{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T07:27:57.173Z","total":10,"returned":10,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"slug":"2026-fbi-identifies-north-korean-remote-it-worker-employed-by-a-us-federal-ag","title":"FBI identifies North Korean remote IT worker employed by a US federal agency","date":"2026-07","date_precision":"month","year":2026,"victim_org":"Unnamed US federal agency","sector":"Government","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":["Fake Job Offer / Recruitment Lure"],"ai_involvement":"Unknown","ai_notes":"","outcomes":["Insider Access","Espionage"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"DPRK remote IT worker programme","summary":"FBI deputy assistant director Todd Hemmen disclosed at a conference on 28 July 2026 that the Bureau had identified, the previous week, a North Korean remote IT worker who was working for the US federal government. The agency involved, the duration of the placement, what systems the individual reached and whether any sensitive information was compromised have not been made public. Experts assess the placement was most likely a contract role, since permanent federal positions require background investigations.","how_it_worked":"The DPRK remote IT worker programme wins access by being hired rather than by breaking in. Operatives apply for remote technical roles using stolen or fabricated identities, often with US-based facilitators who host company laptops, sit for identity checks, or lend a domestic address and bank account so that pay and equipment appear to land with a real person in the United States. Video interviews and onboarding checks are handled by the operative or the facilitator. Once employed the worker holds legitimate credentials and normal access, which is why detection typically comes from behavioural or payroll anomalies rather than security tooling.","lessons":"Live identity proofing at hire and again at equipment issue, plus checks that payroll destinations and laptop network locations match the claimed residence, are what surface these placements.","confidence":"Confirmed","sources":[{"title":"FBI investigating North Korean remote IT staffer working for US agency","url":"https://federalnewsnetwork.com/technology-main/2026/08/fbi-investigating-north-korean-remote-it-staffer-working-for-u-s-agency/","publisher":"Federal News Network"},{"title":"FBI finds North Korean IT worker inside federal agency","url":"https://www.thestreet.com/employment/fbi-north-korean-remote-worker-insider-threat-2026","publisher":"TheStreet"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-fbi-identifies-north-korean-remote-it-worker-employed-by-a-us-federal-ag"},{"slug":"2025-five-plead-guilty-to-helping-north-korean-it-workers-infiltrate-136-us-c","title":"Five plead guilty to helping North Korean IT workers infiltrate 136 US companies","date":"2025-11","date_precision":"month","year":2025,"victim_org":"136 US companies (victims of the fake-worker scheme)","sector":"Technology","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":["Insider Recruitment"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Wire Fraud / Financial Loss","Identity Theft","Insider Access"],"loss_usd":2200000,"loss_kind":"criminal_proceeds","loss_note":"About $2.2 million in revenue generated for the North Korean government through the roles obtained; one defendant agreed to forfeit more than $1.4 million.","records_affected":null,"threat_actor":"DPRK IT worker network","summary":"The US Justice Department announced in November 2025 that five people, four US nationals and a Ukrainian, had pleaded guilty to charges including wire fraud conspiracy and aggravated identity theft for enabling North Korean IT workers to obtain remote jobs at American companies. The conduct affected more than 136 US companies and generated approximately $2.2 million for North Korea. One defendant ran a site selling stolen identities and managed roughly 871 proxy identities and at least three laptop farms.","how_it_worked":"Three of the defendants let overseas workers use their real US identities to apply for and hold remote IT jobs, so background checks returned clean results for genuine Americans. Others hosted company-issued laptops at their homes and installed remote desktop software so workers abroad appeared to be sitting at a US desk. A fourth trafficked stolen and rented identities through a website marketed at overseas jobseekers. The deception targeted HR and IT onboarding rather than any technical control: the trust signals abused were verified identity documents, a US shipping address and a US-looking network origin, all of which onboarding processes treat as proof of presence.","lessons":"Tie identity verification to a live check at onboarding and re-verify periodically; monitor corporate laptops for remote-control tooling and for logins whose network geography does not match the employee's stated location.","confidence":"Confirmed","sources":[{"title":"Five Plead Guilty in U.S. for Helping North Korean IT Workers