What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
On November 4, 2025, the U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) sanctioned eight individuals and two entities that Treasury said helped move or manage money connected to North Korean cybercrime, cryptocurrency theft, sanctions evasion and fraudulent overseas IT-worker operations.
The action targeted more than hackers or fake employees. It focused on alleged financial enablers—including bankers, overseas representatives, an IT company and a North Korean bank—that helped transfer, disguise or remit proceeds. Treasury said the revenue ultimately supported the North Korean government and its weapons programs.
The announcement was made in 2025, not August 2026. The designations are administrative sanctions, not criminal convictions. Treasury’s allegations should be distinguished from separate Justice Department indictments, guilty pleas, seizures and convictions.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Who OFAC sanctioned
Treasury identified eight people and two organizations in the November 4, 2025 action. The targets fell into three connected groups: bankers linked to First Credit Bank, personnel and a company involved in North Korean IT-worker operations, and representatives associated with Ryujong Credit Bank and other North Korean financial institutions.
#1 Best Overall
| Target | Affiliation | Treasury’s stated allegation |
|---|---|---|
| Jang Kuk Chol | First Credit Bank | Helped manage funds for the bank, including cryptocurrency connected to North Korean cybercrime and IT-worker revenue. |
| Ho Jong Son | First Credit Bank | Helped manage similar funds, including approximately $5.3 million in cryptocurrency. |
| Korea Mangyongdae Computer Technology Company (KMCTC) | North Korean IT company | Operated IT-worker delegations from at least Shenyang and Dandong, China, and allegedly used Chinese nationals as banking proxies. |
| U Yong Su | President of KMCTC | Identified by Treasury as the company’s president. |
| Ryujong Credit Bank | North Korean financial institution | Allegedly supported sanctions evasion, foreign-currency remittances, money laundering and transactions for overseas North Korean workers. |
| Ho Yong Chol | North Korean representative in China or Russia | Treasury attributed more than $2.5 million in transfers for Korea Daesong Bank and more than $85 million in transactions for another DPRK-affiliated group. |
| Han Hong Gil | North Korean representative | Allegedly coordinated more than $630,000 in transactions for Ryugyong Commercial Bank. |
| Jong Sung Hyok | North Korean representative | Named among representatives who facilitated transactions for North Korean financial institutions. |
| Choe Chun Pom | North Korean representative | Treasury attributed more than $200,000 in transactions for the DPRK Central Bank. |
| Ri Jin Hyok | North Korean representative | Allegedly handled more than $350,000 for a Foreign Trade Bank front company. |
The names, affiliations and transaction figures come from Treasury’s designation announcement. The release describes alleged conduct; it does not establish that every individual was criminally convicted.
How the alleged money network worked
The sanctions make more sense as an ecosystem than as an isolated banking case. According to Treasury and related Justice Department cases, the alleged revenue chain could include several layers:
- Cybercrime generates money. North Korea-linked actors steal cryptocurrency, conduct ransomware attacks or use other cyber-enabled schemes.
- Remote workers generate apparently legitimate income. North Korean IT workers obtain jobs or contracts using false, stolen or borrowed identities. Employers may pay them through payroll systems, freelance platforms, payment providers or cryptocurrency.
- U.S. intermediaries conceal the workers’ locations. In some Justice Department cases, facilitators hosted employer-issued laptops in U.S. homes and installed remote-access software so workers overseas appeared to be working domestically.
- Intermediaries move the proceeds. Funds may pass through proxy account holders, front companies, Chinese or Russian accounts, cryptocurrency wallets and financial representatives.
- North Korean financial institutions handle remittances. Bank representatives and affiliated institutions allegedly transfer, convert or disguise the money before it is remitted for the benefit of North Korea.
OFAC’s November 2025 action concentrated on the banking and financial-enablement layer. DOJ prosecutions and forfeiture cases provide additional detail about the employment-fraud and cryptocurrency-laundering layers.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesWhy IT-worker fraud is more than a hiring deception
The alleged schemes are not simply cases of a remote worker misrepresenting a home address. U.S. authorities have described a state-linked revenue model involving:
- Stolen U.S. identities and identity documents.
