{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-us-sweep-seizes-200-computers-from-north-korean-it-worker-laptop-farms"},"incident":{"title":"US sweep seizes 200 computers from North Korean IT worker laptop farms","date":"2025-06-30","date_precision":"day","victim_org":"More than 100 US companies, including many Fortune 500 firms","sector":"Technology","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":["Insider Recruitment"],"ai_involvement":"Unknown","ai_notes":"DOJ described stolen and fraudulent identities; the announcement reviewed did not specify AI-generated personas.","outcomes":["Wire Fraud / Financial Loss","Identity Theft","Insider Access","Espionage","Cryptocurrency Theft"],"loss_usd":null,"loss_note":"DOJ cited at least $3 million in victim-company losses for legal fees and remediation, more than $5 million in revenue in one Massachusetts scheme, roughly $915,000 in virtual currency stolen in a Georgia case, and a civil forfeiture action covering over $7.74 million in digital assets. US facilitators received at least $696,000.","records_affected":null,"threat_actor":"DPRK remote IT worker networks and US-based facilitators (Zhenxing 'Danny' Wang, Kejia Wang and others)","summary":"On June 30, 2025 the Justice Department announced coordinated nationwide actions against North Korea's remote IT worker schemes. Between June 10 and 17, agents searched 21 laptop farms across 14 states and seized nearly 200 computers, along with 21 fraudulent websites and 29 financial accounts. One US national, Zhenxing Wang of New Jersey, was arrested; another agreed to plead guilty. Court documents describe more than 100 victim companies, and cases included theft of export-controlled military technology.","how_it_worked":"North Korean workers obtained remote US employment using stolen and fabricated identities that cleared employer background checks. US-based facilitators supplied the American presence the scheme needed: they registered shell companies and fraudulent websites so the identities had verifiable employment history, received the employers' shipped laptops, and installed keyboard-video-mouse switches and remote access software so overseas operators could drive the machines as though sitting in front of them. From inside those employers the workers drew salaries routed to the DPRK, and in several cases went further, exfiltrating sensitive data including export-controlled military technology and stealing virtual currency from employer systems.","lessons":"Employers need live identity proofing tied to the government ID at hire, verification that the issued device is physically where the employee claims to be, and alerting on KVM or remote-access hardware attached to corporate endpoints.","confidence":"Confirmed","sources":[{"title":"Justice Department Announces Coordinated, Nationwide Actions to Combat North Korean Remote Information Technology Workers","url":"https://www.justice.gov/opa/pr/justice-department-announces-coordinated-nationwide-actions-combat-north-korean-remote","publisher":"U.S. Department of Justice"},{"title":"U.S. Arrests Facilitator in North Korean IT Worker Scheme; Seizes 29 Domains and Raids 21 Laptop Farms","url":"https://thehackernews.com/2025/07/us-arrests-key-facilitator-in-north.html","publisher":"The Hacker News"}],"entry_type":"campaign","slug":"2025-us-sweep-seizes-200-computers-from-north-korean-it-worker-laptop-farms","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-us-sweep-seizes-200-computers-from-north-korean-it-worker-laptop-farms"}}