The U.S. State Department, FBI, and allied governments warned that North Korean IT workers are obtaining freelance and full-time jobs at companies worldwide by using stolen identities, forged documents, proxy interview participants, VPNs, remote desktop tools, and overseas "laptop farms" that make them appear to be operating from trusted jurisdictions. Authorities said the workers funnel wages and cryptocurrency payments back to Pyongyang, helping fund North Korea’s nuclear weapons and ballistic missile programs while exposing employers to insider threats including data exfiltration, credential theft, and cryptocurrency theft.
The warning builds on earlier reporting and government actions showing that DPRK-linked workers have infiltrated Western technology and cryptocurrency firms under false identities, sometimes through front companies and facilitators based in Russia and China. Researchers and prior U.S. cases have tied the scheme to broader risks beyond sanctions exposure, including potential malware deployment, espionage, disruption, and money laundering, prompting officials to urge stronger identity verification, closer scrutiny of interviews and payment arrangements, monitoring for anomalous account activity, and rapid reporting of suspected hires.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Vangelis Stykas publicly disclosed findings from 22 months of access to systems used by North Korean hackers and scam IT workers, saying he found evidence that 1,640 organizations in 57 countries were affected and that 700 to 800 suffered especially damaging intrusions. He said the compromises included root access to servers and AWS environments, exposure of cryptocurrency-related assets, and named victims including Boston Children’s Hospital, Coinbase, Uniswap Labs, Oppo, AEON Smart Technology, Italy’s Supreme Judicial Council, an Al Rajhi Bank subsidiary, and Digitaal Vlaanderen.
On July 31, 2026, the U.S. State Department, FBI, and allied governments issued a joint advisory warning that North Korean IT workers were using stolen identities, forged documents, proxies, and remote-access infrastructure to obtain jobs worldwide. The alert said the scheme funds Pyongyang's nuclear and ballistic missile programs and creates insider-threat risks including data theft, credential compromise, and cryptocurrency theft.
On July 3, 2025, South Korea's Foreign Ministry published a press release announcing a joint advisory related to North Korean IT workers. The release indicates an official government warning about the DPRK IT worker threat prior to the later 2026 U.S.- and allies-led advisory.
On June 30, 2025, the U.S. Department of Justice announced coordinated nationwide actions against North Korean remote IT worker operations, including two indictments, an arrest, a plea agreement, searches of laptop farms, and seizures of financial accounts, websites, and computers. DOJ said the schemes used stolen or fake identities to place workers at more than 100 U.S. companies, generated millions in revenue, and in some cases enabled theft of sensitive data and cryptocurrency.
OpenAI reported banning ChatGPT accounts linked to multiple deceptive employment campaigns that used AI to support fraudulent remote IT job applications. It said the activity was behaviorally consistent with publicly attributed North Korea-linked IT worker schemes and disclosed operational details including automated resume generation, interview assistance, contractor recruitment, and research into remote-access tooling.
On February 1, 2025, OpenAI published a case study on an AI-assisted deceptive employment scheme and said it banned dozens of accounts involved. The activity was described as consistent with publicly reported North Korea-linked IT worker tradecraft, including fake applicant materials, interview assistance, remote-access tooling, and recruitment of U.S.-based helpers to receive laptops or lend identities.
On November 22, 2024, Microsoft published intelligence from its CYBERWARCON presentations describing North Korean IT workers operating under false identities and supported by facilitators providing accounts, banking, SIMs, and job-platform access. Microsoft also said it had found a public repository in October 2024 containing resumes, infrastructure details, playbooks, and evidence of AI-enabled identity fraud and voice-changing experimentation.
North Korea's Foreign Ministry publicly denounced the 11-country advisory on its alleged IT worker schemes, calling the accusations politically motivated and intended to damage the country's image. In a statement carried by KCNA, a spokesperson accused the United States of fabricating a cyber-threat narrative to justify pressure on Pyongyang and deepen confrontation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
13 references tracked. Mallory keeps watching after this page renders.
wired.com
Open sourceteiss.co.uk
Open sourcenknews.org
Open sourcenknews.org
Open sourceopenai.com
Open sourcemargin.re
Open sourcemicrosoft.com
Open sourceic3.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.