HomeScience & EnvironmentThousands of North Korean IT workers are infiltrating corporate America

Thousands of North Korean IT workers are infiltrating corporate America

NEWYou can now listen to Fox News articles!

Thousands of North Korean operatives posing as IT workers are applying for remote jobs at U.S. companies, and many are getting hired. 

Using stolen American identities, U.S.-based “laptop farms” and artificial intelligence to write résumés and help answer interview questions, Kim Jong Un’s regime is exploiting the remote-work economy to get its workers inside American companies.

In 2024 alone, the sprawling, state-directed workforce generated nearly $800 million for North Korea, according to the Treasury Department, helping the heavily sanctioned regime fund its weapons programs.

“The North Korean regime targets American companies through deceptive schemes carried out by its overseas IT operatives, who weaponize sensitive data and extort businesses for substantial payments,” Treasury Secretary Scott Bessent said in a statement.

A North Korean flag flutters next to concertina wire. (Edgar Su/Reuters)

The threat goes beyond the paycheck. 

Once hired, the workers gain legitimate credentials and trusted access to corporate networks, potentially opening the door to theft, espionage, extortion and more sophisticated North Korean cyber operations.

Fox News interviewed Michael “Barni” Barnhart, a former Army intelligence specialist turned cybersecurity threat hunter who tracks North Korean IT workers for a living

Barnhart said the workers are so pervasive that when he recently sampled 20 Fortune 500 companies, he found evidence that North Korean IT workers had applied to, worked for or targeted 18 of them.

Barnhart has spent much of his career hunting America’s adversaries. 

He joined the Army as a teenager, training in human intelligence before moving into signals intelligence and counterterrorism and deploying to Iraq

He later moved into cybersecurity, eventually helping build Mandiant’s North Korea-focused threat hunting operation before the company was acquired by Google. Now at cybersecurity firm DTEX, Barnhart focuses on nation-state insider threats, including the sprawling North Korean IT worker operation.

Michael Barnhart

Michael “Barni” Barnhart during his service in the U.S. Army. (Courtesy of Michael Barnhart)

His pursuit of North Korean hackers has even left a permanent mark. 

Barnhart has tattoos on his feet commemorating North Korean hacking groups he has helped investigate, including APT43 and APT45, groups tied to operations targeting U.S. think tanks and healthcare organizations. 

Another tattoo reads “IT workers rich experience,” a reference, he said, to language that repeatedly appears on résumés used by North Korean IT workers.

“Anytime we knock off a North Korean hacking unit, I get them tattooed on my feet,” Barnhart said.

Michael Barnhart

Another tattoo of Barnhart’s reads “IT workers rich experience,” a reference, he said, to language that repeatedly appears on résumés used by North Korean operatives. (Courtesy of Michael Barnhart)

Barnhart said North Korea begins building its cyber workforce remarkably early. The regime can identify children with an aptitude for math, science, technology and problem-solving and funnel them into specialized training beginning as young as seven years old.

“For a communist regime, everything’s a little different,” Barnhart said. “If you look like you’re gonna have some sort of potential or some sort of potential later on, you’re going to get swept in that pipeline.”

By college, some are already working on technology with military applications, Barnhart said, including drones and anti-drone technology. The most talented can be funneled toward North Korea’s elite hacking units, while others become part of its sprawling overseas IT workforce.

And the scheme is evolving.

As American companies become better at spotting suspicious overseas applicants, North Korean operatives are increasingly recruiting people in the U.S. and other countries to become their faces in job interviews, host company laptops or lend them their identities.

They are also turning to AI.

North Korean operatives are now using generative AI and interview-assistance tools to help them answer questions during job interviews in real time. He said they are also using deepfake and other AI technologies as companies become more adept at identifying suspicious applicants.

“They’re using AI, a lot of times, in their actual interviews, using that generative AI to help do it, using interview AI assistance,” Barnhart said.

AI training on keyboard

A symbol representing AI with a person at a keyboard. (iStock)

The technology helps address one of the weaknesses that previously made the scheme easier to spot. 

An applicant claiming to have been born and raised in the United States might struggle with basic questions about the city where he supposedly lives, speak with an unexpected accent or appear to be reading answers from another screen.

But as employers learn more about these warning signs, Barnhart said North Korean operatives are changing their tactics. 

North Korean operators are increasingly working through people in countries including Pakistan, India and Nigeria, Barnhart said, adding even more layers between the North Korean worker and the company being targeted. 

They can also exploit third-party contractors, potentially allowing them to reach a company’s network without ever coming directly through its front door.

DEMOCRATS SOUND ALARM OVER AI JOB APOCALYPSE — BUT LABOR MARKET ISN’T FOLLOWING SCRIPT

“As soon as everyone has a lead on them, they like to switch,” Barnhart said.

These schemes can rely heavily on people thousands of miles away from North Korea.

