North Korean IT workers have significantly expanded their operations to infiltrate a wide range of industries beyond the traditional technology sector, according to research published by Okta Threat Intelligence. The scheme involves North Korean nationals, or individuals funneling money back to Pyongyang, fraudulently obtaining remote employment, primarily in software development roles. Okta's research indicates that nearly half of the targeted companies are outside the IT sector, with finance, healthcare, public administration, and professional services now among the most affected industries. The campaign, which initially focused on U.S.-based cryptocurrency and blockchain firms, has evolved to target organizations in dozens of countries, with 27% of targeted entities now located outside the United States. Okta tracked more than 130 identities associated with North Korean facilitators and workers, linking them to over 6,500 initial job interviews at more than 5,000 companies from 2021 through mid-2025. The methodology for identifying these DPRK-aligned identities relies on a combination of technical indicators, behavioral patterns, and employer reporting, though Okta has withheld some details to avoid alerting the threat actors. The scale of the operation is believed to be much larger than the tracked sample, with the FBI and private security firms, including Google's Mandiant, warning that the problem is widespread among Fortune 500 companies. Mandiant's CTO, Charles Carmakal, noted that almost every CISO of a Fortune 500 company he has spoken to has encountered issues with North Korean IT workers. The North Korean operatives use fake or stolen identities to secure remote roles, circumventing international sanctions and generating millions of dollars for the North Korean military. The campaign's adaptability is evident in its shift to any remote role that fits the scheme's requirements, regardless of industry or geography. Okta's findings highlight the persistent and evolving nature of the threat, with North Korean IT workers now targeting a broad spectrum of organizations globally. The report underscores the need for enhanced identity verification and vigilance in remote hiring processes. The expansion of this scheme poses significant risks to sensitive data, intellectual property, and the integrity of critical sectors such as healthcare and finance. The threat is compounded by the difficulty in detecting these operatives, given their use of sophisticated identity obfuscation techniques. Okta's research suggests that the true scale of North Korean IT worker activity is likely much greater than currently documented. The ongoing campaign demonstrates North Korea's commitment to leveraging cyber-enabled means to generate revenue and evade international restrictions. Organizations are urged to review their remote hiring practices and strengthen controls to mitigate the risk of inadvertently employing North Korean operatives. The findings also highlight the importance of cross-sector collaboration and intelligence sharing to counter this persistent threat. The expansion of North Korean IT worker infiltration represents a significant evolution in state-sponsored cyber-enabled financial operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
35 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-06, the U.S. Department of Justice announced that Matthew Isaac Knoot and Erick Ntekereze Prince were each sentenced to 18 months in prison for facilitating North Korean remote IT worker fraud schemes. DOJ said the schemes affected nearly 70 U.S. companies and generated more than $1.2 million for the DPRK by routing company laptops through U.S. residences and enabling overseas workers to appear domestic.
On 2026-04-15, the U.S. Department of Justice announced that two U.S. nationals were sentenced for facilitating a fraudulent remote IT worker scheme that generated $5 million in revenue for North Korea. The announcement marked a distinct law-enforcement milestone in the DPRK remote-worker crackdown before the later May 2026 sentencing announcement already in the timeline.
On 2026-03-20, the U.S. Department of Justice announced that three individuals were sentenced for facilitating computer access as part of a North Korean sanctions-evasion scheme. The case represents a distinct sentencing milestone in the broader crackdown on DPRK-linked remote IT worker and facilitator operations.
On 2026-03-12, the United States imposed sanctions tied to North Korea's use of remote IT workers to generate revenue for the regime and support its weapons program. The action marked a distinct escalation from prior warnings and criminal cases by adding formal economic penalties.
The U.S. State Department published a release describing how North Korea violates and evades UN sanctions through cyber operations and illicit IT worker activity. The statement marked a new official U.S. government articulation linking the IT worker scheme to broader sanctions-evasion activity.
On 2026-01-05, Kudelski Security published research on the DPRK fake IT worker network, describing IP ranges, proxy usage, and signs of internal coordination. The report added new technical detail on the infrastructure and operational tradecraft supporting North Korea's fraudulent remote-worker scheme.
On 2025-11-17, NK News reported that U.S. and Ukrainian facilitators pleaded guilty to helping North Korean IT workers obtain remote IT jobs. The pleas marked a new law-enforcement milestone in the crackdown on the DPRK remote-worker scheme, distinct from earlier arrests and later sentencings.
