{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-arizona-woman-sentenced-to-8-5-years-for-north-korean-it-worker-laptop-f"},"incident":{"slug":"2025-arizona-woman-sentenced-to-8-5-years-for-north-korean-it-worker-laptop-f","title":"Arizona woman sentenced to 8.5 years for North Korean IT worker laptop farm","date":"2025-07-24","date_precision":"day","year":2025,"victim_org":"More than 300 US companies (victims of the fake-worker scheme)","sector":"Technology","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":["Insider Recruitment"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Wire Fraud / Financial Loss","Identity Theft","Insider Access"],"loss_usd":17000000,"loss_kind":"criminal_proceeds","loss_note":"Approximately $17 million in wages and revenue generated for North Korea through the scheme; the defendant was ordered to forfeit roughly $284,000 and pay about $177,000 in restitution.","records_affected":null,"threat_actor":"DPRK IT worker network","summary":"A US District Court in Washington DC sentenced Christina Marie Chapman of Arizona to 102 months in prison on 24 July 2025 for running a 'laptop farm' that let North Korean IT workers pose as US-based employees. Prosecutors said the scheme touched more than 300 US companies, used the stolen identities of dozens of Americans, and generated roughly $17 million for the North Korean government. She also shipped company laptops overseas.","how_it_worked":"Overseas operatives applied for remote IT roles using stolen or borrowed US identities and forged documents, passing HR checks and video screening because the identity paperwork was genuine and the impersonation was rehearsed. Companies shipped corporate laptops to what they believed was the employee's US home address; in fact the machines were racked at the facilitator's house, where remote access software let workers in Asia operate them from apparently American IP addresses. The trust signals abused were a valid Social Security number, a plausible US address and a working corporate device. Payroll then flowed to US accounts before being laundered abroad.","lessons":"Verify remote hires with live identity proofing tied to the device shipping address, and alert on remote-management software or geographic mismatch on corporate endpoints.","confidence":"Confirmed","sources":[{"title":"Arizona woman sentenced in $17M IT worker fraud scheme that illegally generated revenue for North Korea","url":"https://www.justice.gov/usao-dc/pr/arizona-woman-sentenced-17m-it-worker-fraud-scheme-illegally-generated-revenue-north","publisher":"US Department of Justice"},{"title":"Arizona woman sentenced to 8.5 years for running North Korean laptop farm","url":"https://therecord.media/arizona-woman-sentenced-north-korean-laptop-farm","publisher":"The Record"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-arizona-woman-sentenced-to-8-5-years-for-north-korean-it-worker-laptop-f"}}