The main interview is with Simon Wijckmans, founder of client-side security company c/side, recently relocated to San Francisco and named to Forbes 30 under 30. He recounts how North Korean operatives applied to his job postings with fake identities, using AI-assisted CVs, reverse-engineered coding tests, green-screen computer vision to fake ID cards, VPNs, laptop farms in the US and even deepfaked faces/voices — a story picked up by Wired. He traces individuals to Dandong, China near the North Korean border, explains the financial motives (salaries, IP theft, credentials, direct bank/API access), and shares hiring and cybersecurity tips for SMEs. He also reflects on internet fragility (BGP built on trust), the CrowdStrike incident, Belgium's limited tech ecosystem versus San Francisco's AI-driven revival, and the middenjury exam system that enabled his early career.
Simon Wijckmans speaks with the specificity of someone who has actually chased the fraud he describes down to its source, and that specificity is the throughline of everything he says. His central subject is a North Korean fake-identity operation that infiltrated remote tech hiring, and he does not treat it as an abstract threat but as a documented, staged criminal process. He describes candidates who score "90%+" on take-home coding tests because the tests get reverse-engineered, then fall apart on live technical questions, most memorably one who was asked about the Border Gateway Protocol and, after quietly feeding the question to an AI, "begon te praten over border checks, als in effectief fysieke border checks" 12. The technical sophistication of the deception impressed him as much as it alarmed him: operatives used "green screen formaat" plastic cards with live computer vision to project false identity documents during video verification calls, defeating a paid third-party verification service outright 12. He is equally clear-eyed about the economics behind it, noting that each fake worker is running the con at scale, holding "tegelijkertijd 10 van die jobs" because "het is eigenlijk gewoon een kwestie van volume voor hun" 12 — individuals were traced back to Dandong on the North Korean border.
Wijckmans lays out the operation as an escalating pipeline rather than a single scam: first drawing a US salary, then siphoning intellectual property, then harvesting personal data and credentials for dark web sale, and finally reaching payment APIs and bank accounts directly — a progression that has left crypto firms drained entirely 12. He frames this less as a story about North Korea specifically and more as a case study in how trust-based systems get exploited once someone finds the seam. That diagnosis extends to the internet's architecture itself: "Het internet is gebouwd op vertrouwen in de essentie," he says, pointing to protocols like BGP that accept whatever neighboring systems claim, patched with hotfixes but never fundamentally redesigned 12. He applies the same logic to security tooling in general, arguing that defenders need genuinely deeper access than attackers to have any advantage at all — otherwise it's a coin-flip — which is why he defends CrowdStrike's privileged OS access even after its damaging outage 2. His analogy for the field is characteristically blunt: "Zo is dat ook bijvoorbeeld met fietsendiefstalen. Degene met het dikste slot die gaat blijven staan. Die met het dunste slot die verdwijnt. Zo is dat ook in cybersecurity" 2.
What's notable is how Wijckmans moves from technical diagnosis to organizational prescription without softening into vague advice. He is specific and almost procedural: never hire remote if you don't have to, always call previous employers because that's "het hardste te faken," meet remote hires in person when possible, and above all, "Neem nooit iemand aan voor een job dat je zelf niet begrijpt" 2. He also identifies a structural cause that companies rarely admit: pressuring managers with hiring-speed KPIs directly increases the odds of onboarding fraudulent candidates, because artificial urgency benefits no one but the scammers. Underneath all of this sits a kind of operating instinct he states plainly: "Als iets niet helemaal koser aanvoelt, dan is het waarschijnlijk ook wel even niet zo" 1 — trust your read on a situation, because the fraud is built precisely to survive surface-level scrutiny.
His account of why this went public at all reveals something about his own motivation. He says the scheme had been known among recruiters "sinds COVID" but that knowledge never reached the startup founders and SMEs actually exposed to it, which is why he pushed the story to Wired 12. This is consistent with the mission he states for his own company: not comprehensive security utopia, but incremental, honest progress — "Ik wil het internet veiliger maken... Als we daar een procentje van kunnen krijgen, dan ben ik al heel tevreden" 1. He extends this candor to newer threats he flags without pretending to have solved them, describing a DDoS technique that hijacks ordinary visitors' browsers through JavaScript embedded in ads, exploiting the fact that real browsers on residential IPs leave no fingerprint to filter — and admitting flatly that "er is momenteel geen oplossing" for it.
Beyond security specifics, Wijckmans is unsentimental about geography and institutions. He describes Belgium as fundamentally "een implementatie en verkoop land" in tech, with a small economy that pushes ambitious founders toward the standard path through London and ultimately San Francisco, where he says investor experience, recycled tech wealth, and talent density simply cannot be matched in Europe 12. Yet he's not dismissive of where he came from: he credits Flanders' "middenjury" exam system directly with keeping him in education on his own terms, saying without it "had ik volledig een dropout geweest" 1. That combination, gratitude for a specific enabling structure at home paired with clear-eyed acknowledgment that ambition eventually requires leaving, captures how he thinks generally: precise about mechanisms, unromantic about outcomes, and always willing to name the exact process rather than gesture at the general problem.
Flemish founder Simon Wijckmans (c/side, Forbes 30 under 30) explains how North Korean fake-identity operatives tried to infiltrate his San Francisco security startup via remote job applications, plus hosts discuss Manus AI, Starlink on planes and Russian disinformation.
Flemish founder Simon Wijckmans (C/Side, Forbes 30 under 30) explains how he exposed North Korean fake-identity job applicants infiltrating remote tech jobs — including green-screen ID fraud and laptop farms — plus hosts' segments on Manus AI, Fixer AI, Starlink on United, and Russian disinformation.