Infiltrate 136 Companies","url":"https://thehackernews.com/2025/11/five-us-citizens-plead-guilty-to.html","publisher":"The Hacker News"},{"title":"Ukrainian national pleads guilty in 'laptop farm' scheme that generated income for North Korean IT workers","url":"https://www.justice.gov/usao-dc/pr/ukrainian-pleads-guilty-dc-laptop-farm-scheme-generated-income-north-korean-it-workers","publisher":"US Department of Justice"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-five-plead-guilty-to-helping-north-korean-it-workers-infiltrate-136-us-c"},{"title":"North Korean operatives used Claude to fabricate identities and hold Fortune 500 jobs","date":"2025-08","date_precision":"month","victim_org":"US Fortune 500 technology companies employing fraudulent remote workers","sector":"Technology","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":["Fake Job Offer / Recruitment Lure"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Anthropic reported that DPRK operators used Claude to build convincing professional personas, answer technical interview questions in real time, and then perform the day-to-day technical work required to keep the jobs.","outcomes":["Insider Access","Wire Fraud / Financial Loss"],"loss_usd":null,"loss_note":"Salaries paid to fraudulent workers fund DPRK weapons programmes; amounts not quantified in this report","records_affected":null,"threat_actor":"DPRK remote IT worker operations","summary":"In a threat intelligence report published on 27 August 2025, Anthropic described North Korean operators using Claude throughout the fraudulent remote-employment lifecycle: fabricating detailed professional identities, passing coding and technical assessments during hiring, and delivering the actual engineering work once employed at US Fortune 500 technology companies. Anthropic noted that AI removed the years of training that previously constrained the number of operators the programme could field, letting people with limited coding ability or English proficiency obtain and hold technical roles.","how_it_worked":"The social engineering is embedded in a legitimate process rather than an attack channel. Operators presented resumes, portfolios and interview answers generated to match each job description, so the persona was internally consistent and tailored to the employer's stated needs. Live technical screens, the control most companies rely on to prove a candidate can do the work, were passed with model assistance, which meant competence itself was no longer evidence of authenticity. Once hired, continued AI assistance let the operator meet delivery expectations, so the normal signal that a fraudulent hire generates, poor performance, never appeared. Remote-first norms explained away the absence of in-person contact.","lessons":"Identity assurance must be decoupled from skills assessment: verify documents and liveness, cross-check payroll and device geography, and treat consistent evasion of in-person or unscheduled verification as a signal in its own right.","confidence":"Reported","sources":[{"title":"Detecting and countering misuse of AI: August 2025","url":"https://www.anthropic.com/news/detecting-countering-misuse-aug-2025","publisher":"Anthropic"},{"title":"Anthropic threat intelligence report, August 2025 (PDF)","url":"https://www-cdn.anthropic.com/b2a76c6f6992465c09a6f2fce282f6c0cea8c200.pdf","publisher":"Anthropic"}],"entry_type":"incident","slug":"2025-north-korean-operatives-used-claude-to-fabricate-identities-and-hold-for","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-north-korean-operatives-used-claude-to-fabricate-identities-and-hold-for"},{"slug":"2025-arizona-woman-sentenced-to-8-5-years-for-north-korean-it-worker-laptop-f","title":"Arizona woman sentenced to 8.5 years for North Korean IT worker laptop farm","date":"2025-07-24","date_precision":"day","year":2025,"victim_org":"More than 300 US companies (victims of the fake-worker scheme)","sector":"Technology","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":["Insider Recruitment"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Wire Fraud / Financial Loss","Identity Theft","Insider Access"],"loss_usd":17000000,"loss_kind":"criminal_proceeds","loss_note":"Approximately $17 million in wages and revenue generated for North Korea through the scheme; the defendant was ordered to forfeit roughly $284,000 and pay about $177,000 in restitution.","records_affected":null,"threat_actor":"DPRK IT worker network","summary":"A US District Court in Washington DC sentenced Christina Marie Chapman of Arizona to 102 months in prison on 24 July 2025 for running a 'laptop farm' that let North Korean IT workers pose as US-based employees. Prosecutors said the scheme touched more than 300 US companies, used the stolen identities of dozens of Americans, and generated roughly $17 million for the North Korean government. She also shipped company laptops overseas.","how_it_worked":"Overseas operatives applied for remote IT roles using stolen or borrowed US identities and forged documents, passing HR checks