Skip to content
NetarxImpact Database
Fake IT Worker InfiltrationUnknownConfirmed

Arizona laptop farm placed North Korean IT workers at 309 US companies

309 US companies, including a top-five television network, an aerospace manufacturer, a US carmaker, a Silicon Valley technology firm and a luxury retailer · Technology · United States · October 2023

Criminal proceeds
$17,000,000
What the attackers earned. Not the same as what the victims lost, and often much smaller.
The scheme generated approximately $17 million in revenue for the North Korean government. Chapman was ordered to forfeit $284,555.92 intended for North Korea and to pay a $176,850 fine.
People or records affected
68
68 as reported

What happened

From October 2020 to October 2023, Christina Chapman ran a 'laptop farm' from her Arizona home that let North Korean IT workers appear to be US-based remote employees. The FBI seized more than 90 laptops in an October 2023 raid; she also shipped 49 devices overseas, including to a Chinese city on the North Korean border. The operation used 68 stolen US identities to place workers at 309 companies and generated about $17 million for the DPRK. Chapman was sentenced to 102 months on July 24, 2025.

How the deception worked

North Korean operatives applied for remote IT roles under the identities of real Americans, clearing background checks because the identities were genuine. When each employer shipped a work laptop to the address on file, that address was Chapman's house. She installed remote access software on each machine and kept them running so the workers could connect daily and appear on the employer's network from a US residential IP on US business hours. Chapman also received the direct-deposit wages, forged payroll checks and filed tax returns in the stolen names before moving the money overseas. Employers saw nothing anomalous because the device, the network location and the paperwork were all genuinely American.

AI involvement · Unknown

The DOJ case documents describe stolen real identities rather than AI-generated personas; no AI use was specified in the sentencing reporting.

The control that would have caught it· our reading, not a claim from the sources

Verifying that a shipped device is actually in the hands of the person hired, through live video identity checks at onboarding and device-location attestation, is what breaks the laptop farm model.

Sources (2)

  1. Arizona woman sentenced to 8.5 years for running North Korean laptop farm
    The Record (Recorded Future News)·therecord.mediaOpen ↗
  2. Arizona woman imprisoned for $17M North Korean remote workers scheme
    UPI·upi.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.