October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

U.S. Sanctions North Korean Companies and Individuals Over Cybercrime and IT-Worker Money Laundering

The November 2025 U.S. sanctions targeted eight people and two entities Treasury linked to laundering North Korean cybercrime and IT-worker proceeds. Here’s how the schemes work and what changed in March 2026.
From TheFinanceBase Team7 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

On November 4, 2025, the U.S. Treasury Department announced sanctions against eight individuals and two entities it said helped launder proceeds linked to North Korean cybercrime, cryptocurrency theft, fraudulent overseas IT work and sanctions evasion. The central company targets were Korea Mangyongdae Computer Technology Company and Ryujong Credit Bank. A separate action on March 12, 2026, targeted another six people and two entities tied to North Korean IT-worker fraud, showing that the enforcement effort continued beyond the November designations.

What the November 2025 sanctions targeted

The Office of Foreign Assets Control (OFAC), part of the U.S. Treasury Department, designated eight people and two entities on November 4, 2025. Treasury said the targets played roles in moving or disguising money connected to North Korean cybercrime, cryptocurrency theft and overseas IT-worker schemes. It said the proceeds support the Democratic People’s Republic of Korea (DPRK) regime and are linked to funding its weapons programs. The designations were made under U.S. North Korea-related authorities, including Executive Order 13810. Treasury’s announcement describes the action; OFAC’s designation notice is the reference for the full official listing.

The two named entities

  • Korea Mangyongdae Computer Technology Company (KMCTC): Treasury described it as a North Korean IT company operating worker delegations from at least Shenyang and Dandong, China. It said workers used Chinese nationals as banking proxies to obscure the origin of revenue. Treasury identified U Yong Su as the company’s current president.
  • Ryujong Credit Bank: Treasury said the North Korean financial institution provided financial assistance for sanctions avoidance between China and North Korea. Its stated activities included remitting foreign-currency earnings, laundering money and processing transactions for overseas North Korean workers.

The November announcement’s eight individuals were connected, according to OFAC, to financial institutions and IT-worker networks including the Central Bank of the DPRK, Korea Daesong Bank, the Foreign Trade Bank of the DPRK and KMCTC. For their exact names, aliases and other identifiers, consult the OFAC notice; those details should be checked against the live sanctions list before a financial or hiring decision.

How fraudulent IT work and money laundering fit together

These schemes are not simply cases of a worker using a false résumé. U.S. authorities describe state-supported operations in which people seek remote jobs under stolen or fabricated identities, false nationality or location claims, and misleading employment histories. They may use alias email addresses, social-media profiles and freelance-platform accounts, while facilitators help with recruitment, devices, payments or access.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A worker may do ordinary software-development work after being hired. The employer-side risk comes from paying a person whose identity or location was misrepresented, potentially violating sanctions or fraud rules, and granting access to systems, source code, credentials or customer data. Treasury and DOJ have also warned that some workers have introduced malware, taken sensitive data or extorted companies. Those risks do not mean that every North Korean worker is a hacker; they explain why employment identity and access controls matter. See Treasury’s March 2026 account and DOJ’s sentencing announcement.

The typical money path

  1. A person obtains a job or contract using a false or stolen identity.
  2. The employer pays wages or contractor fees to an account associated with the worker or a proxy.
  3. A facilitator receives, converts or transfers the funds, sometimes through accounts held by other people or companies.
  4. Funds may be split, moved between currencies or cryptocurrencies, swapped between tokens or transferred across blockchains.
  5. Intermediaries may commingle proceeds or route them through accounts linked to North Korean officials, banks or companies.
  6. Some revenue is ultimately directed to the DPRK government or related entities, according to U.S. authorities.

This is a general description of techniques alleged in related cases, not a finding that every step occurred in every November 2025 designation. In a separate civil-forfeiture complaint, DOJ alleged use of fictitious accounts, transaction layering, chain-hopping, token swaps, NFT purchases, U.S.-based online accounts and commingling. The complaint concerns more than $7.74 million allegedly laundered on behalf of North Korea; it is a separate matter from the November sanctions action. DOJ’s announcement sets out those allegations.

This is not only a cryptocurrency-theft story

The November action connects three overlapping sources of funds, rather than describing one uniform scheme:

  • Fraudulent IT employment: salaries and contract payments obtained through false identities or concealed locations.
  • Cybercrime: cryptocurrency theft, hacking, data theft and extortion. Specific allegations should be attributed to the relevant government announcement or court filing.
  • Financial facilitation and sanctions evasion: banks, representatives, trading companies, currency converters and other intermediaries that move or obscure proceeds.

