What happened
The US Justice Department announced in November 2025 that five people, four US nationals and a Ukrainian, had pleaded guilty to charges including wire fraud conspiracy and aggravated identity theft for enabling North Korean IT workers to obtain remote jobs at American companies. The conduct affected more than 136 US companies and generated approximately $2.2 million for North Korea. One defendant ran a site selling stolen identities and managed roughly 871 proxy identities and at least three laptop farms.
How the deception worked
Three of the defendants let overseas workers use their real US identities to apply for and hold remote IT jobs, so background checks returned clean results for genuine Americans. Others hosted company-issued laptops at their homes and installed remote desktop software so workers abroad appeared to be sitting at a US desk. A fourth trafficked stolen and rented identities through a website marketed at overseas jobseekers. The deception targeted HR and IT onboarding rather than any technical control: the trust signals abused were verified identity documents, a US shipping address and a US-looking network origin, all of which onboarding processes treat as proof of presence.
The control that would have caught it· our reading, not a claim from the sources
Tie identity verification to a live check at onboarding and re-verify periodically; monitor corporate laptops for remote-control tooling and for logins whose network geography does not match the employee's stated location.
Sources (2)
- Five Plead Guilty in U.S. for Helping North Korean IT Workers Infiltrate 136 CompaniesThe Hacker News·thehackernews.comOpen ↗
- Ukrainian national pleads guilty in 'laptop farm' scheme that generated income for North Korean IT workersUS Department of Justice·justice.govOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.