Often, companies mail a work laptop to a new employee. An address in North Korea, Russia or China where some of these workers are, would immediately raise red flags. To create the appearance the employee is actually working from inside the United States, North Korean operatives recruit Americans to receive and host the computers. Some Americans host dozens of computers for dozens of companies. These are called, “laptop farms.”

The Justice Department has prosecuted a growing number of Americans and other facilitators for participating in such schemes. 

In some cases, the participants knowingly help overseas workers deceive American companies. In others, Barnhart said, people can initially be “hoodwinked” into believing they are simply helping a foreign developer or earning easy passive income. 

North Korean operatives scour social media, messaging apps, job sites and online forums for potential recruits, Barnhart said, including Reddit, Discord, Telegram, WhatsApp and Craigslist.

The targets are often people struggling financially.

“They like them poor because you need that incentive to dangle in front of them,” Barnhart said.

A person might initially be offered a few hundred dollars to host a laptop, lend an identity or become the American face of an overseas developer. The requests can then escalate.

“All I got to do is have this laptop in my house, and you’re going to give me money,” Barnhart said, describing how an unsuspecting participant might view the arrangement. “Little by little you can start to see over the years the schemes get larger or the asks get bigger.”

Barnhart provided Fox News with an actual recruitment message obtained from a real operation showing how someone was asked to impersonate a job applicant during interviews.

“In my past experience, hiring managers liked my skills and experience but they were not moving forward with me because of my lack of English level. We are looking for a native English speaker/software developer to collaborate closely with me.

“You will be joining all meetings (Google or Zoom) with the given profile name to do interviews with clients and pretend to be someone else during interviews.”

The use of Americans and overseas intermediaries creates another problem for investigators: the person whose identity, address or laptop is being used may not necessarily be the person actually doing the work.

Federal prosecutors have documented schemes involving both witting and unwitting third parties, stolen identities, proxy computers and U.S.-based laptop farms. 

Recent Justice Department cases have also shown facilitators allowing overseas IT workers to create fraudulent résumés in their names, participate in employer vetting and remotely access company-issued laptops from abroad.

In 2025, Arizona resident Christina Chapman was sentenced to more than eight years in prison after pleading guilty to conspiracy to commit wire fraud, aggravated identity theft and conspiracy to launder monetary instruments.

Chapman helped North Korean IT workers get jobs at more than 300 U.S. companies, including several Fortune 500 corporations. The companies included a top-five major television network, a Silicon Valley technology company, an aerospace manufacturer, an American carmaker, a luxury retail store and a U.S. media and entertainment company, according to the Justice Department.

Chapman operated a “laptop farm,” receiving computers from U.S. companies at her home and helping deceive those companies into believing their employees were located in the United States. She shipped 49 laptops overseas, including to China. More than 90 laptops were seized from her home following the execution of a search warrant in October 2023.

Chapman organized and stored the company laptops in her home, even including notes identifying which U.S. company was associated with each computer so she would not confuse them.

North Korean workers are stealing the identities of normal everyday Americans. 

Picture of laptops found inside Christina Chapman’s home

Company-issued laptops discovered inside Christina Chapman’s home, where prosecutors said she operated a “laptop farm” to help North Korean IT workers appear to be working from the United States. (Courtesy of the Justice Department)

The Wall Street Journal recently highlighted a victim of identity theft, Michael Brown. North Korea used Brown’s identity to get jobs in at least two companies, according to the WSJ. 

“North Korea is not just a threat to the homeland from afar. It is an enemy within. It is perpetrating fraud on American citizens, American companies, and American banks. It is a threat to Main Street in every sense of the word,” U.S. Attorney Jeanine Ferris Pirro said in a statement.

The threat, however, is not limited to the money North Korea collects.

Barnhart said he initially viewed the IT workers primarily as a revenue-generation operation and focused his attention instead on North Korea’s more sophisticated hacking units. Then investigators began finding the IT workers intertwined with those hacking operations.

“They’re not just fraudulent hires,” Barnhart said. “You really got to watch out.”

Once a fraudulent worker has been hired, the dynamic changes dramatically. Instead of a North Korean hacker trying to break through a company’s defenses from the outside, the company itself may have handed a North Korean operative credentials, a laptop and trusted access to its systems.

Barnhart said he has seen evidence of workers inside organizations with strategic intelligence value to North Korea, including critical infrastructure, defense-related organizations, research and development and other sensitive sectors.

“Do they have the placement and access to do it? Yes, I can tell you right now, verified,” Barnhart said. “I’ve seen them in places we do not want them to include critical infrastructure as well.”

Barnhart said North Korea’s approach is essentially scattershot: place thousands of workers inside organizations around the world. At an ordinary retail company, the primary objective may simply be collecting a paycheck. But a worker who lands inside a defense contractor, pharmaceutical company, government organization or critical infrastructure operator can suddenly become far more valuable.

