North Korean IT worker fraud is a state-run scheme that employs DPRK operatives to use stolen American identities, win remote IT jobs, and route their wages to Pyongyang's weapons programs. U.S.-based facilitators host the company laptops so the logins look domestic. Operatives have infiltrated more than 100 U.S. companies, stealing source code, credentials, and even export-controlled defense data.
At a glance
North Korea places thousands of IT workers in remote jobs under stolen identities, generating $250 million to $600 million a year for its weapons work.
U.S.-based facilitators host the company laptops in their homes, so an operative in China or Russia logs in from what looks like an American address.
The scheme has escalated from wage collection to source code theft and extortion, including ITAR-controlled data taken from a U.S. defense contractor.
Background checks clear these candidates because the stolen identity belongs to a real American whose credit and employment records are fully genuine.
Deepfake injection attacks bypass the camera during interviews, so the face answering questions may not belong to the person who later takes the job.
—
Whether it's a conference or roundtable, there are three 2026 cases I keep getting asked about, and they show just how far the remote DPRK IT workers threat has spread.
In April, two New Jersey men received a combined 200 months in federal prison for running laptop farms that placed North Korean operatives at more than 100 U.S. companies, one of whom reached ITAR-controlled data at a defense contractor.
On July 28, the FBI disclosed that investigators had found a North Korean IT worker performing work for a U.S. federal agency — the first case publicly confirmed inside government.
Then, on July 31, eleven governments issued a joint alert warning employers worldwide that these workers now operate in teams and rotate who appears on camera.
What connects these cases is that nothing was breached in any of them. Each operative cleared a background check, sat through video interviews, completed onboarding, and started work with credentials the company issued them. The FBI now describes this as one of the most persistent insider threats facing American employers, and the victim list runs into the hundreds.
This guide explains how North Korean IT worker fraud works, the risks they create for U.S. employers (with real cautionary tales), and how available identity controls can catch it before a credential is ever issued.
What is North Korean remote IT worker fraud?
North Korean IT worker fraud is a state-directed scheme in which the DPRK places thousands of skilled technology workers in remote jobs around the world under fabricated or stolen identities. Wages route back to Pyongyang, where the funds support nuclear weapons and ballistic missile programs in violation of UN Security Council sanctions.
How the scheme works, from application to paycheck
DPRK IT worker schemes follow a consistent operational pattern:
A worker, or a network of workers sharing personas, applies to remote IT roles using stolen U.S. identities, AI-generated resumes, and fabricated portfolio sites built to clear automated applicant tracking systems.
References are manufactured, work history reads as plausible, and the identity documents attached to the application belong to a real American with a real credit file, so every record-based background check returns clean results.
Once an offer lands, the worker asks the employer to ship the company laptop to a U.S. address controlled by a domestic facilitator. The facilitator sets the device up at a laptop farm, installs remote desktop software or connects a hardware keyboard-video-mouse switch, and lets the overseas operative connect from North Korea or, more often, China or Russia.
Mandiant, which tracks a cluster of this activity as UNC5267, has documented the same toolkit across investigations. The operative works hours that match the U.S. business day, appearing to be a domestic employee while sitting thousands of miles away.
The role of U.S.-based laptop farms and facilitators
Domestic facilitators make the scheme work, and federal prosecutors have treated them accordingly. The FBI's July 2025 DPRK IT workers advisory catalogs what facilitators supply:
A U.S. internet connection
Remote desktop access to company laptops
Financial account setup
Job platform accounts
Reshipment of laptops overseas
Attendance at virtual interviews on the worker's behalf
Kejia Wang served as the U.S.-based manager for one such network, supervising at least five facilitators who collectively hosted hundreds of victim company laptops in their homes.
The group incorporated shell entities with names like “Hopana Tech LLC” and “Independent Lab LLC,” opened corresponding financial accounts, and used them to make overseas workers look affiliated with legitimate American businesses. Those accounts had no employees and no operations.
Where the money goes, and why that makes this a sanctions problem
Wages earned by DPRK IT workers do not stay with the workers. Funds flow to North Korean state agencies to support weapons of mass destruction and ballistic missile programs, with individual workers reportedly earning up to $300,000 annually.