and video screening because the identity paperwork was genuine and the impersonation was rehearsed. Companies shipped corporate laptops to what they believed was the employee's US home address; in fact the machines were racked at the facilitator's house, where remote access software let workers in Asia operate them from apparently American IP addresses. The trust signals abused were a valid Social Security number, a plausible US address and a working corporate device. Payroll then flowed to US accounts before being laundered abroad.","lessons":"Verify remote hires with live identity proofing tied to the device shipping address, and alert on remote-management software or geographic mismatch on corporate endpoints.","confidence":"Confirmed","sources":[{"title":"Arizona woman sentenced in $17M IT worker fraud scheme that illegally generated revenue for North Korea","url":"https://www.justice.gov/usao-dc/pr/arizona-woman-sentenced-17m-it-worker-fraud-scheme-illegally-generated-revenue-north","publisher":"US Department of Justice"},{"title":"Arizona woman sentenced to 8.5 years for running North Korean laptop farm","url":"https://therecord.media/arizona-woman-sentenced-north-korean-laptop-farm","publisher":"The Record"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-arizona-woman-sentenced-to-8-5-years-for-north-korean-it-worker-laptop-f"},{"title":"US sweep seizes 200 computers from North Korean IT worker laptop farms","date":"2025-06-30","date_precision":"day","victim_org":"More than 100 US companies, including many Fortune 500 firms","sector":"Technology","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":["Insider Recruitment"],"ai_involvement":"Unknown","ai_notes":"DOJ described stolen and fraudulent identities; the announcement reviewed did not specify AI-generated personas.","outcomes":["Wire Fraud / Financial Loss","Identity Theft","Insider Access","Espionage","Cryptocurrency Theft"],"loss_usd":null,"loss_note":"DOJ cited at least $3 million in victim-company losses for legal fees and remediation, more than $5 million in revenue in one Massachusetts scheme, roughly $915,000 in virtual currency stolen in a Georgia case, and a civil forfeiture action covering over $7.74 million in digital assets. US facilitators received at least $696,000.","records_affected":null,"threat_actor":"DPRK remote IT worker networks and US-based facilitators (Zhenxing 'Danny' Wang, Kejia Wang and others)","summary":"On June 30, 2025 the Justice Department announced coordinated nationwide actions against North Korea's remote IT worker schemes. Between June 10 and 17, agents searched 21 laptop farms across 14 states and seized nearly 200 computers, along with 21 fraudulent websites and 29 financial accounts. One US national, Zhenxing Wang of New Jersey, was arrested; another agreed to plead guilty. Court documents describe more than 100 victim companies, and cases included theft of export-controlled military technology.","how_it_worked":"North Korean workers obtained remote US employment using stolen and fabricated identities that cleared employer background checks. US-based facilitators supplied the American presence the scheme needed: they registered shell companies and fraudulent websites so the identities had verifiable employment history, received the employers' shipped laptops, and installed keyboard-video-mouse switches and remote access software so overseas operators could drive the machines as though sitting in front of them. From inside those employers the workers drew salaries routed to the DPRK, and in several cases went further, exfiltrating sensitive data including export-controlled military technology and stealing virtual currency from employer systems.","lessons":"Employers need live identity proofing tied to the government ID at hire, verification that the issued device is physically where the employee claims to be, and alerting on KVM or remote-access hardware attached to corporate endpoints.","confidence":"Confirmed","sources":[{"title":"Justice Department Announces Coordinated, Nationwide Actions to Combat North Korean Remote Information Technology Workers","url":"https://www.justice.gov/opa/pr/justice-department-announces-coordinated-nationwide-actions-combat-north-korean-remote","publisher":"U.S. Department of Justice"},{"title":"U.S. Arrests Facilitator in North Korean IT Worker Scheme; Seizes 29 Domains and Raids 21 Laptop Farms","url":"https://thehackernews.com/2025/07/us-arrests-key-facilitator-in-north.html","publisher":"The Hacker News"}],"entry_type":"campaign","slug":"2025-us-sweep-seizes-200-computers-from-north-korean-it-worker-laptop-farms","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-us-sweep-seizes-200-computers-from-north-korean-it-worker-laptop-farms"},{"title":"Kraken advanced a North Korean fake job applicant to unmask his tradecraft","date":"2025-05","date_precision":"month","victim_org":"Kraken (Payward, Inc.)","sector":"Cryptocurrency","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":[],"ai_involvement":"Unknown","ai_notes":"Kraken reported