The worker could steal information or potentially provide an opening for more sophisticated North Korean cyber operators, Barnhart said.

That possibility is one reason the IT-worker operation represents something different from ordinary employment fraud.

“These are not just insider threats,” Barnhart said, describing them as insiders who can potentially “open the door” for more skilled North Korean hackers.

“This is going to supply a weapons program for a regime that is sanctioned to their eyeballs,” Barnhart said.

North Korean IT workers had already started targeting remote jobs at U.S. companies before the COVID-19 pandemic began. Barnhart said the operation can be traced back more than a decade, with the threat accelerating in the mid-2010s.

Then millions of Americans suddenly began working remotely.

“Once the pandemic hit, it became absolute gasoline on a fire,” Barnhart said.

The remote-work revolution gave North Korean operatives something they previously lacked at scale: the ability to get hired by an American company without ever physically entering an American office.

For North Korea, the operation also offers a critical way around international sanctions.

NORTH KOREA EXPERT WARNS US CAN ‘NEVER TAKE THEIR EYE OFF’ KIM JONG UN FOLLOWING MISSILE TEST DURING IRAN WAR

Barnhart contrasts the IT workers with North Korea’s massive cryptocurrency thefts. A hacking unit might steal millions of dollars in a single operation, drawing immediate international attention. The IT workers instead provide thousands of legitimate-looking paychecks arriving little by little.

“The IT workers are a slow, steady paycheck,” Barnhart said.

Spread across thousands of workers, those salaries create a steady stream of money flowing toward one of the most heavily sanctioned governments in the world.

“It’s a bypass sanction because this is a country that’s sanctioned to their eyeballs,” Barnhart said.

And the money generated by the scheme may have consequences far beyond the Korean Peninsula. The Treasury Department says the North Korean government uses most of the wages earned by its IT workers to generate hundreds of millions of dollars to support the regime’s weapons of mass destruction and ballistic missile programs.

And North Korea is now increasingly intertwined with Russia’s war in Ukraine.

Earlier this month, Ukrainian President Volodymyr Zelenskyy said Russia is preparing to deploy an additional North Korean contingent and has received additional ballistic missiles from Pyongyang. Russia is increasingly dependent on North Korea for its war in Ukraine. 

Kim Jong Un and Vladimir Putin meeting

Russian President Vladimir Putin and North Korean leader Kim Jong Un. (Alexander Kazakov/Pool/AFP via Getty Images)

“For the first time in its history, Russia cannot wage war without reinforcements from North Korea,” Zelenskyy said.

Zelenskyy warned the relationship also gives North Korea something valuable in return: an opportunity to test its troops and weapons under real battlefield conditions and improve them. 

“The more North Korean strikes there are here in Ukraine, in Europe, the more their missiles and soldiers are used, the more they correct their shortcomings and blind spots, the greater the danger will later be for Japan, the Republic of Korea, the Philippines, and other countries in the region,” Zelenskyy said.

Barnhart argues that Americans should understand the chain connecting the remote-work scheme to North Korea’s expanding military relationship with Russia.

Western companies can unknowingly pay North Korean workers. Those workers generate hard currency for a regime under extensive international sanctions. North Korea uses revenue from overseas workers and other illicit schemes to support its government and weapons programs. Pyongyang, in turn, has supplied weapons and troops to Russia.

TRUMP TEASES POTENTIAL KIM JONG UN MEETING LATER THIS YEAR

“If the Western dollars and ally dollars are going to North Korea to help their weapons program, and they in turn are giving those weapons to the Russians to help with their Ukrainian conflict,” Barnhart said, the implications become much broader.

The connection shows why U.S. officials increasingly view the fraudulent-worker operation as more than an employment scam. It is a mechanism for generating hard currency for a sanctioned regime that is simultaneously expanding its military support for Moscow, Barnhart explained. 

Barnhart warned companies cannot rely solely on federal law enforcement to stop the threat because of the sheer scale of the operation and because the North Korean workers themselves are often beyond the reach of U.S. authorities.

“It’s on us to trust but verify,” Barnhart said.

He said companies need to rethink remote hiring and identity-verification procedures, particularly for employees who will receive access to sensitive networks, intellectual property or critical systems. 

One way companies can do this is to run identity checks as well as background checks on potential employees. 

CLICK HERE TO DOWNLOAD THE FOX NEWS APP

While a traditional background check looks into an applicant’s record, an identity check can determine whether the person sitting down for the interview on the computer screen is the same person whose face is on the identification and credentials that were submitted. 

“We have to change,” Barnhart said. “We can’t just rely on law enforcement. They’re only gonna go so far. We have to rely on our own policies and our own verifications in being able to stop them.”

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular

Recent Comments

A WordPress Commenter on Hello world!