On 2025-10-22, the U.S. State Department published a joint statement from the Multilateral Sanctions Monitoring Team on a report covering North Korea's cyber operations and illicit IT worker activity. The statement marked a new multilateral official assessment linking DPRK cyber and remote-worker activity to sanctions monitoring and enforcement concerns.
Daily NK reported that North Korea deployed about 100 IT workers to a newly established base in a Chinese border city, indicating continued operational expansion of the regime's overseas IT worker program. The move adds a concrete new deployment location and suggests sustained support infrastructure for the scheme in China.
Chainalysis published research on how North Korean IT workers are connected to cryptocurrency money-laundering networks. The report added technical and financial detail to the broader understanding of how the scheme generates and moves funds.
Okta disclosed that North Korea's illicit IT worker scheme had expanded across more industries and countries, likely driven by refined tradecraft and pressure from U.S. awareness and law-enforcement disruption. The company also warned that increased pressure could push DPRK actors toward ransomware, data theft, and extortion for revenue.
On 2025-07-24, the U.S. Department of Justice announced that Christina Marie Chapman of Arizona was sentenced to 102 months in prison for helping North Korean IT workers use stolen identities and a U.S.-based laptop farm to obtain remote jobs. DOJ said the scheme generated more than $17 million, defrauded 309 U.S. businesses and two international companies, and attempted to infiltrate two U.S. government agencies.
On 2025-07-21, the FBI issued an alert warning that North Korean IT workers had escalated from fraudulent remote employment into data extortion activity. The notice marked a specific U.S. government warning that these operators were stealing company data and using it to extort employers or clients.
On 2025-07-08, the U.S. Treasury announced sanctions targeting North Korea's illicit IT worker operation used to generate revenue for the Kim regime. The action marked a new formal economic enforcement step between the January 2025 sanctions and the later July 2025 FBI warning about data extortion.
On 2025-06-30, the U.S. Department of Justice announced charges against four North Korean nationals for a cryptocurrency theft scheme involving nearly $1 million. The case represents a new law-enforcement action linking DPRK-linked operators to theft of digital assets, beyond earlier fraud and facilitator cases in the remote IT worker ecosystem.
By mid-2025, Okta had identified more than 130 facilitator- or worker-operated identities tied to over 6,500 initial job interviews across more than 5,000 companies. The company assessed this represented only a small sample of the overall North Korean operation.
Over time, the DPRK's illicit remote-worker operation broadened from an early focus on cryptocurrency and blockchain firms to industries including finance, healthcare, professional services, government, and AI-related roles. Okta said the campaign also spread outside the United States, with non-U.S. organizations making up about 27% of targeted entities in its sample.
On 2025-05-19, Nisos reported a suspected DPRK-linked employment scam network posing as Polish and U.S. nationals to win remote engineering and blockchain jobs. The researchers said the actors used GitHub profiles, portfolio sites, freelancer accounts, and a fake software firm called Inspiration With Digital Living (IWDL), marking an early reported case of DPRK IT workers using a fabricated freelance company front to obtain project-based work.
On 2025-04-24, Okta Threat Intelligence reported that facilitators supporting DPRK-linked fraudulent remote workers were using generative AI to build personas, tailor resumes, rehearse interviews, manage communications, and help workers maintain multiple jobs. The report also noted use of shipping and logistics services to route company devices to Western laptop farms, adding new technical detail on how the scheme was being scaled.
On 2025-01-23, the U.S. Department of Justice announced indictments against five individuals tied to a North Korean fraudulent remote IT worker operation. The case marked a new criminal enforcement action in the broader crackdown on DPRK-linked fake worker schemes, separate from the December 2024 indictment of 14 North Koreans and the January 2025 Treasury sanctions.
On 2025-01-16, the U.S. Treasury Department sanctioned two individuals and four entities for helping North Korea generate revenue through fraudulent remote IT worker operations. OFAC said the network included Department 53, front companies Korea Osong Shipping Co. and Chonsurim Trading Corporation, and Liaoning China Trade Industry Co., Ltd., and supported overseas operations including in Laos.
On 2024-12-12, the U.S. government offered a reward of up to $5 million for information that could help disrupt North Korea's illicit remote IT worker operations, including laptop farms and facilitators. The announcement marked a distinct escalation beyond indictments and seizures by adding a public incentive to identify infrastructure supporting the scheme.
On 2024-12-12, the U.S. Department of Justice announced the indictment of fourteen North Korean nationals for allegedly carrying out a years-long fraudulent remote IT worker scheme. DOJ said the operation involved using false identities to obtain IT jobs at companies and included related extortion activity, marking a new criminal case beyond earlier facilitator-focused actions.