That revenue stream violates UN Security Council sanctions. A company that pays a DPRK IT worker, even unknowingly, may breach U.S. OFAC regulations, UK financial sanctions, Australian sanctions law, or the domestic laws of any of the eleven countries that signed the July 2026 joint alert.
How the threat escalated from salary fraud to data extortion
The DPRK IT worker threat has moved well past wage collection. The FBI's January 2025 advisory documented operatives who had already secured employment threatening to release sensitive company data unless paid additional sums. Workers copied source code repositories to personal accounts, harvested credentials and session cookies for later use, and in some cases, published proprietary code publicly.
The Wang case shows where this leads. Between January and April 2024, an overseas co-conspirator used a laptop belonging to a California defense contractor developing AI-powered military equipment to access technical files, including data marked as ITAR-controlled. Victim companies in that case absorbed at least $3 million in legal fees, network remediation, and other damages, separate from the $5 million that went to the regime.
The scale of the DPRK IT worker threat
North Korea runs this as a staffed program with recruitment, training, and revenue targets, which is why the numbers below describe an operating budget rather than a series of incidents.
The UN Panel of Experts places annual revenue between $250 million and $600 million, with operatives in more than 40 countries. The Justice Department has charged more than 40 individuals, including the nationwide enforcement action of June 2025 that seized 29 financial accounts, 21 fraudulent websites, and an estimated 200 computers across 16 states.
CrowdStrike, which tracks the activity as FAMOUS CHOLLIMA, has reported operatives posing as insiders at more than 100 primarily U.S. technology companies. Unit 42 reached the conclusion that shapes the control section below: no single check is sufficient, and detection requires identity verification, asset management, location analysis, endpoint controls, HR training, and insider-risk monitoring working together.
SentinelOne's research team also tracked roughly 360 fake personas and more than 1,000 applications aimed at SentinelOne alone, including attempts to place operatives on the intelligence engineering team that studies this exact threat. When a single operation submits a thousand applications to one company, manual review stops being a control and becomes a bottleneck.
Known cases: what this looked like at real organizations
Court filings and voluntary disclosures give an unusually detailed account of how these placements unfolded. The cases below were caught by an endpoint alert, a shipping investigation, a federal indictment, and in one instance not by the employer at all:
KnowBe4 hired one and caught it in 25 minutes
In July 2024, security awareness company KnowBe4 disclosed publicly that it had hired a North Korean IT worker for a software engineering role. The candidate cleared a background check, passed four video interviews, and received a company MacBook.
The device started loading malware just minutes after reaching the shipping address. KnowBe4's security operations center flagged the activity at 9:55 p.m. on July 15 and contained the device by roughly 10:20 p.m., and no data left the environment.
KnowBe4 moved faster than most organizations would, and the case is instructive for what preceded the detection. The background check returned clean results because the stolen identity belonged to a real U.S. person with genuine credit and employment history, and video interviews passed because the candidate's photo had been AI-enhanced from a stock image.
Every hiring control cleared. Endpoint detection only caught it afterward, once the device was already in hand.
The Arizona laptop farm behind jobs at 309 companies
Christina Marie Chapman of Litchfield Park, Arizona ran one of the largest facilitator operations the Justice Department has charged.
From October 2020 to October 2023, she hosted company laptops in her home, annotating with notes that identified which company and which stolen identity went with each machine. She shipped 49 devices overseas over those three years, several to a Chinese city on the North Korean border. Investigators seized more than 90 laptops from her house.
The operation compromised 68 U.S. identities, defrauded 309 American businesses and two international ones, and generated more than $17 million. Affected employers included a top-five television network, a Silicon Valley technology company, an aerospace manufacturer, an American car maker, and a luxury retailer. Operatives in the same network also applied unsuccessfully to two federal agencies. Chapman was sentenced in July 2025 to 102 months in prison.
Freelance platforms and payment rails: the October 2023 domain seizures
In October 2023, the Justice Department announced court-authorized seizures of seventeen web domains used by North Korean IT workers posing as U.S.-based technology firms, along with more than $1 million in associated funds.
Operatives used the domains to solicit freelance contracts and moved proceeds through accounts on platforms including PayPal and Payoneer, frequently paired with rented Upwork and Fiverr profiles obtained by paying real users for access to their accounts. That same month, the United States and the Republic of Korea issued joint guidance on the threat.
