What happened
FBI deputy assistant director Todd Hemmen disclosed at a conference on 28 July 2026 that the Bureau had identified, the previous week, a North Korean remote IT worker who was working for the US federal government. The agency involved, the duration of the placement, what systems the individual reached and whether any sensitive information was compromised have not been made public. Experts assess the placement was most likely a contract role, since permanent federal positions require background investigations.
How the deception worked
The DPRK remote IT worker programme wins access by being hired rather than by breaking in. Operatives apply for remote technical roles using stolen or fabricated identities, often with US-based facilitators who host company laptops, sit for identity checks, or lend a domestic address and bank account so that pay and equipment appear to land with a real person in the United States. Video interviews and onboarding checks are handled by the operative or the facilitator. Once employed the worker holds legitimate credentials and normal access, which is why detection typically comes from behavioural or payroll anomalies rather than security tooling.
The control that would have caught it· our reading, not a claim from the sources
Live identity proofing at hire and again at equipment issue, plus checks that payroll destinations and laptop network locations match the claimed residence, are what surface these placements.
Sources (2)
- FBI investigating North Korean remote IT staffer working for US agencyFederal News Network·federalnewsnetwork.comOpen ↗
- FBI finds North Korean IT worker inside federal agencyTheStreet·thestreet.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.