On 2024-09-23, Mandiant published research tracking DPRK-linked IT worker activity as UNC5267, describing stolen identities, facilitators, laptop farms, multiple remote-admin tools, and Astrill VPN-linked access patterns. The blog also provided mitigation guidance and published indicators including a Netlify profile tied to a fabricated software engineer persona.
The U.S. Department of Justice announced the arrest and indictment of Matthew Isaac Knoot for allegedly helping North Korean IT workers obtain remote jobs at U.S. and British companies through a Nashville-based laptop farm and stolen identity. Prosecutors said the operation funneled proceeds to the DPRK and caused victim firms in media, technology, and finance to incur hundreds of thousands of dollars in losses and remediation costs.
On 2024-07-15, KnowBe4 said a newly hired remote software engineer using a stolen U.S. identity triggered security alerts for malware loading, session-history manipulation, harmful file transfers, and unauthorized software execution shortly after receiving a company Mac workstation. The company said it contained the device, reported no data loss or exfiltration, and shared evidence with Mandiant and the FBI as part of an active investigation.
On 2024-05-16, the U.S. Department of Justice announced the arrest of Maryland resident Minh Phuong Vong for allegedly helping North Korean IT workers obtain U.S. remote jobs by posing as him, alongside a premises search and the seizure of 12 domains used to impersonate Western IT services firms. DOJ said the action was part of its DPRK RevGen: Domestic Enabler Initiative targeting U.S.-based facilitators, laptop farms, and fraudulent infrastructure supporting Pyongyang's revenue generation.
On 2024-05-16, the U.S. Department of Justice announced criminal charges and asset seizures in an operation aimed at disrupting a fraud scheme that generated revenue for North Korean IT workers. The action marked an earlier U.S. law-enforcement move against the DPRK remote-worker ecosystem before the later August 2024 Nashville facilitator case.
U.S. authorities publicly warned that North Korea had deployed thousands of remote IT workers abroad, including in the tech sector, to earn wages that were sent back to support the regime. The disclosure highlighted the scale of the scheme and its role in funding Pyongyang's weapons programs.
On 2023-10-18, the U.S. Department of Justice announced a court-authorized action seizing 17 website domains used by North Korean IT workers to impersonate U.S. IT services firms, obtain remote freelance work fraudulently, and generate revenue for the DPRK. DOJ said the operation disrupted infrastructure tied to workers operating mainly from China and Russia and linked the scheme to sanctions evasion, data theft, and potential extortion.
In July 2023, the U.S. Cyber Threat Intelligence Integration Center described how North Korea used cyber operations and deceptive overseas IT worker schemes to evade sanctions and generate revenue for regime priorities. The product named actors including Lazarus Group, APT38, APT37, and Kimsuky, referenced malware such as Manuscrypt and AppleJeus, and provided red flags and mitigation guidance for hiring firms, freelance platforms, and payment processors.
On 2023-05-24, the U.S. government announced sanctions targeting North Korea's illicit IT workforce and associated entities used to generate revenue for the regime. The action marked an early formal U.S. government move against the DPRK remote-worker scheme, preceding later DOJ seizures, warnings, and additional sanctions.
Okta observed North Korean IT worker personas interviewing with U.S. state and federal government departments beginning in 2023. The activity showed the scheme had expanded beyond private-sector tech targets into sensitive public-sector organizations.
On 2022-05-16, the U.S. government published the North Korea Information Technology Workers Advisory warning that DPRK nationals were using remote IT work to generate revenue for the regime. The advisory provided due-diligence guidance and red flags for companies hiring or contracting IT workers, marking an early formal U.S. warning about the scheme.
On 2018-09-13, the U.S. Treasury sanctioned Yanbian Silverstar Network Technology Co., Ltd. in China, its CEO Jong Song Hwa, and Russia-based Volasys Silver Star for generating revenue through North Korean overseas IT workers. OFAC said the firms used front-company structures and deceptive identities to place DPRK IT labor abroad and linked the network to entities associated with North Korea's missile and defense procurement apparatus.
50 references tracked. Mallory keeps watching after this page renders.
osintteam.blog
Open sourcejustice.gov
Open sourcethecyberexpress.com
Open sourcejustice.gov
Open sourcejustice.gov
Open sourcemicrosoft.com
Open sourcejustice.gov
Open sourceic3.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.