Alert to Countries, Companies, and Other Entities Regarding North Korean IT Workers

2026-07-31 USFBI

https://www.ic3.gov/CSA/2026/260731.pdf

Attachments

source_3884.pdf (485 KB)

Thumbnail for Alert to Countries, Companies, and Other Entities Regarding North Korean IT Workers

North Korean IT workers use forged or borrowed identities, third-party facilitators, and concealed remote-access arrangements to obtain employment and remit income to state-linked agencies supporting prohibited weapons programs. The workers can also create insider risk through data exfiltration, sensitive-information theft, and cryptocurrency theft, while increasingly using AI to strengthen false profiles and manipulated communications. Facilitators may operate laptop farms, attend interviews, supply payment accounts, and obscure workers' actual locations through VPNs and remote-desktop tools. Organizations are urged to strengthen identity verification and investigate combinations of anomalous account, payment, IP-address, video-interview, and work-hour patterns.

Related Reports

« Back