PayPal was a payment rail in the scheme and was not accused of wrongdoing, but the action illustrates a pattern that recurs throughout these cases: the scheme runs on ordinary commercial infrastructure, which is exactly what makes the individual transactions look unremarkable.
A federal agency, 2026
At a July 28, 2026 conference hosted by the Digital Government Institute, FBI Deputy Assistant Director Todd Hemmen said investigators had identified a DPRK remote IT worker performing work for the federal government, describing the discovery as having occurred within the prior week. The agency was not named and the scope remains under investigation. Given the background investigation and identity proofing required for direct federal employment, the case most likely involves contract work performed on an agency's behalf.
There is precedent, and it is the single clearest illustration of where conventional verification breaks.
A year earlier, Minh Phuong Ngoc Vong of Bowie, Maryland was sentenced in December 2025 to 15 months in prison. Between 2021 and 2024, thirteen U.S. companies had paid him more than $970,000 for software development work performed by overseas operatives.
In March 2023 he sat for an online interview with a Virginia technology company for a role requiring U.S. citizenship. He verified his identity with a Maryland driver's license and a U.S. passport, and both were authentic. He was the verified person on the provided documents.
The company hired him and placed him on a Federal Aviation Administration contract covering a software application used across multiple agencies to handle sensitive national defense information. The FAA issued him a Personal Identity Verification card granting access to government facilities and systems.
He then installed remote access software on the company laptop and handed his credentials to a co-conspirator in Shenyang, China, who performed the job from March through July 2023.
Every identity check in that sequence worked correctly; it just had no bearing on who operated the account afterward.
$5 million, 100 companies, 80 stolen identities: the Wang sentencings
In April 2026, the Justice Department announced sentences for Kejia Wang and Zhenxing Wang, both of New Jersey, for a scheme running from approximately 2021 through October 2024. Kejia Wang received 108 months and Zhenxing Wang received 92 months, with $600,000 in forfeiture ordered and a restitution judgment of $29,236.03 against Kejia Wang. Six U.S. facilitators collectively took in nearly $700,000 for their roles.
Eight co-defendants indicted in June 2025 remain at large and wanted by the FBI. The State Department's Rewards for Justice program has named them, along with one suspected IT worker, in connection with a reward offer of up to $5 million.
Deepfake job interviews: the new front door
Gartner® predicts that by 2028, one in four candidates worldwide will be fake. Deepfake tooling has clearly become a primary access vector for North Korean IT worker fraud.
This means the hiring pipeline needs more attention, security, and protection against deepfake-driven hiring fraud attacks. Understanding the mechanics, and specifically where detection breaks, is a widening technical gap that most hiring processes aren’t braced for.
How a deepfake job interview works in practice
A deepfake job interview uses AI-generated video to substitute a synthetic or stolen face for the operative's own during a live call. Real-time face-swapping software pairs with a virtual camera application that feeds the manipulated stream directly into the conferencing platform.
From the interviewer's side, a person appears, answers questions, and behaves like any other candidate. But the face on screen belongs to someone other than the person speaking.
The FBI's July 2025 advisory confirms that North Korean operatives have used AI and face-swapping technology during video interviews, and that they reuse phone numbers and email addresses across multiple applicant personas.
Presentation attacks and injection attacks are not the same problem
Security teams routinely collapse two distinct categories of video fraud into one, and the distinction determines whether a control works:
A presentation attack shows an artifact to a real camera: a printed photo, a pre-recorded video on a second screen, a mask. Liveness detection is built to catch this by looking for depth, natural motion, and physiological signals.
An injection attack bypasses the camera entirely. The attacker intercepts the video stream at the software level and substitutes synthetic content before it reaches the application. Liveness detection fails here because it never receives the real camera feed. It analyzes the injected stream and finds it convincing, because the attacker built it to be convincing.
The trend line is steep. iProov's 2026 Threat Intelligence Report documented a 741% annual increase in injection attacks against iOS devices during 2025, with a 1,151% surge in the second half of the year alone, and identified deepfake impersonation spreading into everyday enterprise workflows, particularly video-based interactions. Native virtual camera attacks became the primary threat vector after such tools reached mainstream app stores.