the candidate's primary ID appeared altered, likely using details from an identity theft case two years earlier, and that he switched between voices during interviews in a way consistent with real-time coaching. Kraken did not attribute either to AI.","outcomes":["Attempt Blocked"],"loss_usd":null,"loss_note":"No loss. The candidate was never hired; Kraken advanced him through the process deliberately to collect intelligence.","records_affected":null,"threat_actor":"DPRK-linked fake IT worker network","summary":"Kraken disclosed in May 2025 that an applicant for an engineering role was a North Korean operative. Rather than reject him, the security team advanced him through the hiring process to study the tradecraft. Red flags included a name that differed from the resume during the first call, voice switching mid-interview, remote colocated Mac desktops behind VPNs, a GitHub profile tied to a breached email address, and an ID that appeared altered. An industry partner's list of email addresses linked to the group contained the exact address he had applied with.","how_it_worked":"The infiltration relied on the fact that remote hiring verifies documents and video, not people. The candidate presented a resume and a government ID built from a stolen identity, joined interviews from remote colocated Mac desktops routed through VPNs to mask his real location and network, and appeared to be coached in real time, which produced audible shifts between voices. Kraken's team, already holding a partner-supplied list of email addresses tied to the group, matched his application address and let the process continue. In the final round Chief Security Officer Nick Percoco ran trap identity verification: asking him to confirm his location live, hold up his government ID, and recommend restaurants in the city he claimed to live in. He could not answer questions about his own city or citizenship.","lessons":"Unscripted, locality-specific live verification during a video interview, cross-checked against threat-intel lists of known applicant identifiers, catches what document checks and reference calls cannot.","confidence":"Confirmed","sources":[{"title":"How we identified a North Korean hacker who tried to get a job at Kraken","url":"https://blog.kraken.com/news/how-we-identified-a-north-korean-hacker","publisher":"Kraken"},{"title":"Kraken tells how it spotted North Korean hacker in job interview","url":"https://cointelegraph.com/news/kraken-details-how-it-spotted-north-korean-hacker-in-job-interview","publisher":"Cointelegraph"}],"entry_type":"incident","slug":"2025-kraken-advanced-a-north-korean-fake-job-applicant-to-unmask-his-tradecra","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-kraken-advanced-a-north-korean-fake-job-applicant-to-unmask-his-tradecra"},{"title":"North Korean operatives adopt real-time deepfakes to pass remote job interviews","date":"2025-04","date_precision":"month","victim_org":"Companies hiring remote IT staff, including a Polish AI firm that nearly hired a synthetic candidate","sector":"Technology","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":["Deepfake Video Call","Fake Job Offer / Recruitment Lure"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"Palo Alto Networks Unit 42 demonstrated that a real-time face-swapping deepfake sufficient to fool a video interview could be built in about 70 minutes by a novice on a 2020-era consumer GPU, and linked the technique to DPRK IT-worker operations.","outcomes":["Attempt Blocked","Insider Access"],"loss_usd":null,"loss_note":"","records_affected":null,"threat_actor":"DPRK remote IT worker operations","summary":"In an April 2025 report, Palo Alto Networks Unit 42 documented North Korean IT workers' shift to real-time deepfakes during video job interviews, allowing one operator to interview repeatedly for the same role under different synthetic identities while frustrating law enforcement identification. Researchers showed a working real-time deepfake could be produced in just over an hour on a consumer GTX 3070 with no prior experience. Reporting alongside the research described a Polish AI company that encountered two apparently synthetic candidates believed to be operated by the same person.","how_it_worked":"The pretext is a normal remote job application, which means the attacker is invited into the process rather than having to break in. AI-generated faces provide identities with no real-world footprint, and real-time face-swapping lets a single operator sit multiple interviews without their true appearance ever being recorded. Recruiters treat a live video call as identity verification, so the deepfake attacks exactly the control organisations rely on. Pressure is subtle rather than overt: candidates keep pace with a competitive hiring pipeline, decline in-person meetings for plausible remote-work reasons, and rely on the interviewers' incentive to fill a role quickly. Unit 42 noted detectable artefacts when hands cross the face, during fast head movement, or under sudden lighting changes.","lessons":"Hiring