Fall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowFall ResetAmazon USWork and home upgrades are worth comparing todayAmazon US: today's deals, useful picks and quick comparisons.See Picks×
Skip to content
Blog

DOJ Actions Target North Korean IT Worker Scheme Using Stolen U.S. Identities

By TheFinanceBase Team8 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

The Department of Justice’s June 2023 actions targeted a scheme in which North Korean remote IT workers allegedly used stolen or borrowed identities to get jobs at U.S. companies. U.S.-based facilitators hosted employer-issued laptops so workers abroad could operate them remotely, making their connections appear to come from inside the United States. The announcement was one stage in a series of investigations—not a single case covering every later indictment, plea, or sentence.

What the DOJ announced

In June 2023, the DOJ announced arrests, criminal charges, civil forfeiture actions, and seizures of domains and other assets as part of coordinated efforts against schemes involving North Korean remote IT workers. Prosecutors said U.S.-based facilitators helped workers located abroad obtain jobs with American companies and conceal where the work was being done. The allegations and enforcement actions are described in the DOJ’s coordinated-action announcement and a related release on charges and seizures.

The cases concern more than conventional résumé fraud. Prosecutors described identity misuse, misleading employment arrangements, and U.S. addresses used to host company equipment. A person whose identity, address, or services appeared in the scheme was not necessarily a knowing participant; the government’s allegations concern particular defendants and conduct.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the scheme worked

  1. Build an applicant identity. A worker allegedly used stolen, forged, or borrowed personal information to create or support an employment profile. DOJ materials describe fraudulent or altered identification documents; see the DOJ document.
  2. Apply for remote technical work. The worker sought roles such as software development, IT, or engineering using online hiring channels, recruiters, or front-company infrastructure.
  3. Complete hiring and onboarding. The applicant interviewed and was hired under an identity that suggested U.S. residence. Remote interviews and document checks could fail to reveal who would actually perform the work.
  4. Send the company laptop to a U.S. address. A facilitator received or hosted employer-issued equipment and connected it to the internet.
  5. Operate the device from abroad. The worker remotely accessed the laptop. Because the company’s device was physically in the United States, ordinary device-location or IP checks could make the user appear domestic.
  6. Earn wages and gain access. Salary could be routed for the benefit of the workers or North Korea, while legitimate employee credentials could provide access to company systems and information.

What a “laptop farm” is—and why location checks can miss it

A laptop farm is a U.S. home or other facility where multiple employer-issued laptops are stored and connected to the internet for remote operation. It need not be a formal data center: DOJ cases describe ordinary residences hosting computers supplied by victim companies. A worker abroad can control a laptop at that location, so a U.S. IP address or a device registered in the United States does not establish that the person using it is physically there. The setup is described in the 2023 DOJ case release and the 2024 indictment announcement.

That distinction matters for employers: endpoint management can confirm a company laptop is genuine and online without proving who is operating it. IP geolocation, device posture, or a single video interview is therefore a signal, not conclusive identity verification.

Why companies were targets

Payroll revenue

DOJ said salaries from U.S. employers generated revenue for workers abroad and benefited North Korea. In one 2023 case, prosecutors said more than 300 companies were involved and more than $6.8 million in revenue was generated for workers outside the United States, including in China and Russia. Those figures apply to that case and should not be combined with totals from other prosecutions.

Access to company systems

A worker hired into a legitimate role may receive accounts, source-code access, cloud permissions, internal communications, customer information, or other sensitive resources. DOJ and the FBI warn that such workers can pose data and network risks. Hiring a fraudulent worker does not, by itself, prove that the employer suffered a data breach or that information was stolen.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Compliance and insider risk

Prosecutors have characterized some schemes as generating revenue for the DPRK government and evading sanctions. That makes the issue relevant to sanctions, export-control, privacy, contractual, and security reviews—not only recruiting. The legal significance depends on the facts of each company’s case and obligations.

How the public cases developed

Date Development What it establishes
June 2023 DOJ announced arrests, charges, seizures, and forfeiture actions tied to remote IT worker schemes. A set of enforcement actions against alleged facilitators and infrastructure; see the DOJ release.
June 2024 Two North Korean nationals and three facilitators were indicted in a related multi-year scheme; the FBI arrested two U.S.-based facilitators and searched a North Carolina residence used as a laptop farm. An indictment is an accusation, not a finding of guilt. See the DOJ announcement.
December 2024 Fourteen North Korean nationals were indicted in a multi-year remote IT worker network involving identities of U.S. and other persons, front companies, and laptop farms. A separate indictment announcement describing prosecutors’ allegations; defendants are presumed innocent unless convicted. See the DOJ release.
February 2025 Christina Marie Chapman pleaded guilty in the District of Columbia to conspiracy to commit wire fraud, aggravated identity theft, and conspiracy to launder monetary instruments. DOJ said her scheme involved 68 U.S. person identities, 309 U.S. businesses, two international businesses, and approximately $17 million in illicit revenue. These are figures for her prosecution, not an overall total. See the DOJ case announcement.
April 2026 Two U.S. nationals were sentenced for facilitating a fraudulent remote IT worker scheme. DOJ said the scheme used at least 80 stolen U.S. identities and generated more than $5 million. This is a separate case total and should not be added to figures above. See the DOJ sentencing announcement.