Why "turn your camera on" stopped being a control
Requiring video was a meaningful check in 2022. Today the stream arrives live, the face responds in real time, and the background looks like a home office, with no camera ever pointing at the person on the call. Absent tooling that verifies the integrity of the capture itself, a video call establishes that someone is present and nothing about who.
What deepfake hiring fraud is teaching security teams
The pattern is documented rather than speculative. KnowBe4 confirmed it in 2024. SentinelOne measured it at scale in 2025. The FBI addressed it directly in its July 2025 advisory. The eleven-government joint alert of July 2026 states that North Korean IT workers integrate AI to obscure their identities, and notes that these workers operate in teams, so the individual a hiring official deals with may change depending on the time of day.
That last point deserves emphasis, because it’s a government confirmation of something most hiring processes do not account for at all: the person who interviews may never be the person who works.
Red flags for identifying a North Korean IT worker
These are grouped by stage because the evidence available to you changes as a candidate moves through hiring. The FBI, OFSI, and Mandiant have each published indicator lists that overlap heavily; the groupings below consolidate them.
No single indicator is conclusive. Value comes from patterns, particularly signals that recur across different stages of the process.
During application and screening
Resume and LinkedIn profile disagree on names, employment dates, or education, or the profile links to a differently named person with the same background.
Contact numbers are VoIP rather than carrier-issued. VoIP numbers cost nothing to create and carry no location.
The resume shows signs of AI generation: unusually uniform formatting, implausibly smooth career progression, and a portfolio domain registered recently.
Separate applicants share banking documentation, an email domain, or a shipping address. The State Department alert adds a related signal for platform operators: multiple accounts created from the same identification document.
The candidate accepts contract terms without negotiation or bids noticeably below market.
During the interview
Video shows latency, unnatural facial motion, or lip movement out of sync with audio.
The background is blurred, virtual, or otherwise obscured. The FBI advisory suggests asking the candidate to point the camera out a window and describe what they see.
The candidate declines spontaneous video calls or requires advance notice before appearing.
Asking the candidate to pass a hand across their face produces a visible glitch. This catches older presentation tooling and does not reliably detect injection attacks.
The candidate cannot answer basic questions about the city or address on their identity documents.
Capture a still during each interview. A different face at the next call is a significant signal, and the FBI documents cases where one person passed the interview and another did the job.
At onboarding and equipment shipping
The shipping address for the company device differs from the stated home address or the address on the identity documents.
The candidate asks for equipment to go to a third party, a freight forwarder, or a commercial mailbox.
Remote desktop software such as AnyDesk, TeamViewer, RustDesk, or Chrome Remote Desktop appears on the device shortly after delivery. Mandiant's investigations found the same tooling, alongside IP-based KVM devices, across laptop farm cases.
The candidate requests access beyond the role's requirements or asks about network architecture early in onboarding.
After hire, in day-to-day work
Sessions stay open for unusually long stretches, sometimes past 24 hours, or the account authenticates from multiple countries within a short window.
Work quality diverges from interview performance in either direction, with output that reads as AI-generated.
The employee is hard to reach during core hours and active at times consistent with a different time zone.
Payment requests shift toward cryptocurrency, offshore accounts, or remittance services after hire.
The employee resists unscheduled video calls or in-person meetings.
Why standard hiring controls miss this
Nothing in a standard hiring stack asks the question that matters here: is the person in this interview the person these documents describe, and will they still be the person using this account next month?
Four controls come close, but each stops short in a different way:
Background checks validate records, not the person holding them
A background check queries databases: criminal history, credit files, employment verification, SSN validation. When an operative uses a stolen identity belonging to a real U.S. person with a clean record, every query returns accurate results for that person.
The check passes because the records are genuine and they describe someone else. Background checks were built to surface disqualifying history; confirming that the applicant is the person whose history appeared is a separate problem requiring a separate control.
Document upload without liveness detection verifies a file, not a face
Many onboarding workflows ask candidates to upload a government ID. That upload confirms a document exists and that its fields are internally consistent, but says nothing about whether the person who submitted it appears on it.
Without a liveness-verified match between the document photo and a live biometric capture, a document upload is just a file transfer. The State Department alert notes that identification documents used in these schemes frequently show signs of forgery or image editing.
