08/26/2026
https://www.fbi.gov/investigate/cyber/alerts/2025/north-korean-it-worker-threats-to-u-s-businesses
The gist of this scam is that North Korean nationals use stolen or fabricated identities, often impersonating U.S. citizens, to obtain remote employment with U.S. companies. Many target IT-related positions. To conceal their true location, they provide U.S. mailing addresses associated with accomplices or facilitators. Company-issued laptops are shipped to these U.S. addresses, where the facilitators power on the devices and enable remote access, allowing the North Korean worker to operate the computer from overseas while appearing to be located in the United States.
Once hired, the worker performs legitimate job functions and receives a salary, which is then funneled back to North Korea in violation of international sanctions. The access they obtain creates significant security risks because they may have access to sensitive corporate data, source code, cloud resources, customer information, or administrative systems. In some documented cases, these workers have stolen data, intellectual property, or cryptocurrency. The arrangement also introduces the potential risk of insider threats, data theft, extortion, or ransomware activity.
U.S.-based facilitators sometimes operate "laptop farms," maintaining dozens of company-owned computers for remote access by overseas operators. Federal investigations have uncovered laptop farms containing large numbers of devices supporting these fraudulent employment schemes.
The primary goal is stealing US funds from employers by funneling paid salaries back to North Korea. However, the threat actor will not hesitate to steal corporate data or attack the business with ransomware or similar threats if there is financial motivation to do so.
The FBI is providing an update to previously shared guidance regarding Democratic People's Republic of Korea (North Korea) Information Technology (IT) workers to raise public awareness of the threat posed to U.S. businesses.