
Thousands of North Korean operatives are posing as IT workers to secure remote jobs at American companies, using stolen identities, US-based laptop farms and artificial intelligence to make themselves harder to detect.
The operation generated nearly $800 million (£588.2 million) for North Korea in 2024, according to the Treasury Department, providing revenue for a heavily sanctioned regime and its weapons programmes.
Once hired, the workers can receive company laptops, legitimate credentials and trusted access to corporate networks, creating risks that extend far beyond employment fraud. Cybersecurity threat hunter Michael 'Barni' Barnhart told Fox News that North Korean IT workers had applied to, worked for or targeted 18 of 20 Fortune 500 companies he recently sampled.
As companies improve their ability to spot suspicious applicants, North Korean operatives are changing their methods, using intermediaries, Americans and AI-assisted interview tools. The result is an operation that can place operatives inside organisations' networks without them ever physically entering the United States.
How North Korea Gets Workers Inside US Companies
According to a Fox News report, North Korea has been developing its technology workforce from an early age, Barnhart said, identifying children with abilities in maths, science, technology and problem-solving and directing them into specialised training. Some eventually enter elite hacking units, while others become part of the overseas IT workforce.
The operation has existed for years, but the growth of remote work made it easier to operate at scale. 'Once the pandemic hit, it became absolute gasoline on a fire,' Barnhart said.
North Korean operatives can reportedly use stolen American identities to apply for jobs, while Americans are recruited to receive company laptops and make it appear that workers are physically located in the US. These locations, known as 'laptop farms', can hold computers belonging to multiple companies.
Some facilitators knowingly participate, while others can initially be 'hoodwinked' into believing they are helping a foreign developer or earning passive income. Recruiters search social media, job sites and online forums for people who may be willing to host laptops or lend their identities.
The scheme has also involved people in countries including Pakistan, India and Nigeria, creating additional layers between North Korean workers and the companies they target. Third-party contractors can provide another route into corporate networks.
The Justice Department has reportedly prosecuted facilitators involved in these operations. Arizona resident Christina Chapman was sentenced to more than eight years in prison in 2025 after helping North Korean IT workers obtain jobs at more than 300 US companies. More than 90 laptops were seized from her home.
AI Is Making The Operation Harder To Detect
Artificial intelligence is now helping North Korean operatives overcome some of the weaknesses that previously exposed them. Barnhart said they are using generative AI and interview-assistance tools to help answer questions during interviews in real time, alongside deepfake and other AI technologies.
Previously, an applicant claiming to be American might struggle with questions about the city where they supposedly lived, speak with an unexpected accent or appear to be reading answers from another screen. AI can make those warning signs harder to identify.
The consequences can also extend well beyond a fraudulent pay cheque. Barnhart said investigators have found IT workers inside organisations with strategic value to North Korea, including critical infrastructure, defence-related organisations and research and development operations.
'They're not just fraudulent hires,' Barnhart said. 'You really got to watch out.'
A legitimate employee account can provide an operative with access that an outside hacker would have to work to obtain. Barnhart described these workers as insiders who can potentially 'open the door' for more skilled North Korean hackers.
The financial incentive is also considerable. Treasury officials say the wages generated by North Korean IT workers help support the regime's weapons of mass destruction and ballistic missile programmes.
'The IT workers are a slow, steady paycheck,' Barnhart said.
For companies, Barnhart argues that stopping the operation requires more than relying on law enforcement. Employers need to verify that the person appearing for an interview is actually the person whose identity and credentials were submitted.
'We have to change,' Barnhart said. 'We can't just rely on law enforcement. They're only gonna go so far. We have to rely on our own policies and our own verifications in being able to stop them.'




