Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →On January 23, 2025, the U.S. Department of Justice announced an indictment accusing two North Korean nationals, one Mexican national and two U.S. nationals of running a fraudulent remote-worker operation. Prosecutors allege that the group used stolen identities, U.S.-based “laptop farms,” unauthorized remote-access software and payment intermediaries to make overseas workers appear to be in the United States.
The indictment says the operation obtained work from at least 64 U.S. companies. Payments from 10 of those companies totaled at least $866,255. That figure is alleged revenue from identified payments—not a proven total of every victim’s losses, the value of the entire operation or a finding that every company suffered a data breach.
What the DOJ announced
The case is a federal prosecution in the Southern District of Florida investigated by the FBI Miami Field Office. DOJ’s January 23, 2025 announcement says the alleged conduct ran from approximately April 2018 through August 2024.
Prosecutors say the defendants and unnamed co-conspirators helped North Korean information-technology workers obtain remote jobs with U.S. companies while concealing the workers’ true identities and locations. DOJ described the case as part of its “DPRK RevGen: Domestic Enabler Initiative,” which targets U.S.-based facilitators of North Korean IT-worker activity.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
An indictment is an accusation, not a conviction. Each defendant is presumed innocent unless proven guilty in court.
Who was indicted
| Defendant | Nationality or status | Allegations or case detail |
|---|---|---|
| Jin Sung-Il | North Korean national | Allegedly used another person’s identity to obtain U.S. IT work; also charged in the IEEPA-related conspiracy. |
| Pak Jin-Song | North Korean national | Charged in the alleged worker-fraud and sanctions-evasion conspiracies. |
| Pedro Ernesto Alonso De Los Reyes | Mexican national, described as residing in Sweden | Allegedly permitted use of his identity; arrested in the Netherlands on January 10, 2025. |
| Erick Ntekereze Prince | U.S. national | Allegedly handled laptops, addresses and payments through Taggcar Inc.; later sentenced. |
| Emanuel Ashtor | U.S. national | Allegedly operated a North Carolina residence used as a laptop farm; awaiting trial as of May 6, 2026. |
Names, capitalization and transliterations can vary between the DOJ release and the indictment. The federal case is United States v. Jin Sung-Il et al., Case No. 25-CR-20021-GAYLES/GOODMAN.
How the alleged laptop-farm operation worked
A “laptop farm” is a location—often a residence—where employer-issued computers are physically kept and connected to the internet. A worker elsewhere can control those computers remotely, making network telemetry appear to originate from the United States.
- Identity and applications: The alleged North Korean workers used false or stolen identities, online personas and supporting documents to apply for remote technology jobs.
- Domestic device hosting: U.S.-based facilitators allegedly received company laptops and kept them at residential addresses.
- Remote control: The indictment alleges that unauthorized tools, including AnyDesk and TeamViewer, were installed so workers operating from China and Russia could access the devices.
- Employer deception: Employers allegedly believed the person using the laptop was the identified worker located in the United States.
- Payment routing: Salaries and contractor payments allegedly moved through staffing companies, U.S. businesses, bank accounts and online-payment platforms, with most of the identified proceeds allegedly laundered through a Chinese bank account or related infrastructure.
DOJ alleges, for example, that Jin applied in June 2021 for a U.S. IT position using Alonso’s identity, with Alonso’s consent and an address associated with Prince. The job allegedly paid about $120,000 a year. Prince’s company, Taggcar Inc., allegedly sent eight invoices to a U.S. staffing company totaling approximately $75,709 for work Jin performed while allegedly posing as Alonso. These details come from the indictment and remain allegations.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11A laptop-hosting service or remote-access application is not automatically unlawful. The alleged criminal conduct concerns unauthorized control, identity deception, concealment of the actual worker and associated fraud or sanctions violations.
What the $866,255 figure means
| Amount | What DOJ said it represents |
|---|---|
| At least $866,255 | Revenue from payments by 10 U.S. companies identified in the January 2025 indictment and DOJ announcement. |
| More than $943,069 | Salary payments that a May 6, 2026 DOJ update said victim companies paid to DPRK IT workers associated with the case. |
| More than $1 million | Auditing and remediation costs that the later DOJ update attributed to the defendants’ actions. |
The figures are not interchangeable. They may reflect different accounting categories, evidence developed after the indictment or a broader calculation of payments and harm. The $866,255 amount should not be described as the complete loss suffered by all 64 companies.
