North Korean Operatives Infiltrate U.S. Companies via Remote IT Jobs and Laptop Farms
North Korean agents are posing as remote IT employees, securing positions at American firms and using stolen identities and laptop farms to gain network access.
North Korean state-run operatives are masquerading as remote information-technology workers to obtain jobs at U.S. companies, relying on stolen personal data, U.S.-based “laptop farms” and AI-assisted résumé creation. Treasury data shows the program earned nearly $800 million in 2024, providing hard currency for Pyongyang’s sanctioned weapons development. Cyber-security veteran Michael “Barni” Barnhart, now with DTEX, says the workers have penetrated many large corporations, using generative AI during interviews and recruiting intermediaries in countries such as Pakistan, India and Nigeria to conceal their origins.
U.S. prosecutors have charged both willing and unwitting Americans for hosting laptops and facilitating identity fraud, exemplified by the sentencing of Arizona resident Christina Chapman. Once hired, these operatives obtain legitimate credentials and network access, creating pathways for espionage, data theft and potential support for more advanced hacking units. The scheme, which predates the pandemic, has expanded with the rise of remote work, offering the regime a steady revenue stream that underwrites its missile and nuclear programs and its growing military cooperation with Russia. Experts warn that companies must strengthen identity verification beyond law-enforcement reliance to block the threat.
Why it matters
The scheme lets a sanctioned regime earn hard cash and gain network access inside U.S. firms, threatening corporate security and funding weapons.
In this story