Video interviews without injection detection verify a stream, not a human
A video interview confirms that a video stream is arriving not that the stream originates from a physical camera pointed at a physical person. Absent tooling that establishes the integrity of the capture, a video call is not an identity verification event. iProov's threat data shows why this matters now rather than eventually: virtual camera tooling has reached mainstream app stores, and the skill required to deploy it has collapsed.
Verification stops at hire, but the operator can change afterward
Most hiring processes treat identity verification as a single event. The Vong case shows why that assumption fails: authentic documents, a genuine person, a correct verification, and then credentials handed to someone in Shenyang. The July 2026 joint alert makes the same point in general terms, noting that these workers operate in teams and rotate who interacts with the employer.
Account recovery, device replacement, and privilege escalation are all moments when the human behind a credential may have changed. Most organizations process them as routine IT tickets.
What the FBI and international advisories tell employers
Six governments have now published guidance naming this threat, and the obligations differ by where you hire rather than where you are headquartered. The advisories below overlap heavily on indicators and diverge sharply on what happens if an operative reaches your payroll.
The FBI advisory timeline: May 2024, January 2025, July 2025
The FBI has published three public service announcements on this threat. The May 2024 advisory covered U.S.-based facilitators and laptop farm mechanics. The January 2025 advisory documented the escalation to data extortion, including code repositories copied to personal accounts and credential harvesting for later compromise. The July 2025 advisory, IC3 alert I-072325-4, updated operational guidance for employers with specific interview techniques, shipping controls, payment analysis, and instructions for working with third-party staffing firms. Each release reflects both a more sophisticated scheme and a wider blast radius.
The FBI wanted list and the $5 million State Department reward
The FBI's Cyber Most Wanted listing carries fourteen named DPRK IT worker operatives, subject to a December 2024 federal arrest warrant out of the Eastern District of Missouri covering conduct from approximately April 2017 through March 2023. The seven-year window shows how long these operations run before enforcement reaches them.
The State Department's Rewards for Justice program offers up to $5 million for information leading to the disruption of financial mechanisms supporting North Korea, including the export of workers to generate revenue, money laundering, specified cyber activity, and support for WMD proliferation.
The OFSI advisory on North Korean IT workers and UK sanctions exposure
The UK's Office of Financial Sanctions Implementation published its advisory on North Korean IT workers on September 12, 2024, aimed at the IT, cryptocurrency, electronic money, and money services sectors. OFSI assessed it as almost certain that UK firms were already being targeted by DPRK IT workers presenting themselves as freelance third-country contractors, and highly likely that those workers were using online freelance platforms and job marketplaces to reach them.
The advisory sets out six key threats, red flag indicators, and mitigation measures, and states plainly that individuals and entities employing or paying DPRK IT workers may be breaching UK financial sanctions directly or indirectly. For any organization with UK operations or UK-based hiring authority, this is the governing reference.
Australian and other national guidance
The Australian Sanctions Office advisory was first issued in August 2024 and last updated in December 2025. It outlines how payments to DPRK IT workers breach both UN Security Council sanctions and Australia's autonomous sanctions regime, and details the verification steps it expects Australian employers to take before engaging remote technical contractors.
On July 31, 2026, eleven governments issued a joint alert on the threat. Signatories include the U.S. State Department and FBI, five Japanese ministries and agencies, the Republic of Korea's Ministry of Foreign Affairs and National Police Agency, the UK's Foreign, Commonwealth and Development Office and OFSI, Global Affairs Canada and the RCMP, and the foreign ministries of Australia, France, Germany, Italy, the Netherlands, and New Zealand. It remains the broadest multilateral response to date.
How to detect remote IT worker fraud
Detecting remote IT worker fraud takes a layered model applied across the employment lifecycle, the same conclusion Unit 42 reached after its own investigations. The four layers below map directly onto the four failure mechanisms described earlier.
1. Verify a government ID against a live human before any credential is issued
The first control is identity proofing: matching a government-issued document against a live biometric capture of the person presenting it.
This is not a simple document upload or video call. It’s a verified match between the document photo and the face in front of the camera at the moment of verification, completed before any system credential, email account, or device is provisioned.