These developments are related in subject and operating methods, but they are not one prosecution with a single set of defendants or totals. An arrest or indictment is not a conviction; a guilty plea or sentence applies to the person and charges in that case.

Warning signs employers can investigate

The FBI’s guidance on North Korean IT worker threats describes indicators for employers. None is proof on its own. A mismatch should lead to a proportionate review rather than an automatic accusation or termination.

Recruiting and identity checks

  • Compare identity documents with application details and other records; look for alterations, inconsistencies, or signs that documents or profile materials have been reused.
  • Check whether résumé history, professional profiles, claimed location, time zone, language, and interview answers fit together. Treat a discrepancy as a question to resolve, not proof of fraud.
  • Use live, appropriately documented identity checks and consistent hiring procedures. Document-only checks can fail when genuine stolen information is used, while video checks may be vulnerable to impersonation or manipulation.
  • Review whether the person’s interview presence can be verified. A camera or voice issue may have innocent explanations, so follow up through an established process.

Equipment, network, and access

  • Ship equipment only to an address that has been verified under a consistent policy. Investigate requests to redirect devices or use an address unrelated to the worker.
  • Correlate device, network, identity, and access signals. Look for unexplained remote-access tools, VPN or proxy patterns, location conflicts, or connections to multiple workers at the same address.
  • Use least-privilege access, strong authentication, and prompt review of sensitive permissions. Monitor repositories, cloud consoles, secrets stores, and administrative systems as well as the endpoint.
  • Review patterns involving shared phone numbers, payment accounts, recruiters, addresses, or devices, while accounting for legitimate shared housing, staffing arrangements, and managed IT services.

Payroll and third parties

  • Apply consistent checks to payroll changes and payment destinations; investigate unusual or repeated links among workers without assuming that a shared service proves wrongdoing.
  • Set verification responsibilities with staffing agencies, recruiters, and employer-of-record providers, and confirm that their processes match the employer’s requirements.
  • Keep screening proportionate, privacy-conscious, and consistently applied. Document why information is collected, who can access it, and how long it is retained.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to do if a company suspects a fraudulent hire

  1. Preserve evidence. Retain application and employment records, interview recordings, identity materials, shipping and payroll records, communications, endpoint telemetry, VPN logs, and remote-access records. Avoid wiping or reimaging a device before forensic preservation unless incident-response counsel or investigators direct it.
  2. Bring the right teams together. Involve security, HR, legal, privacy, compliance, and relevant executives so the response addresses both access risk and employment records.
  3. Contain access carefully. Disable or suspend accounts as appropriate, revoke active sessions and tokens, rotate credentials and API keys, isolate devices, and review privileged access. Preserve logs before changes where feasible.
  4. Scope potential exposure. Review source-code repositories, cloud accounts, secrets stores, customer data, internal messaging, administrative tools, and any systems reachable from the employee’s account. The absence of malware does not establish that access was harmless.
  5. Contact law enforcement where appropriate. The FBI’s public threat guidance is a starting point for reporting and mitigation. Coordinate communications with counsel and avoid publicly identifying a suspected person before appropriate review.
  6. Assess legal duties. Consider sanctions, export controls, privacy and breach-notification rules, contracts, and regulatory obligations with qualified counsel. These steps are general incident-response guidance, not legal advice.

What the cases do—and do not—show

The public record includes allegations, indictments, guilty pleas, and sentences from different proceedings. Prosecutors’ allegations should not be treated as adjudicated facts for defendants who have not pleaded guilty or been convicted. The cases show that fraudulent hiring and remote operation of U.S.-based equipment can be part of alleged schemes to obtain wages and corporate access; they do not establish that every company identified in an investigation lost data, or that every person whose address or identity appeared knew about the conduct.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Remote work itself is not the problem. The exposure arises when identity, location, equipment, access, and payment checks are treated as separate boxes rather than signals that need to agree. A layered process—combining recruiting verification, controlled equipment delivery, access limits, monitoring, and a careful escalation path—addresses the failure mode without treating every location mismatch as evidence of a crime.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.