Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Amazon Blocked 1,800 Suspected North Korean IT-Worker Applicants. What the Figure Means

Amazon says it blocked more than 1,800 suspected DPRK-linked applicants—not confirmed employees—through screening since April 2024. Here’s how the schemes work and what layered defenses look like.
From TheFinanceBase Team7 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Amazon says it stopped more than 1,800 people it suspected of being linked to North Korean IT-worker operations from joining the company since April 2024. The figure, disclosed by Amazon Chief Security Officer Stephen Schmidt in December 2025, describes suspected applicants blocked before joining—not 1,800 confirmed North Korean employees or a reported breach involving that many people. Amazon also said DPRK-affiliated applications rose 27% quarter over quarter during 2025, without publishing the underlying counts or measurement method. Schmidt’s disclosure

What Amazon disclosed—and what it did not

Schmidt said Amazon combines AI-assisted screening with human verification, background checks, credential verification, and structured interviews. The company’s model analyzes application anomalies, geographic inconsistencies, and connections to nearly 200 high-risk institutions. Amazon has not publicly identified those institutions or explained its scoring criteria. The company’s statement does not break down the 1,800 figure by role, location, hiring stage, or confirmed versus suspected cases.

  • “Suspected” is important: Amazon has not said every applicant was conclusively identified as a North Korean national or operative.
  • “Stopped from joining” means blocked from entering the company, not hired and later removed.
  • The disclosure does not establish that Amazon was breached by those applicants or that none ever got through.
  • The 27% increase is quarter over quarter in 2025; without a baseline or methodology, it cannot be translated into an annual growth rate or total application count.

Dark Reading reported Amazon’s observations of résumé and education inconsistencies, stolen or dormant professional accounts, laptop farms, and increased targeting of AI and machine-learning roles. That is an Amazon-attributed observation, not proof that every employer faces the same rate of targeting. Dark Reading’s account

How DPRK IT-worker schemes operate

These schemes are not simply a false résumé submitted by one applicant. U.S. authorities describe networks that combine stolen or borrowed identities, facilitators, remote access, and sometimes fake online personas to obtain remote work and route earnings to North Korea. Some cases also involve data theft or extortion. The specific tactics vary, and not every fraudulent hire is established to have an espionage objective.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Identity and application

An applicant may use a stolen or borrowed U.S. identity, alias email addresses, altered credentials, or a compromised or dormant job-platform or social-media account. The FBI has also warned that actors may use AI or face-swapping technology to obscure who appears in a video interview. FBI advisory on data extortion

Facilitators and laptop farms

A U.S.-based facilitator may provide an address, internet connection, payment account, or access to a company-issued computer. A “laptop farm” is a location where company laptops are received and kept in the United States while a purported employee—or another person—connects remotely from elsewhere. The FBI describes facilitators receiving equipment, enabling remote desktop access, reshipping devices, or helping with interviews. FBI guidance on U.S.-based facilitators

That arrangement can defeat superficial checks: a U.S. shipping address, a U.S. IP address, or a laptop physically located in the country does not prove who is operating it or where that person is. DOJ actions have also described false websites, proxy computers, and facilitators as parts of broader schemes. DOJ announcement of coordinated actions

Why the work can be valuable to North Korea—and risky for employers

The central objective described by Schmidt is revenue generation: wages can be funneled to support the North Korean regime, including its weapons programs. Government cases also describe risks beyond wage fraud, including unauthorized access, theft of source code or proprietary information, and data extortion. The FBI’s 2025 advisory covers data-extortion activity; DOJ announcements describe specific prosecutions and enforcement actions. FBI advisory · DOJ announcement

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

DOJ said one coordinated enforcement action involved placements at more than 100 U.S. companies; a separate May 2024 announcement described schemes involving more than 300 companies. Those are counts tied to particular actions, not a census of affected firms or the total size of the campaign. DOJ coordinated action · DOJ May 2024 action

Amazon’s reported increase in targeting of AI and machine-learning roles is worth noting, but it is not a measured industry-wide trend. Plausible reasons include demand for specialized talent, remote-friendly work, and access to valuable code, data, and cloud systems; those are explanations, not findings Amazon publicly attributed to its screening data.

Why ordinary hiring checks can miss the scheme

A clean background check, credible technical interview, or valid identity document answers only part of the question. A real person’s identity may be misused, a facilitator may appear during an interview, or another person may operate the equipment after onboarding. Likewise, an IP geolocation check can be distorted by proxies, corporate networks, VPNs, or a laptop farm.