The distinction that matters is what the verification is resistant to. Given that injection attacks bypass the camera, a check is only as strong as its ability to prove the capture is genuine. Require these properties of any identity-proofing process you deploy:
A challenge the attacker cannot pre-render. If the biometric capture is driven by a one-time, server-controlled challenge unique to that session, synthetic video prepared in advance cannot satisfy it.
Server-side decisioning. A verdict rendered inside a client SDK is a verdict an attacker controls. The determination should be made on infrastructure the attacker cannot reach.
Capture environment integrity. The system should detect virtual camera drivers, emulators, and stream substitution, rather than analyzing whatever pixels arrive.
Cryptographic binding of the capture to the session. Without it, a legitimate capture from one session can be replayed into another.
For organizations that cannot verify in person, the FBI's interview measures reduce risk: unobscured backgrounds, asking the candidate to point the camera out a window, capturing stills for comparison at later touchpoints. These are useful supplements and they do not substitute for verification built to survive an injection attack.
2. Bind the verified identity to the device and the account
Once identity is established, bind it to the specific credential and device the employee will use. Phishing-resistant, hardware-backed authentication ties access to physical possession of a verified device by a verified person, so a handoff to a different operator breaks the binding rather than inheriting it. Require the worker to confirm the laptop serial number and physical possession during IT onboarding.
Network controls reinforce this layer. Restricting access by autonomous system number surfaces logins arriving from infrastructure associated with the VPN and proxy providers these operations rely on, and correlating multiple accounts authenticating from one address catches the laptop farm pattern directly. The State Department alert lists both signals, alongside a single account reached from many addresses in a short period.
3. Re-verify at high-risk moments: account recovery, privilege escalation, device replacement
Re-verification belongs at every moment the human behind a credential might have changed. Account recovery is the highest-risk event in the enterprise, because it is the standard, supported, well-documented mechanism for transferring control of an account to whoever calls the help desk. Privilege escalation requests, device replacements, and role changes that widen access belong in the same category.
Treating these as routine IT operations rather than identity events is the specific gap the Vong case exploited. Running the same biometric verification used at hire, at each of these moments, closes it.
4. Push the same standard into third-party staffing agreements
Third-party staffing is the highest-risk vector in this threat, and the FBI's July 2025 advisory flags it explicitly: companies that outsource IT work are removed from the direct hiring process and inherit whatever verification the vendor performed. Some facilitators have gone further and stood up front companies that present themselves as short-term technical staffing providers.
Staffing contracts should require liveness-verified identity proofing before any candidate is presented, retention of verification records, and an audit right over those records. A staffing partner that cannot evidence how it verified the people it places is carrying your risk without your visibility.
Sanctions, legal, and regulatory exposure for employers
Exposure here runs in parallel rather than in sequence. A single hire can trigger sanctions, export control, and breach notification obligations at once, in every jurisdiction where the company hires.
United States: OFAC sanctions and export control liability
In the United States, paying a DPRK IT worker violates OFAC sanctions, and export control liability attaches where the worker touched controlled technology. The Wang case put ITAR-controlled defense data in an overseas co-conspirator's hands, which is the scenario that turns an employment problem into a national security matter.
Whether employers are treated as victims
To date, DOJ and OFAC have characterized hiring companies as victims that were systematically targeted. Neither agency has committed to holding that position, and both have signaled an expectation of vigilance. An organization that ignored available red flags is in a materially weaker posture than one that can document its controls.
United Kingdom: OFSI and financial sanctions breaches
In the United Kingdom, the OFSI advisory states that employing or paying DPRK IT workers may breach financial sanctions directly or indirectly. Penalties reach seven years' imprisonment for individuals alongside civil monetary penalties for organizations, and the regime reaches any company with UK operations or UK-based hiring authority.
Australia: penalties and the due diligence defense
In Australia, payments to DPRK IT workers breach both UN and autonomous sanctions, with corporate penalties of up to 10,000 penalty units or three times the transaction value. The available due diligence defense makes documented verification a legal asset rather than only an operational one.
Across every jurisdiction, a breach caused by a DPRK IT worker layers notification obligations under applicable privacy law on top of the sanctions question.
