FBI warns of North Korean fake IT workers

Published July 27, 2026

North Korean operatives use stolen identities and forged documents to get hired as remote IT workers at companies worldwide. Their pay gets funneled back to fund North Korea's weapons programs, and their inside access opens the door to stolen data and cryptocurrency.

Report priority
Medium
Involves
Exchange

What is known

Operatives apply for freelance and full-time tech jobs on hiring and contracting platforms using falsified nationality details and doctored ID photos, sometimes with the help of paid proxies who sit for interviews or lend their bank accounts.

What to do

Hiring managers and finance teams should review recent remote tech hires for red flags such as refusal to enable video, mismatched payment-account names, requests for cryptocurrency pay, or multiple accounts sharing one ID or IP address.

The joint advisory recommends tighter identity verification, in-person or closely scrutinized live video interviews, monitoring for the listed red flags, and reporting suspected cases to the FBI or the relevant national authority.

Reported details

The advisory, issued jointly by the US State Department, FBI, and counterparts in Japan, Canada, Germany, Australia, the UK, and South Korea, describes North Korean IT workers using AI tools to polish fake profiles and communications while hiding their location with VPNs, remote desktop software, and 'laptop farms' run by local facilitators. Hiring or paying these workers can violate UN Security Council Resolution 2397 and domestic sanctions laws. Eight people have been sentenced in 2026 for facilitating these schemes.

References