The U.S. State Department, FBI, and allied governments including Japan, Canada, Germany, Australia, the United Kingdom, and the Republic of Korea have issued a joint alert warning companies worldwide that North Korean information technology workers are infiltrating private firms with stolen identities, forged documents, and proxy networks.
According to the July 31, 2026 advisory, these operatives remotely secure freelance and full-time contracts so they can remit salaries to Pyongyang and help finance the regime’s unlawful nuclear weapons and ballistic missile programs.
Officials say the schemes also create serious insider threats, enabling data exfiltration, cryptocurrency theft, and the theft of sensitive corporate information.
North Korean IT workers typically impersonate foreign nationals on online employment, procurement, and contracting platforms. They register accounts with falsified nationality details and forged identification documents, often using images supplied by third-party proxies living in other countries.
FBI Warns of North Korean IT Workers
Those proxies may sit for interviews, establish in-person contact, or lend bank accounts so the real workers remain hidden. Payment preferences are a frequent red flag: many applicants refuse direct deposit and instead request money transfer services or cryptocurrency, or they direct wages to a third party’s account that later routes funds overseas after taking a cut.
In 2026 alone, eight people have already been sentenced in connection with these facilitation schemes, underscoring how seriously authorities are treating the threat.
The advisory describes an expanding toolkit. Workers increasingly rely on artificial intelligence to polish profiles, generate convincing communications, and obscure their true identities. Many operate from North Korea, China, Russia, Southeast Asia, or Africa while masking their locations with VPNs, remote desktop software, and so-called “laptop farms.”
In those setups, U.S.-based or other overseas facilitators receive company-issued laptops and keep them powered on so North Korean workers can log in remotely and appear to be working from a trusted jurisdiction.
Beyond coding jobs in web development, mobile apps, software, and blockchain, some operatives also run fraudulent foreign-exchange trading systems they built themselves to generate additional hard currency.
Companies that unknowingly hire these workers risk more than a bad hire. Contracting with North Korean nationals and paying them can violate United Nations Security Council Resolution 2397 and domestic sanctions laws in the United States, Japan, South Korea, and other jurisdictions, exposing firms to legal penalties and financial sanctions.
The Financial Action Task Force continues to blacklist North Korea as a high-risk jurisdiction for proliferation financing, and IT-worker revenue streams are explicitly cited as a sanctions-evasion pathway. At the same time, successful infiltration can lead to stolen source code, customer data, credentials, and cryptocurrency holdings.
The joint alert urges organizations to tighten identity verification and hiring controls. Officials recommend rigorous review of identification documents, preference for in-person or carefully scrutinized live video interviews, and systems that flag anomalous account activity such as frequent changes to names or bank details, mismatched payment-account names, multiple accounts sharing the same ID or IP address, forged or edited identity images, unnaturally long login sessions, and profiles riddled with translation errors.
During video calls, employers should watch for photo-ID mismatches, manipulated or AI-generated feeds, refusal to turn on cameras, below-market rates, signs that multiple people are operating one account, and demands for cryptocurrency payment. Platform operators are encouraged to notify users of suspicious entries and strengthen account monitoring tools.
Anyone who suspects they have encountered a North Korean IT worker scheme is advised to report the activity promptly to relevant national authorities.
By combining stronger identity checks, video scrutiny, payment diligence, and timely reporting, companies can reduce the chance of funding weapons programs, suffering data theft, or facing sanctions exposure tied to these sophisticated remote-worker frauds.