If you think you already hired one: the first 24 hours
If you believe your organization has hired a North Korean IT worker, act on the suspicion rather than waiting for confirmation. Confirmation usually arrives through the investigation itself, and the window for preserving what that investigation needs closes fast.
Sequence matters as much as substance here, starting with whether to revoke access immediately or hold the session long enough to see what it shows you.
1. Preserve before you act
Consult counsel on whether to hold the active session for forensic purposes before revoking access. Cutting access ends the exposure and can also destroy the evidence you need to scope what was taken.
2. Establish privilege early
Engage outside counsel at the outset and structure investigation communications to preserve attorney-client privilege, particularly where regulatory disclosure or law enforcement cooperation is likely.
3. Contain the credential, not just the device
Disabling a laptop accomplishes little if the operative established persistence through remote access tooling, secondary accounts, or harvested credentials. Audit every system the employee touched.
4. Coordinate HR, employment counsel, and report to the FBI and IC3
Termination carries jurisdiction-specific employment law considerations. Involve both functions before any action.
You can also contact your local FBI field office and file with the Internet Crime Complaint Center. Reporting supports the wider enforcement effort and is relevant to how your organization is characterized in any subsequent proceeding. The FBI also recommends building a standing relationship with your field office Private Sector Coordinator before an incident occurs.
5. Audit for others
Where one operative is found, check payroll and access logs for more. These networks place multiple workers at a single employer and reuse banking documentation, shipping addresses, and IP infrastructure across personas. Chapman kept notes identifying which stolen identity went with which laptop, for hundreds of machines.
What it takes to stop North Korean IT worker fraud
Stronger identity controls help prevent North Korean remote workers from landing jobs in the West, limiting the theft of sensitive data, source code, credentials, and funds that can follow successful infiltration.
The tools and controls to stop North Korean IT worker fraud are available today. Identity proofing that survives an injection attack, a credential bound to the verified person and device, re-verification at account recovery and privilege escalation, and contractual verification requirements pushed into every staffing relationship.
What these controls require is an assumption change: That the person on the other side of the video call is unproven until the verification proves them, and that the proof expires the moment control of the account can change hands.
Remote workforce verification and authentication with 1Kosmos
1Kosmos brings those layers together on one platform. Remote workforce verification and authentication confirms employee identity at onboarding through government ID validation, liveness detection, and biometric matching, then binds it to a passwordless FIDO2 credential.
The same biometric check runs again at help desk calls, password resets, account recovery, and privileged access requests, securing the moments where the operator behind an account can change.
Contact us for a live walkthrough of 1Kosmos remote workforce verification in your environment.
FAQs
What is a DPRK IT worker?
A DPRK IT worker is a skilled technology professional deployed by the North Korean government to obtain remote employment outside North Korea, typically using a stolen or fabricated identity. Wages route back to the regime to fund its weapons programs. The scheme operates in more than 40 countries and generates an estimated $250 million to $600 million annually, according to the UN Panel of Experts.
Is my company liable if we hired one?
U.S. companies that hired DPRK IT workers have generally been treated as victims by DOJ and OFAC, a posture neither agency has guaranteed will continue. Organizations with weak compliance programs, or those that overlooked documented red flags, carry more risk. In the UK, employing or paying a DPRK IT worker may breach financial sanctions regardless of intent. In Australia, a due diligence defense is available to companies that can demonstrate reasonable verification steps.
How many companies have been affected?
The Chapman case alone involved 309 U.S. businesses and two international ones. The Wang case involved more than 100 U.S. companies, many of them Fortune 500. CrowdStrike has reported infiltration at more than 100 primarily U.S. technology companies. Publicly documented figures almost certainly understate the total.
Can a deepfake pass a live video interview?
Yes. Injection attacks that bypass the camera at the software level produce a live stream that looks natural to an interviewer, and iProov's 2026 data shows those attacks rising sharply as virtual camera tooling reaches mainstream app stores. The FBI's hand-wave test may catch older presentation tooling and does not reliably detect injection attacks. Verification that resists this requires a server-controlled challenge the attacker cannot pre-render, server-side decisioning, and detection of virtual cameras and stream substitution.
What does the FBI advisory recommend?
