October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

DOJ Indicts Five in Alleged $866,255 North Korean IT-Worker Scheme

The DOJ alleged that five defendants helped North Korean IT workers obtain jobs at at least 64 U.S. companies using stolen identities, U.S.-based laptop farms and concealed remote access. Payments from 10 companies totaled at least $866,255, while later DOJ figures cited more than $943,069 in salaries and over $1 million in remediation costs.
From TheFinanceBase Team6 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

On January 23, 2025, the U.S. Department of Justice announced an indictment accusing two North Korean nationals, one Mexican national and two U.S. nationals of running a fraudulent remote-worker operation. Prosecutors allege that the group used stolen identities, U.S.-based “laptop farms,” unauthorized remote-access software and payment intermediaries to make overseas workers appear to be in the United States.

The indictment says the operation obtained work from at least 64 U.S. companies. Payments from 10 of those companies totaled at least $866,255. That figure is alleged revenue from identified payments—not a proven total of every victim’s losses, the value of the entire operation or a finding that every company suffered a data breach.

What the DOJ announced

The case is a federal prosecution in the Southern District of Florida investigated by the FBI Miami Field Office. DOJ’s January 23, 2025 announcement says the alleged conduct ran from approximately April 2018 through August 2024.

Prosecutors say the defendants and unnamed co-conspirators helped North Korean information-technology workers obtain remote jobs with U.S. companies while concealing the workers’ true identities and locations. DOJ described the case as part of its “DPRK RevGen: Domestic Enabler Initiative,” which targets U.S.-based facilitators of North Korean IT-worker activity.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

An indictment is an accusation, not a conviction. Each defendant is presumed innocent unless proven guilty in court.

Who was indicted

Defendant Nationality or status Allegations or case detail
Jin Sung-Il North Korean national Allegedly used another person’s identity to obtain U.S. IT work; also charged in the IEEPA-related conspiracy.
Pak Jin-Song North Korean national Charged in the alleged worker-fraud and sanctions-evasion conspiracies.
Pedro Ernesto Alonso De Los Reyes Mexican national, described as residing in Sweden Allegedly permitted use of his identity; arrested in the Netherlands on January 10, 2025.
Erick Ntekereze Prince U.S. national Allegedly handled laptops, addresses and payments through Taggcar Inc.; later sentenced.
Emanuel Ashtor U.S. national Allegedly operated a North Carolina residence used as a laptop farm; awaiting trial as of May 6, 2026.

Names, capitalization and transliterations can vary between the DOJ release and the indictment. The federal case is United States v. Jin Sung-Il et al., Case No. 25-CR-20021-GAYLES/GOODMAN.

How the alleged laptop-farm operation worked

A “laptop farm” is a location—often a residence—where employer-issued computers are physically kept and connected to the internet. A worker elsewhere can control those computers remotely, making network telemetry appear to originate from the United States.

  1. Identity and applications: The alleged North Korean workers used false or stolen identities, online personas and supporting documents to apply for remote technology jobs.
  2. Domestic device hosting: U.S.-based facilitators allegedly received company laptops and kept them at residential addresses.
  3. Remote control: The indictment alleges that unauthorized tools, including AnyDesk and TeamViewer, were installed so workers operating from China and Russia could access the devices.
  4. Employer deception: Employers allegedly believed the person using the laptop was the identified worker located in the United States.
  5. Payment routing: Salaries and contractor payments allegedly moved through staffing companies, U.S. businesses, bank accounts and online-payment platforms, with most of the identified proceeds allegedly laundered through a Chinese bank account or related infrastructure.

DOJ alleges, for example, that Jin applied in June 2021 for a U.S. IT position using Alonso’s identity, with Alonso’s consent and an address associated with Prince. The job allegedly paid about $120,000 a year. Prince’s company, Taggcar Inc., allegedly sent eight invoices to a U.S. staffing company totaling approximately $75,709 for work Jin performed while allegedly posing as Alonso. These details come from the indictment and remain allegations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A laptop-hosting service or remote-access application is not automatically unlawful. The alleged criminal conduct concerns unauthorized control, identity deception, concealment of the actual worker and associated fraud or sanctions violations.

