Federal officials say a growing number of North Korean operatives are posing as remote information‑technology workers and securing jobs at American firms. By exploiting stolen U.S. identities, “laptop farms” and generative artificial intelligence, the regime is turning the remote‑work boom into a lucrative source of revenue and a conduit for cyber‑espionage.
Scale of the threat
The Treasury Department reported that in 2024 the state‑directed workforce generated nearly $800 million for North Korea, helping fund its weapons programs despite heavy sanctions. Treasury Secretary Scott Bessent warned that these operatives target American companies with deceptive schemes, weaponizing sensitive data and extorting substantial payments.
How the scheme works
Operatives first acquire stolen American identities and set up U.S.‑based laptop farms—collections of computers that appear to be located in the United States. They then use AI tools to craft résumés and answer interview questions in real time, often employing deep‑fake or interview‑assistance software. Once hired, they gain legitimate credentials and trusted access to corporate networks, opening the door to theft, espionage and further extortion.
Cyber‑security expert Michael “Barni” Barnhart, a former Army intelligence specialist now with DTEX, says the operation is pervasive. In a recent sample of 20 Fortune 500 companies, evidence of North Korean IT applicants or targets was found in 18 of them.
Recruitment and intermediaries
As companies improve their vetting processes, the regime has shifted tactics. It now recruits individuals in the United States and other countries—such as Pakistan, India and Nigeria—to act as the public face of the operation, host laptops, or lend their identities. These intermediaries are often people facing financial hardship, offered a few hundred dollars to host a laptop or impersonate a job applicant.
Facilitators may initially be unaware of the larger scheme. Some believe they are simply helping a foreign developer earn passive income. Over time, requests can expand, leading participants to unwittingly enable fraudulent résumé creation, employer vetting and remote access to company‑issued laptops.
Law‑enforcement response
The Justice Department has prosecuted a growing number of Americans and foreign facilitators for participating in these schemes. Recent cases include an Arizona resident sentenced to more than eight years for wire‑fraud conspiracy linked to a North Korean IT operation.
Federal prosecutors emphasize that both witting and unwitting third parties can be used to obscure the true source of the work, making investigations more complex.
Implications for businesses
Beyond the immediate financial loss, the infiltration poses a national‑security risk. Once inside a corporate network, operatives can exfiltrate proprietary data, conduct espionage against U.S. think tanks and healthcare organizations, and lay the groundwork for more sophisticated cyber attacks.
Companies are urged to scrutinize remote‑worker applications for inconsistencies—such as mismatched accents, unfamiliar local knowledge, or suspicious laptop shipment addresses—and to verify identity documents through multiple channels.
What individuals can do
Potential employers should be wary of unsolicited offers to host laptops or provide personal information. If approached, they should report the request to law‑enforcement and avoid sharing credentials or hardware.
As the remote‑work landscape evolves, vigilance remains the best defense against foreign cyber threats that seek to exploit American businesses for profit and strategic advantage.
Original reporting: Fox News (HLL/CB) — read the source article.