Thousands of North Korean operatives are infiltrating U.S. companies as IT workers, utilizing stolen identities and advanced technology to exploit the remote work economy, raising significant security concerns.
North Korean operatives are increasingly posing as IT workers to secure remote jobs at U.S. companies, with many successfully hired. Utilizing stolen American identities, laptop farms based in the U.S., and artificial intelligence to craft résumés and assist in interviews, Kim Jong Un’s regime is capitalizing on the remote work economy to embed its workforce within American corporations. In 2024 alone, this extensive, state-directed workforce generated nearly $800 million for North Korea, according to the U.S. Treasury Department, enabling the heavily sanctioned regime to fund its weapons programs.
“The North Korean regime targets American companies through deceptive schemes carried out by its overseas IT operatives, who weaponize sensitive data and extort businesses for substantial payments,” Treasury Secretary Scott Bessent stated.
The implications of this infiltration extend beyond financial gain. Once hired, these workers gain legitimate credentials and trusted access to corporate networks, which could facilitate theft, espionage, extortion, and more sophisticated cyber operations orchestrated by North Korea.
Michael “Barni” Barnhart, a former Army intelligence specialist turned cybersecurity threat hunter, tracks North Korean IT workers. He revealed that, in a recent survey of 20 Fortune 500 companies, he found evidence that North Korean operatives had applied to, worked for, or targeted 18 of them.
Barnhart has dedicated much of his career to countering threats posed by adversaries. After joining the Army as a teenager, he trained in human intelligence and later transitioned to cybersecurity. He played a key role in developing Mandiant’s North Korea-focused threat hunting operation before the company was acquired by Google. Now at cybersecurity firm DTEX, Barnhart concentrates on nation-state insider threats, including the extensive North Korean IT worker operation.
His pursuit of North Korean hackers has left a lasting impression, with tattoos on his feet commemorating hacking groups he has investigated, such as APT43 and APT45, which are linked to operations targeting U.S. think tanks and healthcare organizations. One tattoo reads “IT workers rich experience,” a phrase frequently found on résumés submitted by North Korean IT workers.
According to Barnhart, North Korea begins cultivating its cyber workforce at a remarkably young age. The regime identifies children with aptitude in math, science, technology, and problem-solving, funneling them into specialized training as early as seven years old. “For a communist regime, everything’s a little different,” Barnhart explained. “If you look like you’re going to have some sort of potential, you’re going to get swept into that pipeline.” By college, many are already engaged in technology with military applications, including drones and anti-drone technology. The most talented are directed toward elite hacking units, while others become part of the expansive overseas IT workforce.
The tactics employed by North Korean operatives are evolving. As U.S. companies become more adept at identifying suspicious overseas applicants, North Korean operatives are increasingly recruiting individuals within the U.S. and other countries to serve as their representatives in job interviews, host company laptops, or lend their identities.
Generative AI and interview-assistance tools are now being utilized by North Korean operatives to help them navigate job interviews in real time. Barnhart noted that these technologies address weaknesses that previously made the scheme easier to detect. An applicant claiming to have been born and raised in the U.S. might struggle with basic questions about their supposed hometown or exhibit an unexpected accent, but AI tools can help mitigate these issues.
As employers become more aware of these warning signs, North Korean operatives are adapting their strategies. They are increasingly collaborating with individuals in countries such as Pakistan, India, and Nigeria, adding layers of separation between the North Korean worker and the targeted company. This approach allows them to exploit third-party contractors, potentially gaining access to a company’s network without direct interaction.
These schemes often rely on individuals thousands of miles away from North Korea. Companies frequently send work laptops to new employees, and an address in North Korea, Russia, or China would raise immediate red flags. To create the illusion that employees are working from within the U.S., North Korean operatives recruit Americans to receive and host these computers. Some individuals host multiple laptops for various companies, creating what are known as “laptop farms.”
The Justice Department has prosecuted a growing number of Americans and other facilitators involved in such schemes. In some instances, participants knowingly assist overseas workers in deceiving American companies. In other cases, Barnhart noted, individuals may initially be “hoodwinked” into believing they are simply helping a foreign developer or earning easy passive income.
North Korean operatives actively scour social media, messaging apps, job sites, and online forums for potential recruits, targeting individuals who are often struggling financially. “They like them poor because you need that incentive to dangle in front of them,” Barnhart explained. An individual might initially be offered a few hundred dollars to host a laptop, lend their identity, or act as the American face of an overseas developer. Over time, these requests can escalate.
Barnhart provided an example of a recruitment message obtained from a real operation, in which someone was asked to impersonate a job applicant during interviews. The message detailed how the individual would join meetings and interviews using a provided profile name, effectively pretending to be someone else.
The involvement of Americans and overseas intermediaries complicates investigations. The person whose identity, address, or laptop is being used may not be the individual actually performing the work. Federal prosecutors have documented schemes involving both witting and unwitting third parties, stolen identities, proxy computers, and U.S.-based laptop farms.
In 2025, Arizona resident Christina Chapman was sentenced to over eight years in prison after pleading guilty to conspiracy to commit wire fraud, aggravated identity theft, and conspiracy to launder monetary instruments. Chapman assisted North Korean IT workers in obtaining jobs at more than 300 U.S. companies, including several Fortune 500 corporations. She operated a “laptop farm,” receiving computers from U.S. companies at her home and helping to deceive those companies into believing their employees were located in the U.S.
North Korean operatives are not only stealing identities but also posing a direct threat to American citizens and companies. U.S. Attorney Jeanine Ferris Pirro remarked, “North Korea is not just a threat to the homeland from afar. It is an enemy within, perpetrating fraud on American citizens, companies, and banks.” The ramifications of this infiltration extend far beyond financial loss.
Barnhart emphasized that the IT worker operation represents more than just employment fraud. These operatives can potentially open doors for more skilled North Korean hackers, posing significant risks to sensitive sectors such as critical infrastructure and defense-related organizations. “Do they have the placement and access to do it? Yes, I can tell you right now, verified,” Barnhart stated.
The remote work revolution, accelerated by the COVID-19 pandemic, has provided North Korean operatives with unprecedented opportunities to infiltrate U.S. companies without ever stepping foot in an American office. This operation allows North Korea to circumvent international sanctions, generating a steady flow of income for its regime.
Barnhart highlighted the contrast between the IT workers and North Korea’s more aggressive cyber thefts. While a hacking unit might steal millions in a single operation, the IT workers provide a consistent stream of legitimate-looking paychecks. “The IT workers are a slow, steady paycheck,” he noted, contributing to the regime’s funding of weapons programs.
As North Korea’s military relationship with Russia deepens, the implications of this infiltration become even more concerning. U.S. officials increasingly view the fraudulent worker operation as a mechanism for generating hard currency for a sanctioned regime that is expanding its military support for Moscow. Barnhart warned that companies cannot rely solely on federal law enforcement to mitigate this threat, emphasizing the need for robust identity verification and hiring practices.
In conclusion, the infiltration of North Korean operatives into the U.S. corporate landscape poses a multifaceted threat that extends beyond financial fraud. Companies must adapt their hiring and verification processes to safeguard against these sophisticated schemes, as the consequences of inaction could have far-reaching implications for national security.
According to Fox News, the ongoing evolution of these tactics underscores the need for vigilance in the face of a growing threat.

