What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Two U.S. nationals who helped overseas IT workers pose as U.S.-based employees were sentenced to federal prison in April 2026. Kejia “Tony” Wang received 108 months and Zhenxing “Danny” Wang received 92 months. Prosecutors said the scheme used more than 80 stolen U.S. identities to place workers at more than 100 U.S. companies and generated more than $5 million for the North Korean government.
The defendants were not North Korean nationals: they were U.S.-based facilitators in a broader network. The case shows how fraudulent remote hiring can expose employers to financial losses, identity theft and unauthorized access to sensitive systems.
Who were the defendants?
Kejia Wang, 42, of Edison, New Jersey, was described by prosecutors as the U.S.-based manager of the operation. He pleaded guilty in September 2025 to conspiracy to commit wire fraud, money laundering and identity theft. Prosecutors said he supervised at least five U.S. facilitators and traveled to Shenyang and Dandong, China, in 2023 to meet overseas participants.
Zhenxing Wang, 39, of New Brunswick, New Jersey, pleaded guilty in January 2026 to conspiracy involving mail and wire fraud and conspiracy to commit money laundering. He hosted employer-issued laptops at his residence and helped overseas workers connect to them remotely. The two men were part of a wider network; the case does not establish that they were the only people operating laptop farms or recruiting workers. The Justice Department’s sentencing announcement describes their roles and pleas.
#1 Best Overall
How did the laptop-farm scheme work?
A “laptop farm” is a physical location, often a private home, where multiple employer-issued computers are kept. A company could ship a laptop to what it believed was the employee’s U.S. address, while the person hired used remote access to operate that machine from overseas. Prosecutors said facilitators used keyboard-video-mouse (KVM) switches and other remote-access methods to support this arrangement.
The setup helped make the device and its network connection appear to be in the United States, even when the worker was elsewhere. The alleged fraud was not simply the use of remote-access technology: it involved deception about identity and work location, stolen identities, and support for workers linked to a sanctioned North Korean revenue operation. A legitimate employee or IT administrator using remote access is not, by itself, evidence of a laptop farm.
The employment pipeline
- Stolen or compromised U.S. identities were used to create or support worker personas.
- Overseas IT workers applied for remote jobs while claiming to be U.S.-based; facilitators helped with hiring and onboarding processes using false information.
- Employers shipped computers and other equipment to U.S. residences hosting the devices.
- Remote-access arrangements let overseas workers perform work through the U.S.-located computers.
- Shell companies and U.S. financial accounts helped disguise affiliations and receive or transfer earnings.
- In at least one instance, a worker accessed company files that included ITAR-controlled technical information.
These steps implicate different risks: employment fraud to obtain jobs, identity theft to impersonate U.S. people, money laundering or sanctions evasion to move proceeds, and possible cyber or data harm through unauthorized access to employer systems.
How large was the operation?
According to the Justice Department, the Wang-linked operation ran approximately from 2021 through October 2024. Prosecutors said it used more than 80 U.S. identities and helped overseas workers obtain jobs at more than 100 U.S. companies, including Fortune 500 companies and a California defense contractor.
Rank #3
| Figure | What it describes |
|---|---|
| More than $5 million | Revenue prosecutors said the scheme generated for the DPRK government; this is not the same as company losses or facilitator payments. |
| At least $3 million | Victim-company losses and remediation costs, including legal fees and network remediation, according to prosecutors. |
| Nearly $700,000 | Payments to six U.S.-based facilitators in the cell, according to the Justice Department’s coordinated-action announcement. |
| $600,000 | Combined forfeiture ordered for the two defendants; the Justice Department said $400,000 had been received by its April 15, 2026 announcement. |
The amounts measure different things and should not be added together as though they were one category of loss. During the investigation, authorities searched eight locations in three states in October 2024 and recovered more than 70 laptops and remote-access devices. In June 2025, authorities announced seizures involving 17 web domains and 29 financial accounts. The Justice Department’s account of those coordinated actions provides the seizure and loss figures.
What information and systems were at risk?
The case involved access to employer laptops, internal company systems, sensitive data and source code. The most specific publicly described example concerns a California-based defense contractor developing AI-powered equipment and technologies. Prosecutors said an overseas co-conspirator accessed a company laptop and files containing technical data, including ITAR-marked information, from January 19 to April 2, 2024.
