Thousands of North Korean operatives are slipping into U.S. companies through remote jobs, turning a modern hiring trend into a national security headache. The scheme leans on stolen identities, fake paperwork, U.S.-based laptop farms, and AI tools to help applicants sound convincing enough to get hired. What looks like ordinary remote work can quickly become a pipeline for cash, access, and espionage.
North Korea has found a lucrative loophole in the remote economy. By placing workers inside American firms, the regime can collect steady paychecks while hiding the real identity and location of the people doing the work. In 2024 alone, the operation brought in nearly $800 million, according to the Treasury Department, giving Pyongyang another way to bankroll its weapons programs.
That money trail matters because this is not just about fake résumés and sloppy interviews. Once a North Korean operative gets a legitimate company login, the risk jumps fast, since the worker may now have access to internal systems, private data, and corporate trust. Treasury Secretary Scott Bessent said the regime is using deceptive overseas IT operatives to target American companies, weaponize sensitive data, and extort businesses for major payments.
Cybersecurity experts say the scale is bigger than many people realize. Michael “Barni” Barnhart, a former Army intelligence specialist now focused on threat hunting, said his own sample of Fortune 500 firms showed how widespread the problem can be, with North Korean IT activity touching most of the companies he reviewed. He described the operation as a long-running pipeline that starts early, with talented children in North Korea being identified and pushed into technical training at a very young age.
By the time some of those recruits reach adulthood, they are already prepared for work that serves the regime’s military goals. Barnhart said some are steered toward tools with battlefield use, including drone-related technology, while others are placed into the broader overseas IT workforce. The line between making money and building cyber capability gets blurry fast, especially when the same people can be used for both.
The scam has also gotten smarter. North Korean operators increasingly rely on Americans and other foreign intermediaries to front for them in interviews, host company-issued laptops, or lend an identity that makes the applicant seem local. AI has made the con even slicker, helping with résumés, live interview answers, and other moments where a fake worker might otherwise stumble.
That evolution is a direct response to companies learning the old tricks. A phony applicant may no longer be exposed by a heavy accent, a vague answer about a hometown, or obvious reading from a second screen. Instead, the operation now uses more layers, more countries, and more digital cover, making it harder for employers to tell whether they are hiring a real person or a proxy for someone overseas.
One of the ugliest parts of the scheme is the use of “laptop farms.” In those setups, someone in the U.S. receives company devices and keeps them running, giving the illusion that an employee is working from inside the country. Federal prosecutors have already pursued cases involving unwitting hosts and people who knew exactly what they were doing, and those cases show how quickly a small favor can turn into a serious federal crime.
The Justice Department has also tracked Americans who helped North Korean workers get jobs at hundreds of U.S. companies. In one major case, Christina Chapman was sentenced to more than eight years in prison after prosecutors said she helped workers land positions at more than 300 companies and shipped dozens of laptops overseas. Her home reportedly held a stash of company computers, each tied to a different employer, like a warehouse for fraud.
There is a deeper danger lurking behind the paycheck. Barnhart said these workers can end up inside sensitive sectors such as defense, research, critical infrastructure, and other places where access alone can be valuable. Even if the immediate goal is simply to earn money, the long-term effect is giving a sanctioned regime a foothold inside American organizations.
The remote-work boom made all of this easier. Before the pandemic, North Korean operatives were already chasing U.S. jobs, but the shift to distributed work removed one of the biggest barriers: showing up in person. Now a company can hire someone it has never met, mail out a laptop, and unknowingly hand over the keys if the screening process is weak.
That is why experts keep hammering the same point. Companies cannot assume a video call and a résumé are enough, especially when sensitive systems are on the line. The threat is not just fraud, it is a sanctioned state building revenue, access, and leverage through the same remote work tools that millions of honest workers use every day.