- False résumés, pseudonymous accounts and fake contracting companies.
- Business websites with misleading or fabricated information.
- U.S.-based “laptop farms” that receive and operate employer equipment.
- Intermediaries who attend interviews or meetings for the real worker.
- Virtual private networks and unauthorized remote-access software.
- Access to proprietary systems, source code and sensitive company data.
- Extortion demands when companies refuse to pay.
In a 2024 indictment, the Justice Department alleged that 14 North Korean nationals used false identities to obtain remote IT work and generated at least $88 million over approximately six years. The indictment also alleged source-code theft and threats to release proprietary information unless companies paid.
Those allegations concern a separate criminal case, not proof that every person involved in the OFAC designation participated in the same conduct.
The cryptocurrency and ransomware connection
Treasury said Jang Kuk Chol and Ho Jong Son helped manage funds for First Credit Bank, including approximately $5.3 million in cryptocurrency. The agency said some of the funds were linked to a North Korean ransomware actor that targeted U.S. victims and handled revenue from North Korean IT workers.
Recommended Free Tools
Treasury also said North Korea-affiliated cybercriminals had stolen more than $3 billion, primarily in cryptocurrency, during the preceding three years. That is Treasury’s attributed estimate, not a universally accepted independent total.
Related DOJ materials describe laundering methods such as splitting funds into smaller transfers, moving assets between blockchains, swapping tokens, buying NFTs, using U.S.-based accounts and commingling proceeds. Blockchain records can make transactions visible, but visibility does not by itself reveal who controls a wallet or whether a transaction is sanctioned. Conversely, chain-hopping or cryptocurrency use alone does not prove North Korean involvement.
What the sanctions legally mean
OFAC designations generally have immediate consequences for U.S.-linked property and transactions:
Rank #3
- Property and interests in property belonging to designated people or entities that are in the United States, or within the possession or control of U.S. persons, are blocked.
- U.S. persons generally may not transact with designated targets unless OFAC has authorized the activity.
- U.S. financial institutions generally must block covered property and comply with applicable reporting obligations.
- Entities owned directly or indirectly, individually or in aggregate, at least 50% by one or more blocked persons are generally treated as blocked under OFAC’s 50 Percent Rule.
The 50 Percent Rule does not mean that every affiliate, business partner or company associated with a designated person is automatically blocked. Ownership, control and the specific transaction must be assessed under the applicable sanctions rules.
Free tools Windows power users keep installed
One-click scans. No signup required.
Sanctions also do not automatically remove every overseas account or prevent all activity in non-U.S. financial systems. Their effect is strongest where U.S. persons, U.S. financial institutions, U.S. dollar clearing, U.S.-located property or other U.S. connections are involved. Non-U.S. parties can nevertheless face sanctions or enforcement risk for prohibited dealings.
How this fits the wider U.S. crackdown
The Treasury action was part of a broader U.S. campaign against North Korean cybercrime, fraudulent remote employment and the financial networks supporting them.
In a 2025 nationwide enforcement action, the Justice Department announced five guilty pleas and more than $15 million in virtual-currency forfeiture actions. DOJ said the schemes affected more than 136 U.S. companies and generated more than $2.2 million for the North Korean regime. A forfeiture action is a legal process seeking government ownership of assets; a seizure or restraint is not the same as a final forfeiture or a return to victims.
In another case, DOJ announced a civil forfeiture complaint involving more than $7.74 million frozen and seized in connection with North Korean IT-worker proceeds and Foreign Trade Bank representative Sim Hyon Sop. The government’s action sought forfeiture of the assets.
Rank #4
In April 2026, DOJ announced prison sentences for two U.S. nationals accused of facilitating fraudulent remote IT-worker operations. That announcement said more than 100 U.S. companies were affected, identities of more than 80 U.S. persons were compromised and at least $3 million in victim-company damages were alleged.