The July 2025 advisory, IC3 alert I-072325-4, recommends scrutinizing identity documents for inconsistencies, verifying prior employment and education directly with institutions, requiring in-person verification where feasible, capturing candidate images for comparison across meetings, comparing payment accounts across employees for shared banking documentation, shipping equipment only to the address on the identity documents, withholding system access until background checks complete, and auditing third-party staffing practices. It also directs organizations to build a relationship with their local FBI field office Private Sector Coordinator.
How do I report a suspected North Korean IT worker?
Contact your local FBI field office and file at ic3.gov. UK organizations should notify OFSI of any potential sanctions breach and report to the National Cyber Security Centre. Australian organizations should contact the Australian Sanctions Office.
Sources
Australian Department of Foreign Affairs and Trade. Joint Statement on DPRK IT Workers. July 31, 2026.
Australian Sanctions Office. Advisory Note: Democratic People's Republic of Korea (DPRK) Information Technology (IT) Workers. First published August 26, 2024; last updated December 14, 2025.
CrowdStrike. 2024 CrowdStrike Threat Hunting Report: Nation-States Exploit Legitimate Credentials to Pose as Insiders. August 20, 2024.
Federal Bureau of Investigation. DPRK IT Workers, Cyber's Most Wanted. n.d.
Federal Bureau of Investigation. Field Office Directory. n.d.
Federal Bureau of Investigation. Internet Crime Complaint Center. n.d.
Federal Bureau of Investigation, Internet Crime Complaint Center. Joint United States and Republic of Korea Guidance on DPRK IT Workers. October 18, 2023.
Federal Bureau of Investigation, Internet Crime Complaint Center. North Korean IT Worker Threats to U.S. Businesses, Alert I-072325-4-PSA. July 23, 2025.
Federal Bureau of Investigation, Internet Crime Complaint Center. North Korean IT Workers Conducting Data Extortion. January 23, 2025.
Federal Bureau of Investigation, Internet Crime Complaint Center. Public Service Announcement on North Korean IT Workers. May 16, 2024.
Federal News Network. FBI Investigating North Korean Remote IT Staffer Working for U.S. Agency. August 2026.
Global Affairs Canada. Alert to Countries, Companies, and Other Entities Regarding North Korean IT Workers. July 31, 2026.
iProov. 2026 Threat Intelligence Report. April 8, 2026.
KnowBe4. How a North Korean Fake IT Worker Tried to Infiltrate Us. July 2024.
Mandiant. Staying a Step Ahead: Mitigating the DPRK IT Worker Threat. September 23, 2024.
Office of Financial Sanctions Implementation, HM Treasury. Advisory on North Korean IT Workers. September 12, 2024.
Palo Alto Networks, Unit 42. Global Companies Are Unknowingly Paying North Koreans: Here's How to Catch Them. November 13, 2024.
SentinelLabs. Research on DPRK IT Worker Personas Targeting SentinelOne. 2025.
United Nations Security Council. Note by the President of the Security Council, S/2024/215. March 7, 2024.
U.S. Attorney's Office for the District of Columbia. Arizona Woman Sentenced in $17M IT Worker Fraud Scheme That Illegally Generated Revenue for North Korea. July 24, 2025.
U.S. Department of Justice. Court-Authorized Action to Disrupt DPRK IT Worker Revenue Generation. October 18, 2023.
U.S. Department of Justice. Justice Department Announces Coordinated, Nationwide Actions to Combat North Korean Remote Information Technology Workers' Illicit Revenue Generation Schemes. June 30, 2025.
U.S. Department of Justice. Maryland Man Sentenced for Conspiracy to Commit Wire Fraud. December 2025.
U.S. Department of Justice. Two U.S. Nationals Sentenced for Facilitating Fraudulent Remote Information Technology Worker Scheme That Generated $5M in Revenue for the Democratic People's Republic of Korea. April 15, 2026.
U.S. Department of State, Office of the Spokesperson. Alert to Countries, Companies, and Other Entities Regarding North Korean IT Workers. July 31, 2026.
U.S. Department of State, Rewards for Justice. North Korea Money Laundering: Nine Individuals. n.d.
About the author

Mike Engle
Co-Founder and CSO
Mike is the CSO and a co-founder of 1Kosmos with deep expertise in information security, product development, and business development across Fortune 100 financial institutions and early-stage startups.





