Alert to Countries, Companies, and Other Entities Regarding North Korean IT Workers
2026-07-31 • USFBI •
Attachments
source_3884.pdf (485 KB)
North Korean IT workers use forged or borrowed identities, third-party facilitators, and concealed remote-access arrangements to obtain employment and remit income to state-linked agencies supporting prohibited weapons programs. The workers can also create insider risk through data exfiltration, sensitive-information theft, and cryptocurrency theft, while increasingly using AI to strengthen false profiles and manipulated communications. Facilitators may operate laptop farms, attend interviews, supply payment accounts, and obscure workers' actual locations through VPNs and remote-desktop tools. Organizations are urged to strengthen identity verification and investigate combinations of anomalous account, payment, IP-address, video-interview, and work-hour patterns.