October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

U.S. DOJ Cracks Down on North Korean IT Workers Targeting U.S. Employers

DOJ has announced charges, indictments, guilty pleas and forfeiture actions over North Korean remote IT worker schemes that used false identities and laptop farms to win U.S. jobs. Here is what each release says, and how to read its figures.
From TheFinanceBase Team6 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Between May 2024 and November 2025, the U.S. Department of Justice (DOJ) announced charges, indictments, guilty pleas and civil forfeiture actions in cases alleging that North Korean nationals and their facilitators used false identities and concealed locations to win remote information technology (IT) jobs at American companies. DOJ says the work generated revenue for the Democratic People’s Republic of Korea (DPRK), and that some workers went on to steal data or extort the employers they had joined.

These cases are U.S.-focused. The company counts below are the figures DOJ reported in its own releases for the actions each release describes. They are not a worldwide total, and they should not be added together.

What DOJ announced

Four DOJ releases make up the public record for this enforcement push. They differ in what stage each case had reached, so the table separates the reported figures from the procedural status.

Date DOJ announcement What the release reports Status described
May 16, 2024 Charges and seizures in a fraud scheme aimed at denying revenue to workers associated with North Korea Overseas workers allegedly posed as U.S. citizens or residents. DOJ reported that IT workers had infiltrated more than 300 U.S. companies, a figure tied to the actions in this release. Charges and seizures
December 12, 2024 Fourteen North Korean nationals indicted for a multi-year fraudulent IT worker scheme and related extortions The alleged scheme used false, stolen or borrowed identities to conceal nationality and location, along with pseudonymous online accounts, proxy systems and third parties. The stated objective was obtaining remote IT jobs and generating revenue for the DPRK. Indictment, which contains allegations
January 23, 2025 Two North Korean nationals and three facilitators indicted for a multi-year fraudulent remote IT worker scheme Five defendants and co-conspirators allegedly obtained work from at least 64 U.S. companies between approximately April 2018 and August 2024. Methods alleged include forged or stolen identity documents, remote-access software on employer-provided laptops hosted at facilitators’ homes, and laundering of payments. Indictment, which contains allegations
November 14, 2025 Justice Department nationwide actions to combat illicit North Korean government revenue generation Five guilty pleas and more than $15 million in civil forfeiture actions involving DPRK remote IT work and virtual-currency schemes. DOJ says facilitators provided identities and hosted company-issued laptops at U.S. residences, and that remote workers posing as legitimate employees committed data extortion and exfiltrated proprietary and sensitive company data. Five guilty pleas in the cases specified; civil forfeiture actions

Allegations, guilty pleas and forfeitures are different things

Reading these announcements accurately depends on keeping three categories apart.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Cybersecurity Word Cloud Hacker Computer Coders Programmer Hardcover Journal, Black
  • Cybersecurity.
  • This merchandise, which shows a computer cybersecurity word cloud design, is ideal for computer programmers, coders, and hackers. It is also for software engineer or software developers, as well as information technology or computer science majors.
  • Hardcover journal with 240 line-ruled pages (120 sheets)
  • Built-in elastic closure and ribbon bookmark
  • Includes an expandable inner storage pocket and a pen holder
  • Indictments are allegations. The December 2024 and January 2025 figures describe what prosecutors say the defendants and co-conspirators did. Nothing in those releases establishes that the allegations were proven in court.
  • Guilty pleas are admissions in the specified cases. The five pleas announced in November 2025 apply to those defendants and cases. They do not extend to the 14 people in the December 2024 indictment or to the companies named in other releases.
  • Civil forfeiture actions are separate proceedings. The more than $15 million in the November 2025 release refers to forfeiture actions tied to DPRK remote IT work and virtual-currency schemes. They are not criminal convictions, and they should not be read as a measure of the harm to employers.

The company counts also come from different releases and different case groupings. The 300-plus figure from May 2024 and the at-least-64 figure from January 2025 should be reported separately, with each attributed to DOJ and the release that contains it.

How the alleged scheme worked

Across the releases, DOJ describes a repeatable set of tactics. These are allegations drawn from the indictments and announcements, not findings about any particular employer.