What the $866,255 figure means

Amount What DOJ said it represents
At least $866,255 Revenue from payments by 10 U.S. companies identified in the January 2025 indictment and DOJ announcement.
More than $943,069 Salary payments that a May 6, 2026 DOJ update said victim companies paid to DPRK IT workers associated with the case.
More than $1 million Auditing and remediation costs that the later DOJ update attributed to the defendants’ actions.

The figures are not interchangeable. They may reflect different accounting categories, evidence developed after the indictment or a broader calculation of payments and harm. The $866,255 amount should not be described as the complete loss suffered by all 64 companies.

Charges and potential penalties

DOJ says all five defendants faced conspiracy charges involving:

  • Causing damage to a protected computer;
  • Wire fraud and mail fraud;
  • Money laundering; and
  • Transferring false identification documents.

Jin Sung-Il and Pak Jin-Song also faced a conspiracy charge under the International Emergency Economic Powers Act (IEEPA), the sanctions statute used in the case. The indictment cites, among other provisions, 18 U.S.C. §§ 371, 1349, 1956(h), 1028(a)(2) and (f), 50 U.S.C. § 1705(a) and (c), and 18 U.S.C. § 1030(i). DOJ cited statutory maximums of up to 20 years’ imprisonment for the described charges; actual sentences depend on the counts of conviction, sentencing rules and each defendant’s outcome.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What happened after the indictment

The defendants did not have the same procedural outcome. According to DOJ’s May 6, 2026 update:

  • Erick Ntekereze Prince: Sentenced to 18 months in prison, followed by three years of supervised release, and ordered to forfeit $89,000.
  • Emanuel Ashtor: Awaiting trial.
  • Pedro Ernesto Alonso De Los Reyes: In custody in the Netherlands awaiting extradition.
  • Jin Sung-Il and Pak Jin-Song: Described by DOJ as fugitives.

Those statuses are the government’s reported position as of May 6, 2026; court proceedings can change them. Prince’s sentence does not establish that the remaining defendants were convicted.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why employers and security teams should care

The case shows how employment fraud can become a cybersecurity and national-security problem. A person who obtains legitimate credentials may reach source code, repositories, proprietary documents, credentials or session cookies. The FBI has separately warned that North Korean IT workers may exfiltrate data, conduct cybercrime or extort companies, and that revenue from these operations supports DPRK government priorities. Those broader warnings do not prove that every company in this indictment experienced data theft or extortion.

The operation also demonstrates why a U.S. IP address or a laptop located in the United States does not prove that the person operating it is physically there. Domestic facilitators—who allegedly hosted devices, supplied addresses, installed software or moved money—can be as important to the scheme as the remote worker.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Employer red flags and practical controls

No single indicator proves North Korean involvement. Security and HR teams should evaluate combinations of identity, device, location and payment evidence without making decisions based on nationality or ethnicity.

Identity and hiring checks

  • Match identity documents, tax records, employment history, professional references and payroll information.
  • Use strong identity proofing for contractors and remote hires, and confirm that the person interviewed is the person who will work.
  • Require staffing vendors to identify the actual worker rather than relying only on an intermediary.

Device and access controls

  • Use endpoint detection and response, software allowlisting and application-control policies to block unauthorized remote-administration tools.
  • Bind authentication to managed devices, device certificates and hardware-backed credentials.
  • Apply conditional access based on device posture and location signals, while recognizing that VPNs, proxies and remote desktops can make IP geolocation unreliable.
  • Limit remote control, forwarding and transfer of corporate laptops.

Behavior and vendor monitoring

  • Investigate multiple unrelated workers’ devices associated with one residential address, network or handler.
  • Review unusual login times, time-zone mismatches, communication patterns, repository downloads, mass file access and session-cookie activity.
  • Scrutinize payroll or contractor payments routed through unusual intermediaries.

If identity or location becomes doubtful

  1. Preserve relevant identity, endpoint, authentication, payroll and vendor records.
  2. Revoke credentials and isolate the device under the company’s incident-response plan.
  3. Review repository, cloud and email access for unauthorized downloads or persistence.
  4. Coordinate with legal counsel, the staffing vendor and appropriate law-enforcement channels.

What remains unresolved

The public record summarized above does not establish the final outcome for every defendant, whether additional co-conspirators or companies will be identified, or the ultimate loss calculation. It also does not establish that each victim company suffered data theft or extortion. Those questions depend on later court filings and evidence.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.