should combine government-ID document authentication with liveness challenges that stress the deepfake pipeline, such as asking the candidate to pass a hand across their face or turn sharply, and interviews should be recorded for later forensic review.","confidence":"Confirmed","sources":[{"title":"False Face: Unit 42 Demonstrates the Alarming Ease of Synthetic Identity Creation","url":"https://unit42.paloaltonetworks.com/north-korean-synthetic-identity-creation/","publisher":"Palo Alto Networks Unit 42"},{"title":"North Korean Operatives Use Deepfakes in IT Job Interviews","url":"https://www.darkreading.com/remote-workforce/north-korean-operatives-deepfakes-it-job-interviews","publisher":"Dark Reading"}],"entry_type":"campaign","slug":"2025-north-korean-operatives-adopt-real-time-deepfakes-to-pass-remote-job-int","year":2025,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-north-korean-operatives-adopt-real-time-deepfakes-to-pass-remote-job-int"},{"title":"KnowBe4 hired a North Korean fake IT worker who loaded malware on day one","date":"2024-07-15","date_precision":"day","victim_org":"KnowBe4","sector":"Technology","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":["Fake Job Offer / Recruitment Lure"],"ai_involvement":"Confirmed AI-enabled","ai_notes":"The candidate's profile photo was a stock image manipulated with AI to match a stolen US identity, and KnowBe4 described the persona as an AI deepfake that held up across four video interviews.","outcomes":["Attempt Blocked","Insider Access"],"loss_usd":null,"loss_note":"No loss occurred. KnowBe4 stated no data was accessed and no systems were compromised.","records_affected":null,"threat_actor":"DPRK state-sponsored fake IT worker, confirmed with Mandiant and the FBI","summary":"Security awareness vendor KnowBe4 hired a person for a Principal Software Engineer role who turned out to be a North Korean operative using a stolen US identity and an AI-manipulated photo. The candidate cleared four video interviews, background checks and reference checks. Malware began loading on the shipped MacBook the moment it was received on July 15, 2024; the SOC detected it at 21:55 EST and contained the device by about 22:20. KnowBe4 published a detailed account and hiring-process changes.","how_it_worked":"The persona was assembled rather than invented: a real US person's identity supplied the details that background and reference checks validated, and a stock photograph enhanced with AI supplied a face consistent enough to survive four video calls. The shipping address was not a home but an IT mule laptop farm, so the corporate workstation arrived at a location that would keep it online in the US while the operative connected in by VPN from North Korea or nearby, working nights to match US hours. Within minutes of receipt the operative used a Raspberry Pi to download malware onto the workstation and began manipulating session history files. Challenged by the SOC, they claimed router troubleshooting, then went silent.","lessons":"Live identity verification against the government ID during interviews, plus device shipment to a verified address and endpoint monitoring that treats day-one activity as high-risk, are what turned this into a contained incident rather than a breach.","confidence":"Confirmed","sources":[{"title":"How a North Korean Fake IT Worker Tried to Infiltrate Us","url":"https://blog.knowbe4.com/how-a-north-korean-fake-it-worker-tried-to-infiltrate-us","publisher":"KnowBe4"},{"title":"KnowBe4 Hires Fake North Korean IT Worker, Catches New Employee Planting Malware","url":"https://www.securityweek.com/knowbe4-hires-fake-north-korean-it-worker-catches-new-employee-planting-malware/","publisher":"SecurityWeek"},{"title":"Cyber firm KnowBe4 hired a fake IT worker from North Korea","url":"https://cyberscoop.com/cyber-firm-knowbe4-hired-a-fake-it-worker-from-north-korea/","publisher":"CyberScoop"}],"entry_type":"incident","slug":"2024-knowbe4-hired-a-north-korean-fake-it-worker-who-loaded-malware-on-day-on","year":2024,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-knowbe4-hired-a-north-korean-fake-it-worker-who-loaded-malware-on-day-on"},{"title":"Munchables loses $62.5M to a developer it hired who was linked to North Korea","date":"2024-03-26","date_precision":"day","victim_org":"Munchables (NFT game on Blast)","sector":"Cryptocurrency","country":"Unknown","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Cryptocurrency Theft","Insider Access"],"loss_usd":62500000,"loss_note":"About $62.5 million in ether at the time of the exploit. All funds were recovered after the developer surrendered the private keys without a ransom being paid.","records_affected":null,"threat_actor":"A developer using the GitHub handle 'Werewolves0493', assessed by investigator ZachXBT as North Korea-linked","summary":"Munchables, a game on the Blast network, lost about $62.5 million in ether on March 26, 2024. Blockchain investigators traced the exploit to a developer the project had hired, who had been given privileged access to