaries to agencies that fund weapons programs, with AI-assisted obfuscation methods now part of the playbook. The UN Panel of Experts has traced this revenue for years. The UN Security Council resolution requiring member states to repatriate North Korean nationals earning income abroad is not new. That eleven governments coordinated the alert suggests the scale has grown past what any one jurisdiction’s enforcement can address.

There is something darkly impressive about the operation. Pyongyang saw a gap in the global labour market — a hunger for cheap, skilled remote developers — and filled it with people who are effectively undercover intelligence officers. The workers impersonate South Koreans, Chinese, anyone whose identity they can steal or fabricate. They pass background checks. They integrate into teams. And then they exfiltrate data, steal cryptocurrency, and skim their paycheques to the regime. The threat is not hypothetical.

The repatriation clause is theater. Which country is going to round up the North Korean freelancers in its jurisdiction — the ones operating through third-party contractors on Upwork-style platforms — and send them home to a regime that will probably shoot them? No one. The trilateral coordination between the United States, South Korea, and Japan — deepened at an Ankara meeting just weeks ago — is a necessary diplomatic response. A joint alert is not a joint enforcement mechanism.

What the alert does not name is the structural vulnerability at the centre of the operation. Global remote-contracting platforms were built to connect buyers and sellers of labour at scale, which means they were built to minimise friction in hiring, not to verify that the person accepting a contract is who they claim to be. A contractor in Shenyang earning forty thousand dollars a year writing JavaScript under a stolen Canadian passport is, from the platform’s perspective, a contractor who delivered the code and got paid. The platform took its commission. The platform does not, and at current technical capacity cannot, distinguish a legitimate contractor from a nation-state operative at the scale at which it operates. The security gap is a design choice, not an accident. Verification adds friction. Friction reduces transaction volume. Transaction volume is what the platform extracts its commission from.

It is worth being precise about what the proposed remedy actually entails at platform scale. Enhanced identity verification means government-issued identification, biometric checks, document verification, liveness detection — integrated into the platform’s onboarding flow. Every contractor who wants to work through the platform will submit to deeper identity checks than currently required. The verification infrastructure — the vendors who sell it, the platforms that integrate it, the data pipelines that carry it — is a business. The joint alert is a market-creation event for that business. No one currently knows how to verify identity reliably at the scale these platforms operate. The alert’s language describes an aspiration, not a technical specification. The platforms will comply by purchasing verification products from vendors who will sell them. The vendors will sell the same products to every other platform that needs to demonstrate compliance.

South Korea, notably, is building the compute and the surveillance-industrial apparatus simultaneously. The Lee Jae Myung government’s proposal for a Korean In-Q-Tel — a venture-investment vehicle modelled on the CIA’s In-Q-Tel, designed to fund domestic security-technology startups — feeds exactly this kind of infrastructure to Korean intelligence agencies. The alert’s mandate is the demand signal that justifies the investment. The compute infrastructure the Lee government is building with firms like AMD provides the hardware layer. North Korean IT workers “employ increasingly sophisticated methods, including the integration of AI, to obfuscate their identities.” The proposed remedy is AI-powered verification: the same class of tools, deployed on the same class of data, for opposite purposes. Both sides of the obfuscation-detection arms race feed the same infrastructure. The surveillance dividend accrues to the platforms regardless of whether the verification catches a single operative.

This is the pattern the tech-policy world has seen before. A platform failure — the inability to verify identity, the inability to prevent misuse, the inability to distinguish legitimate from malicious actors — is recast as a security threat. Governments respond with mandates that expand the platform’s data collection and control. The platforms, which created the vulnerability through their architecture, profit from the mandated expansion of their surveillance capability. The security gap — the actual technical problem no one knows how to solve at scale — remains. The platforms that host the contracts will collect more data on every worker — not just the North Korean ones — because that is what identity verification at scale requires.

The platform companies will comply. The verification vendors will profit. The Korean surveillance-industrial complex will have its demand signal. The North Korean IT workers will, in all likelihood, adapt — because the obfuscation and the detection are in a permanent arms race, and the platforms’ architecture is the arena in which that race runs. What will not happen is the platforms being held accountable for the architecture that created the vulnerability in the first place. The platforms sold scale; the scale came without verification; the verification is now being mandated; and the platforms will sell that, too.

The remote army keeps coding. The legitimate contractors will submit to deeper surveillance because the platforms could not be bothered to verify identity when it would have cost them transaction volume. The cost of verifying identity at scale ought to be borne by the platforms that designed the unverified architecture, not transferred to the workers who want to participate in the platform economy. It is the engineering equivalent of the merchant who sells you the lock after selling you the door that doesn’t have one. And the bombs keep getting built.