These cases show why U.S. authorities are pursuing domestic facilitators as well as overseas operators. A worker located abroad may need a U.S.-based person to receive a laptop, maintain an address, pass hiring checks or make the activity appear normal.
What banks and financial institutions should watch for
A name-screening match is important, but it is not the only compliance issue. Institutions assessing potential exposure may need to consider:
- Direct and indirect ownership of customers and counterparties.
- Aliases, transliteration differences and inconsistent identity records.
- Connections to North Korea, China, Russia or known North Korean financial representatives.
- Payments involving designated banks, front companies or cryptocurrency addresses.
- Transactions inconsistent with the customer’s stated business or source of funds.
- Repeated small transfers, rapid movement across blockchains, token swaps or commingling.
- Payments that appear connected to overseas IT-worker payrolls or proxy account holders.
No single indicator proves North Korean involvement. Institutions should apply their risk-based controls, investigate unusual activity and follow OFAC requirements rather than treating nationality, remote work or cryptocurrency use as conclusive evidence.
What employers should check
Employers hiring remote technical workers face both sanctions risk and ordinary cybersecurity risk. DOJ materials have identified warning signs including:
Best Value
- A worker’s claimed location conflicts with technical, logistical or identity evidence.
- A third party appears for an interview, meeting or work task.
- The worker asks for company equipment to be shipped to an unrelated U.S. residence.
- Several workers are connected to one residential address.
- Identity documents, résumé details, online history and location data do not align.
- Remote-access software is installed without authorization.
- A contractor’s website has implausible addresses, mismatched phone-area codes or copied and nonsensical text.
- The worker seeks privileged access before identity and location checks are complete.
These are risk indicators, not proof of criminality. A sensible response is additional verification: confirm identity through independent channels, validate the worker’s location, restrict initial access, use company-managed devices and monitor for unauthorized software or unusual data transfers. Employers should avoid automatically rejecting people because they are foreign nationals, work remotely or use a residential address.
What crypto companies should consider
For exchanges, custodians, payment providers and other crypto businesses, the relevant question is broader than whether a wallet appears on a sanctions list. Risk reviews may need to account for:
- Fictitious or stolen identities.
- Funds divided into many smaller transfers.
- Movement between multiple blockchains.
- Token swaps and NFT purchases used to obscure or store value.
- U.S.-based accounts that make activity appear legitimate.
- Commingling of suspected proceeds with other customer funds.
Businesses should use applicable sanctions-screening, transaction-monitoring and customer-verification controls and document how alerts are resolved. A transaction pattern may warrant investigation without proving illicit activity; the absence of an obvious wallet match does not eliminate attribution or sanctions risk.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →What remains uncertain
Treasury’s public announcement does not describe the complete global network, establish the full amount handled by each individual or quantify how much of any particular transaction directly funded a weapons program. The release attributes conduct to the designated people and entities, but sanctions designations and criminal cases have different legal standards and procedural statuses.
The safest reading is therefore precise: OFAC said these targets helped facilitate or manage money associated with North Korean cybercrime, sanctions evasion and fraudulent IT-worker operations. Separate DOJ cases show how identity theft, laptop farms, remote access, cryptocurrency laundering and U.S. facilitators can connect to that broader revenue system.
Why the action matters
The central development was the targeting of the financial infrastructure behind North Korea’s cyber and IT-worker revenue schemes. By designating bankers, representatives, an IT company and a bank, Treasury sought to disrupt the bridge between stolen cryptocurrency or apparently ordinary wages and the North Korean institutions that receive and move the money.
For banks, crypto businesses and employers, the lesson is practical: sanctions compliance cannot rely only on a single-name search. Ownership, identity, location, payment behavior, device access and intermediary relationships can all matter. At the same time, risk indicators must be investigated carefully rather than treated as automatic proof of wrongdoing.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