the contracts. ZachXBT assessed the developer as likely North Korean based on GitHub commit patterns and links to other accounts. After public pressure the developer handed over all private keys and the funds were recovered.","how_it_worked":"This was infiltration rather than intrusion: the attacker was hired. Working as a Munchables developer with contract-deployment privileges, they positioned control of stored user funds ahead of a scheduled contract upgrade, then transferred those funds to themselves before the upgrade landed, so the movement looked like part of routine deployment activity. ZachXBT's analysis of GitHub commit timing and cross-referenced accounts suggested the developer was part of a cluster of DPRK-linked personas that had recommended one another into crypto projects, meaning the vetting failure compounded across multiple hires. Recovery came from negotiation, not from any control the project held.","lessons":"Live identity verification, tied to independently corroborated employment history, is the gate for anyone who will hold deployment or upgrade keys, and no single developer should be able to move user funds without multi-party approval.","confidence":"Reported","sources":[{"title":"Munchables Exploited for $62M, North Korea-Linked Exploiter Returns Private Keys to Web 3 Firm","url":"https://www.coindesk.com/tech/2024/03/27/munchables-exploited-for-62m-ether-linked-to-rogue-north-korean-team-member","publisher":"CoinDesk"},{"title":"Explained: The Munchables Hack (March 2024)","url":"https://www.halborn.com/blog/post/explained-the-munchables-hack-march-2024","publisher":"Halborn"}],"entry_type":"incident","slug":"2024-munchables-loses-62-5m-to-a-developer-it-hired-who-was-linked-to-north-k","year":2024,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-munchables-loses-62-5m-to-a-developer-it-hired-who-was-linked-to-north-k"},{"title":"Arizona laptop farm placed North Korean IT workers at 309 US companies","date":"2023-10","date_precision":"month","victim_org":"309 US companies, including a top-five television network, an aerospace manufacturer, a US carmaker, a Silicon Valley technology firm and a luxury retailer","sector":"Technology","country":"United States","primary_vector":"Fake IT Worker Infiltration","secondary_vectors":[],"ai_involvement":"Unknown","ai_notes":"The DOJ case documents describe stolen real identities rather than AI-generated personas; no AI use was specified in the sentencing reporting.","outcomes":["Wire Fraud / Financial Loss","Identity Theft","Insider Access"],"loss_usd":17000000,"loss_note":"The scheme generated approximately $17 million in revenue for the North Korean government. Chapman was ordered to forfeit $284,555.92 intended for North Korea and to pay a $176,850 fine.","records_affected":68,"threat_actor":"DPRK IT worker network, facilitated by Christina Marie Chapman","summary":"From October 2020 to October 2023, Christina Chapman ran a 'laptop farm' from her Arizona home that let North Korean IT workers appear to be US-based remote employees. The FBI seized more than 90 laptops in an October 2023 raid; she also shipped 49 devices overseas, including to a Chinese city on the North Korean border. The operation used 68 stolen US identities to place workers at 309 companies and generated about $17 million for the DPRK. Chapman was sentenced to 102 months on July 24, 2025.","how_it_worked":"North Korean operatives applied for remote IT roles under the identities of real Americans, clearing background checks because the identities were genuine. When each employer shipped a work laptop to the address on file, that address was Chapman's house. She installed remote access software on each machine and kept them running so the workers could connect daily and appear on the employer's network from a US residential IP on US business hours. Chapman also received the direct-deposit wages, forged payroll checks and filed tax returns in the stolen names before moving the money overseas. Employers saw nothing anomalous because the device, the network location and the paperwork were all genuinely American.","lessons":"Verifying that a shipped device is actually in the hands of the person hired, through live video identity checks at onboarding and device-location attestation, is what breaks the laptop farm model.","confidence":"Confirmed","sources":[{"title":"Arizona woman sentenced to 8.5 years for running North Korean laptop farm","url":"https://therecord.media/arizona-woman-sentenced-north-korean-laptop-farm","publisher":"The Record (Recorded Future News)"},{"title":"Arizona woman imprisoned for $17M North Korean remote workers scheme","url":"https://www.upi.com/Top_News/US/2025/07/24/chapman-north-korea-remote-workers-fraud/7551753396658/","publisher":"UPI"}],"entry_type":"incident","slug":"2023-arizona-laptop-farm-placed-north-korean-it-workers-at-309-us-companies","year":2023,"loss_kind":"criminal_proceeds","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-arizona-laptop-farm-placed-north-korean-it-workers-at-309-us-companies"}]}