  • False identity. Workers allegedly used forged, stolen or borrowed identity documents to appear as U.S. citizens or residents, or as someone other than a North Korean national.
  • Concealed location. Proxy systems and third parties allegedly hid where the worker actually was, so that a company could believe it was hiring a domestic contractor.
  • Pseudonymous accounts. Online accounts used in job applications and communications were allegedly registered under names that did not match the person doing the work.
  • Employer-issued devices at U.S. addresses. Facilitators allegedly received company laptops, installed remote-access software and hosted the equipment at their homes, so that logins and activity appeared to come from the United States.
  • Payment laundering. DOJ’s January 2025 announcement says the scheme also involved laundering the proceeds of the work.
  • Data theft and extortion. The November 2025 release states that some workers exfiltrated proprietary and sensitive company data and committed data extortion. The December 2024 release’s title refers to related extortions.

What a laptop farm is

A laptop farm, in the way DOJ uses the term in these cases, is a U.S.-based setup of computers and a facilitator who receives, configures and hosts employer-issued equipment. The arrangement lets an overseas worker connect remotely while the company’s systems show a U.S. device in a U.S. home. The laptops are the physical link between the remote worker’s activity and a domestic address, which is why facilitators are central to the cases described above.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why employers were exposed

DOJ frames the harm in three ways. The first is sanctions and revenue: the alleged work generated money for the DPRK, and the November 2025 release says it tricked U.S. companies into funding the regime’s priorities. The second is data security: workers with legitimate access allegedly took proprietary information. The third is extortion: in some matters, DOJ says workers threatened the employers they had deceived. A company that hires a remote contractor it cannot verify faces all three risks at once.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What officials said

In the November 2025 release, Supervisory Official Devin DeBacker of DOJ’s National Security Division said: “The Department of Justice remains committed to disrupting North Korea’s cyber-enabled sanctions-evading schemes, which seek to trick U.S. companies into funding the North Korean regime’s priorities, including its weapons programs.”

In the January 2025 release, FBI Assistant Director Bryan Vorndran of the Cyber Division said: “FBI investigation has uncovered a years-long plot to install North Korean IT workers as remote employees to generate revenue for the DPRK regime and evade sanctions.”

Checks employers can consider

The releases describe what the alleged workers did. They do not prescribe a control set, and the measures below are practical responses to those tactics rather than DOJ recommendations or endorsements of any product.

Identity and location verification

  • Confirm identity against government-issued documents during onboarding, and check that the documents match the name on payroll and tax forms.
  • Ask for a live video verification at hiring and at key points afterward, so that the person on the call is the person being paid.
  • Treat a mismatch in the stated location, such as a contractor whose devices only ever connect from a single foreign-linked network, as a reason to look more closely.

Access and device management

  • Limit what a new remote contractor can reach on day one, and expand access only after the role and identity have been checked.
  • Do not let contractors install remote-access tools on company devices without approval, and review which tools are present on each laptop.
  • Track where company devices are shipped and who receives them, especially where a third party handles equipment for remote staff.

Endpoint monitoring and trade-offs

  • Log logins, location signals and data transfers, and set alerts for unusual patterns such as logins from unexpected places or large exports of data.
  • Expect false positives. Legitimate travelers, employees using VPNs and people working irregular hours will trigger alerts, so define a review process before a control goes live.
  • Weigh privacy obligations. Monitoring that captures personal activity needs a clear written policy and an employee notice, and the scope should match the security purpose.

What remains unestablished

The releases cited here date from May 2024 to November 2025 and describe the status of each case as of its announcement. They do not establish how each criminal proceeding has since developed, whether every named defendant has been sentenced, or how much of each forfeiture action has been completed. Readers who need the current status of a specific case should check the relevant federal court docket and any later DOJ release on the same matter.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

Bestseller No. 1
Cybersecurity Word Cloud Hacker Computer Coders Programmer Hardcover Journal, Black
Cybersecurity Word Cloud Hacker Computer Coders Programmer Hardcover Journal, Black
Cybersecurity.; Hardcover journal with 240 line-ruled pages (120 sheets); Built-in elastic closure and ribbon bookmark
$16.99

“

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.