  • One résumé signal is not proof. Education dates, claimed majors, employment history, email addresses, and location discrepancies should prompt corroboration, not automatic rejection.
  • Remote tools have legitimate uses. Remote desktop software may be needed for support or accessibility; investigate context and authorization rather than assuming its presence establishes fraud.
  • Identity verification has limits. A valid document or liveness check does not prove that the person who interviewed is the person doing the work every day.
  • Nationality and accent are not security indicators. Controls should rely on evidence and behavior, be applied consistently, and be reviewed for discriminatory effects.
  • E-Verify is not a location or operator check. The FBI recommends verifying worker information through E-Verify where applicable, but it does not by itself prove who is using a device.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

A layered defense for remote hiring

The FBI’s recommendations span hiring, onboarding, employment, and vendor relationships. A practical program pairs identity and credential checks with device controls and monitoring; no single signal or vendor can identify every fraudulent worker.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Before hiring: verify identity, credentials, and work history

  • Use structured interviews and role-specific questions, with more than one live session for sensitive roles. Compare the candidate’s account of past work across interviews and documents.
  • Verify degrees and certifications with the issuing institution or a trusted service where appropriate. Check whether claimed dates and programs are plausible, but do not treat a school or country as a proxy for guilt.
  • Where lawful and proportionate, use document and liveness checks and confirm that the person presenting identification matches the applicant across interview and onboarding.
  • Investigate unexplained changes in address, payment details, identity records, or account history, while allowing candidates to explain legitimate changes.

At onboarding: control equipment and initial access

  • Confirm identity and delivery details before shipping equipment; monitor address changes close to shipment.
  • Record serial numbers and chain of custody, enroll company devices in endpoint management, and require device-health checks before access.
  • Limit local administrator rights and prohibit or tightly control unauthorized remote-access tools. Use hardware-backed authentication and least-privilege access for privileged systems.
  • Give new hires only the access required for their initial duties, with additional permissions granted through review.

During employment: monitor devices, accounts, and data movement

  • Look for remote sessions inconsistent with the worker’s declared location, unusual access hours, repeated proxy or remote-desktop connections, and unexplained device-management activity.
  • Review source-code and cloud activity for bulk cloning, unusual downloads, new SSH keys or API tokens, unexpected OAuth applications, and access to secrets or administrative systems outside normal duties.
  • Monitor for unauthorized KVM devices, unusual USB activity, persistence mechanisms, and remote-access software. A legitimate tool can still be abused, so validate its purpose and approval.
  • Do not rely on latency or geolocation alone; VPNs, corporate proxies, routing, and cloud development environments can create misleading signals.

Across staffing firms and contractors: extend the same controls

Employees may enter through staffing agencies, outsourced development firms, freelance platforms, subcontractors, managed-service providers, or acquired businesses. The FBI specifically advises auditing third-party staffing firms. FBI guidance

  • Require identity and employment verification, disclosure of subcontracting, and security standards for devices and access.
  • Require prompt notice of changes in personnel, work address, or payment platform; include audit, logging, incident-notification, sanctions, and export-control terms where relevant.
  • Make vendor personnel subject to the same least-privilege and endpoint rules as direct hires, and ensure the company can obtain relevant security logs.

What to do if a worker or applicant appears fraudulent

  1. Preserve records. Retain recruiting documents and résumé versions, interview recordings where lawful, verification results, device telemetry, access logs, shipping records, payment details, and communications.
  2. Restrict risk proportionately. Revoke privileged access first and contain accounts or devices as appropriate, coordinating with incident-response counsel and investigators before actions that could destroy evidence or alert suspects.
  3. Keep the device intact. Do not wipe or reimage a laptop unless incident responders, counsel, or investigators direct it; preserve logs and chain-of-custody information.
  4. Investigate access and persistence. Review remote-access tools, VPN and remote desktop sessions, KVM devices, installed software, administrative activity, and unusual data transfers.
  5. Rotate exposed credentials and tokens. Prioritize cloud consoles, source-code repositories, secrets managers, CI/CD systems, signing keys, and administrator accounts.
  6. Assess data exposure. Check for bulk downloads, repository cloning, archive creation, access outside expected geography or hours, and unusual egress.
  7. Involve the right teams. Coordinate security, legal, HR, compliance, and sanctions personnel. Determine whether any identity holder was a knowing facilitator, an unwitting participant, or a victim of identity theft; do not make public accusations.
  8. Report when appropriate. The FBI advises reporting suspected activity to law enforcement; its IC3 guidance is available at IC3’s October 2023 public service announcement. Review staffing and contractor channels as part of the investigation.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.