Rank #4
Access is not the same as confirmed copying or exfiltration. The public account establishes that sensitive information was accessed in at least one case; it does not establish that every affected company suffered a network intrusion or that military secrets were stolen. The Justice Department characterized the conduct as a threat to national and economic security, but that is not proof of a broader intelligence operation.
What sentences and financial orders did the court impose?
| Defendant | Prison sentence | Supervised release | Other reported order |
|---|---|---|---|
| Kejia Wang | 108 months (nine years) | 3 years | $29,236.03 restitution, reported by the Justice Department’s Office of Public Affairs |
| Zhenxing Wang | 92 months | 3 years | $200,000 restitution, reported by the U.S. Attorney’s Office for the District of Massachusetts |
The two men were also ordered to forfeit $600,000 combined. The Justice Department reported that the United States had received $400,000 by April 15, 2026. The separate restitution amounts come from different Justice Department announcements; they should not be combined into a single total without consulting the sentencing judgments. The District of Massachusetts announcement gives Zhenxing Wang’s sentence and restitution figure.
Best Value
What happened to the rest of the network?
The prosecution was part of a broader case involving overseas co-conspirators and other U.S. facilitators. The Justice Department’s April 2026 announcement said nine other individuals indicted in connection with the scheme remained at large, according to contemporaneous reporting. An indictment is an accusation, not a conviction, and the status of those individuals may change. SecurityWeek’s report on the sentences describes the reported number still at large.
The Wang case also sits within a wider federal effort to disrupt DPRK-linked remote-worker networks and prosecute U.S.-based enablers. The Justice Department described these sentences as the seventh and eighth U.S.-based laptop-farm sentences secured in five months. Enforcement has included searches, arrests and indictments, as well as domain and financial-account seizures. The Justice Department’s enforcement announcement provides context on that broader effort.
What can employers do to reduce the risk?
No single check can prove who is actually doing remote work, and risk-reduction controls are not guarantees. The Justice Department urged organizations to monitor data, strengthen remote-hiring processes and report suspicious activity. Practical measures include:
- Recruiting and onboarding: Verify that the person interviewed is the same person completing identity and tax onboarding. Review inconsistent identity details, duplicated résumés and recycled employment histories as risk signals—not as proof of misconduct.
- Identity and location assurance: Compare identity, shipping, payroll, device and network-location information. Use appropriate in-person or trusted third-party verification for sensitive roles. Do not treat nationality, accent, a VPN, or an unusual IP address as proof of fraud.
- Device custody: Track where employer hardware is shipped and who has physical custody. Use device-management controls to identify unusual remote-access software or hardware, including unauthorized peripherals.
- Access limits and monitoring: Give new hires only the access needed at first, then expand privileges as appropriate. Monitor unusual login geography, simultaneous sessions, impossible-travel alerts and unexpected remote-desktop activity.
- Extra controls for sensitive work: Apply stronger review to roles involving source code, defense-related data, financial systems, cryptocurrency or production credentials. A foreign employee lawfully working outside the United States is not equivalent to a fraudulent scheme.
- Response readiness: Have a process to suspend access and offboard quickly if identity or work location is credibly questioned. Preserve devices, logs, shipping and payment records, and onboarding evidence; report suspected fraud to the FBI.
These controls should focus on identity assurance, authorization, device custody and observable behavior—not nationality profiling. The case also does not establish that generative AI or deepfakes were used; AI-assisted interview fraud is a separate risk discussed in Okta’s threat-intelligence analysis, not a proven feature of this prosecution.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Quick Recap
What remains unclear from the public account?
- The Justice Department named categories of victims, including a defense contractor, but its public sentencing announcement does not identify every affected company.
- It reports access to sensitive files, including ITAR-controlled information in at least one case, but does not establish the full extent of any copying or exfiltration.
- The precise roles of each overseas participant and the eventual status of those still at large are not fully resolved in the sentencing announcements.
- The reported restitution figures differ between Justice Department releases; the sentencing orders would be needed to establish the complete financial picture.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