Rank #3
Charges and potential penalties
DOJ says all five defendants faced conspiracy charges involving:
- Causing damage to a protected computer;
- Wire fraud and mail fraud;
- Money laundering; and
- Transferring false identification documents.
Jin Sung-Il and Pak Jin-Song also faced a conspiracy charge under the International Emergency Economic Powers Act (IEEPA), the sanctions statute used in the case. The indictment cites, among other provisions, 18 U.S.C. §§ 371, 1349, 1956(h), 1028(a)(2) and (f), 50 U.S.C. § 1705(a) and (c), and 18 U.S.C. § 1030(i). DOJ cited statutory maximums of up to 20 years’ imprisonment for the described charges; actual sentences depend on the counts of conviction, sentencing rules and each defendant’s outcome.
What happened after the indictment
The defendants did not have the same procedural outcome. According to DOJ’s May 6, 2026 update:
Rank #4
- Erick Ntekereze Prince: Sentenced to 18 months in prison, followed by three years of supervised release, and ordered to forfeit $89,000.
- Emanuel Ashtor: Awaiting trial.
- Pedro Ernesto Alonso De Los Reyes: In custody in the Netherlands awaiting extradition.
- Jin Sung-Il and Pak Jin-Song: Described by DOJ as fugitives.
Those statuses are the government’s reported position as of May 6, 2026; court proceedings can change them. Prince’s sentence does not establish that the remaining defendants were convicted.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Why employers and security teams should care
The case shows how employment fraud can become a cybersecurity and national-security problem. A person who obtains legitimate credentials may reach source code, repositories, proprietary documents, credentials or session cookies. The FBI has separately warned that North Korean IT workers may exfiltrate data, conduct cybercrime or extort companies, and that revenue from these operations supports DPRK government priorities. Those broader warnings do not prove that every company in this indictment experienced data theft or extortion.
The operation also demonstrates why a U.S. IP address or a laptop located in the United States does not prove that the person operating it is physically there. Domestic facilitators—who allegedly hosted devices, supplied addresses, installed software or moved money—can be as important to the scheme as the remote worker.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
Employer red flags and practical controls
No single indicator proves North Korean involvement. Security and HR teams should evaluate combinations of identity, device, location and payment evidence without making decisions based on nationality or ethnicity.
Identity and hiring checks
- Match identity documents, tax records, employment history, professional references and payroll information.
- Use strong identity proofing for contractors and remote hires, and confirm that the person interviewed is the person who will work.
- Require staffing vendors to identify the actual worker rather than relying only on an intermediary.
Device and access controls
- Use endpoint detection and response, software allowlisting and application-control policies to block unauthorized remote-administration tools.
- Bind authentication to managed devices, device certificates and hardware-backed credentials.
- Apply conditional access based on device posture and location signals, while recognizing that VPNs, proxies and remote desktops can make IP geolocation unreliable.
- Limit remote control, forwarding and transfer of corporate laptops.
Behavior and vendor monitoring
- Investigate multiple unrelated workers’ devices associated with one residential address, network or handler.
- Review unusual login times, time-zone mismatches, communication patterns, repository downloads, mass file access and session-cookie activity.
- Scrutinize payroll or contractor payments routed through unusual intermediaries.
If identity or location becomes doubtful
- Preserve relevant identity, endpoint, authentication, payroll and vendor records.
- Revoke credentials and isolate the device under the company’s incident-response plan.
- Review repository, cloud and email access for unauthorized downloads or persistence.
- Coordinate with legal counsel, the staffing vendor and appropriate law-enforcement channels.
What remains unresolved
The public record summarized above does not establish the final outcome for every defendant, whether additional co-conspirators or companies will be identified, or the ultimate loss calculation. It also does not establish that each victim company suffered data theft or extortion. Those questions depend on later court filings and evidence.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




