FBI Warns of North Korean IT Workers Using Stolen Identities

The U.S. State Department, FBI, and allied governments—including Japan, Canada, Germany, Australia, the United Kingdom, and South Korea—have jointly issued a warning about North Korean IT workers infiltrating private companies using stolen identities, forged documents, and proxy networks. These operatives secure remote freelance and full-time positions to funnel salaries back to Pyongyang, thereby financing the regime’s illicit nuclear weapons and ballistic missile programs.

Beyond financial implications, these schemes pose significant insider threats, including data exfiltration, cryptocurrency theft, and the compromise of sensitive corporate information. North Korean IT workers often impersonate foreign nationals on online employment platforms, registering accounts with falsified nationality details and forged identification documents. They frequently use images provided by third-party proxies residing in other countries. These proxies may participate in interviews, establish in-person contact, or provide bank accounts to conceal the true workers’ identities.

Payment methods can serve as red flags. Many applicants avoid direct deposit, preferring money transfer services, cryptocurrency, or directing wages to a third party’s account, which then routes funds overseas after taking a commission. In 2026 alone, eight individuals have been sentenced in connection with these facilitation schemes, highlighting the seriousness of the threat.

The advisory notes an expanding toolkit among these operatives. They increasingly utilize artificial intelligence to enhance profiles, generate convincing communications, and obscure their true identities. Operating from locations such as North Korea, China, Russia, Southeast Asia, or Africa, they mask their whereabouts using VPNs, remote desktop software, and “laptop farms.” In these setups, facilitators in trusted jurisdictions receive company-issued laptops, keeping them powered on so North Korean workers can log in remotely, appearing to work locally.

These operatives are not limited to coding jobs in web development, mobile apps, software, and blockchain. Some also run fraudulent foreign-exchange trading systems they have developed to generate additional hard currency. Companies that unknowingly hire these workers risk more than just a poor hire. Contracting with North Korean nationals and paying them can violate United Nations Security Council Resolution 2397 and domestic sanctions laws in the United States, Japan, South Korea, and other jurisdictions, exposing firms to legal penalties and financial sanctions.

The Financial Action Task Force continues to blacklist North Korea as a high-risk jurisdiction for proliferation financing, explicitly citing IT-worker revenue streams as a sanctions-evasion pathway. Successful infiltration can lead to stolen source code, customer data, credentials, and cryptocurrency holdings.

The joint alert urges organizations to tighten identity verification and hiring controls. Recommendations include rigorous review of identification documents, preference for in-person or carefully scrutinized live video interviews, and systems that flag anomalous account activity. Indicators to watch for include frequent changes to names or bank details, mismatched payment-account names, multiple accounts sharing the same ID or IP address, forged or edited identity images, unnaturally long login sessions, and profiles riddled with translation errors.

During video calls, employers should be vigilant for photo-ID mismatches, manipulated or AI-generated feeds, refusal to turn on cameras, below-market rates, signs that multiple people are operating one account, and demands for cryptocurrency payment. Platform operators are encouraged to notify users of suspicious entries and strengthen account monitoring tools.

Anyone suspecting they have encountered a North Korean IT worker scheme is advised to report the activity promptly to relevant national authorities.

As remote work becomes increasingly prevalent, the sophistication of these infiltration tactics underscores the need for robust identity verification processes and heightened vigilance in hiring practices. Organizations must remain proactive to protect their assets and comply with international regulations.