{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:22:04.222Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Arizona laptop farm placed North Korean IT workers at 309 US companies","date":"2023-10","date_precision":"month","victim_org":"309 US companies, including a top-five television network, an aerospace manufacturer, a US carmaker, a Silicon Valley technology firm and a luxury retailer","sector":"Technology","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":[],"ai_involvement":"Unknown","ai_notes":"The DOJ case documents describe stolen real identities rather than AI-generated personas; no AI use was specified in the sentencing reporting.","outcomes":["Wire Fraud / Financial Loss","Identity Theft","Insider Access"],"loss_usd":17000000,"loss_note":"The scheme generated approximately $17 million in revenue for the North Korean government. Chapman was ordered to forfeit $284,555.92 intended for North Korea and to pay a $176,850 fine.","records_affected":68,"threat_actor":"DPRK IT worker network, facilitated by Christina Marie Chapman","summary":"From October 2020 to October 2023, Christina Chapman ran a 'laptop farm' from her Arizona home that let North Korean IT workers appear to be US-based remote employees. The FBI seized more than 90 laptops in an October 2023 raid; she also shipped 49 devices overseas, including to a Chinese city on the North Korean border. The operation used 68 stolen US identities to place workers at 309 companies and generated about $17 million for the DPRK. Chapman was sentenced to 102 months on July 24, 2025.","how_it_worked":"North Korean operatives applied for remote IT roles under the identities of real Americans, clearing background checks because the identities were genuine. When each employer shipped a work laptop to the address on file, that address was Chapman's house. She installed remote access software on each machine and kept them running so the workers could connect daily and appear on the employer's network from a US residential IP on US business hours. Chapman also received the direct-deposit wages, forged payroll checks and filed tax returns in the stolen names before moving the money overseas. Employers saw nothing anomalous because the device, the network location and the paperwork were all genuinely American.","lessons":"Verifying that a shipped device is actually in the hands of the person hired, through live video identity checks at onboarding and device-location attestation, is what breaks the laptop farm model.","confidence":"Confirmed","sources":[{"title":"Arizona woman sentenced to 8.5 years for running North Korean laptop farm","url":"https://therecord.media/arizona-woman-sentenced-north-korean-laptop-farm","publisher":"The Record (Recorded Future News)"},{"title":"Arizona woman imprisoned for $17M North Korean remote workers scheme","url":"https://www.upi.com/Top_News/US/2025/07/24/chapman-north-korea-remote-workers-fraud/7551753396658/","publisher":"UPI"}],"entry_type":"incident","slug":"2023-arizona-laptop-farm-placed-north-korean-it-workers-at-309-us-companies","year":2023,"loss_kind":"criminal_proceeds","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-arizona-laptop-farm-placed-north-korean-it-workers-at-309-us-companies"}]}