Treasury said the broader DPRK IT-worker operation generated nearly $800 million in 2024. That government estimate concerns the wider operation; it is not the amount attributed to the November 2025 targets or to the March 2026 designees. DOJ separately announced a case in which two U.S. nationals were sentenced in connection with approximately $5 million in revenue for the DPRK. These figures describe different cases or estimates and should not be added together. Treasury’s March 2026 announcement provides the $800 million estimate, and DOJ’s sentencing announcement describes the separate case.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the enforcement actions fit together

Date Action and focus
January 16, 2025 OFAC targeted an IT-worker network involving entities including Chonsurim Trading Corporation and Korea Osong Shipping Corporation, along with associated people and companies. OFAC notice.
July 8, 2025 Treasury sanctioned Song Kum Hyok, Gayk Asatryan, two Asatryan companies and two DPRK trading corporations. Treasury said the Russian network was used to employ or arrange the deployment of North Korean IT workers. Treasury announcement.
July 24, 2025 OFAC targeted Korea Sobaeksu Trading Corporation and three associated individuals over sanctions evasion and fraudulent IT-worker schemes. OFAC notice.
August 27, 2025 OFAC targeted Korea Sinjin Trading Corporation, Shenyang Geumpungri Network Technology Co., Ltd. and associated individuals in a network linked to North Korean IT-worker activity. OFAC notice.
November 4, 2025 Eight people and two entities were designated for roles Treasury linked to laundering proceeds from cybercrime and IT-worker schemes. Treasury announcement.
March 12, 2026 OFAC designated six people and two entities in another action focused on IT-worker fraud and related financial facilitation. OFAC notice.

What changed in the March 2026 action

The March action was related to the November case, but it was a separate designation, with different targets and an emphasis on IT-worker fraud and facilitators. OFAC named six individuals: York Louis Celestino Herrera, Do Phi Khanh, Hoang Minh Quang, Hoang Van Nguyen, Nguyen Quang Viet and Yun Song Guk. It also designated Amnokgang Technology Development Company and Quangvietdnbg International Services Company Limited. The notice contains aliases, locations, linked persons and cryptocurrency addresses: OFAC’s March 12 listing.

Treasury said Amnokgang managed overseas IT-worker delegations and was also involved in illicit procurement of military and commercial technology. It said Nguyen Quang Viet facilitated currency conversion for North Koreans through a Vietnam-based company. Those descriptions are Treasury’s stated basis for the action, not criminal convictions. Treasury’s announcement provides its account of the network.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What employers and financial firms should check

A single video interview, résumé review or sanctions-name search is not enough to address the range of risks. Hiring, procurement, security, payroll and compliance teams should share responsibility for identity, access and payment controls.

For hiring and contracting teams

  • Verify identity using independent, authoritative documents, and confirm that the person applying is the person doing the work.
  • Validate claimed residence, work authorization, tax information and payment geography. Investigate mismatches among a person’s stated location, device location and network location.
  • Use live technical assessments and direct communication with the actual worker; do not rely solely on a résumé, video call or public coding profile.
  • Look for repeated identities or contact details across applicants, and scrutinize requests to route pay through unrelated people or offshore accounts.
  • Recheck identity when work location, payment instructions or access privileges change.

For security teams

  • Use company-managed devices and require approval for remote-control software.
  • Limit administrator privileges and use hardware-backed multifactor authentication where available.
  • Separate source-code repositories, production systems, secrets and customer data; grant only the access needed for the role.
  • Log remote access and unusual credential activity, and apply data-loss-prevention controls to repositories and cloud storage.

For banks, payment processors and cryptocurrency businesses

  • Screen relevant people, entities, intermediaries, banks, beneficial owners and wallet addresses against current sanctions information.
  • Investigate payments routed through unrelated individuals or companies, repeated small transfers, and unexplained currency conversion.
  • Assess cryptocurrency exposure where relevant; transfers across tokens or blockchains do not remove sanctions obligations.
  • Escalate potential matches or suspicious activity through the organization’s compliance process rather than relying on a static list of names in a news article.

OFAC provides a Sanctions List Search Tool and a North Korea sanctions program page with program information and guidance. Screening is only one control: spelling variants, aliases, intermediaries and ownership can complicate name-only checks.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What an OFAC designation means for a business

For U.S. persons, property and interests in property of a designated person that come within U.S. jurisdiction generally must be blocked, and transactions involving designated persons are generally prohibited unless OFAC authorizes them. The consequences can also reach an entity owned 50 percent or more, directly or indirectly and in aggregate, by blocked persons. The relevant rules and guidance are on OFAC’s North Korea sanctions page.

That is not a blanket rule that every relationship with every listed person is automatically unlawful. Legal obligations depend on jurisdiction, ownership, transaction facts and applicable authorizations. Non-U.S. businesses, banks processing U.S.-origin payments and firms operating in allied jurisdictions may face different requirements; obtain qualified sanctions advice when a potential match or transaction arises.

An OFAC designation is an administrative sanctions action, not by itself a criminal conviction. DOJ complaints contain allegations unless established in court, while a sentencing announcement records a court outcome. Keep those categories distinct when assessing a specific person or company.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.