Skip to content
NetarxImpact Database
Database

Social engineering incidents

277 entries spanning 1995 to 2026. Filter by how the attacker reached the human, what it cost, and whether AI was involved.

Showing 8 of 8 entries
November 2025·Technology

Five plead guilty to helping North Korean IT workers infiltrate 136 US companies

136 US companies (victims of the fake-worker scheme) · United States

The US Justice Department announced in November 2025 that five people, four US nationals and a Ukrainian, had pleaded guilty to charges including wire fraud conspiracy and aggravated identity theft for enabling North Korean IT workers to obtain remote jobs at American companies. The conduct affected more than 136 US companies and generated approximately $2.2 million for North Korea. One defendant ran a site selling stolen identities and managed roughly 871 proxy identities and at least three laptop farms.

Fake IT Worker Infiltration
$2.2M criminal proceedsConfirmed2 sources
July 24, 2025·Technology

Arizona woman sentenced to 8.5 years for North Korean IT worker laptop farm

More than 300 US companies (victims of the fake-worker scheme) · United States

A US District Court in Washington DC sentenced Christina Marie Chapman of Arizona to 102 months in prison on 24 July 2025 for running a 'laptop farm' that let North Korean IT workers pose as US-based employees. Prosecutors said the scheme touched more than 300 US companies, used the stolen identities of dozens of Americans, and generated roughly $17 million for the North Korean government. She also shipped company laptops overseas.

Fake IT Worker Infiltration
$17.0M criminal proceedsConfirmed2 sources
October 2023·Technology

Arizona laptop farm placed North Korean IT workers at 309 US companies

309 US companies, including a top-five television network, an aerospace manufacturer, a US carmaker, a Silicon Valley technology firm and a luxury retailer · United States

From October 2020 to October 2023, Christina Chapman ran a 'laptop farm' from her Arizona home that let North Korean IT workers appear to be US-based remote employees. The FBI seized more than 90 laptops in an October 2023 raid; she also shipped 49 devices overseas, including to a Chinese city on the North Korean border. The operation used 68 stolen US identities to place workers at 309 companies and generated about $17 million for the DPRK. Chapman was sentenced to 102 months on July 24, 2025.

Fake IT Worker Infiltration
$17.0M criminal proceeds68 affectedConfirmed2 sources
June 30, 2025·TechnologyCampaign

US sweep seizes 200 computers from North Korean IT worker laptop farms

More than 100 US companies, including many Fortune 500 firms · United States

On June 30, 2025 the Justice Department announced coordinated nationwide actions against North Korea's remote IT worker schemes. Between June 10 and 17, agents searched 21 laptop farms across 14 states and seized nearly 200 computers, along with 21 fraudulent websites and 29 financial accounts. One US national, Zhenxing Wang of New Jersey, was arrested; another agreed to plead guilty. Court documents describe more than 100 victim companies, and cases included theft of export-controlled military technology.

Fake IT Worker Infiltration
Confirmed2 sources
July 2026·Government

FBI identifies North Korean remote IT worker employed by a US federal agency

Unnamed US federal agency · United States

FBI deputy assistant director Todd Hemmen disclosed at a conference on 28 July 2026 that the Bureau had identified, the previous week, a North Korean remote IT worker who was working for the US federal government. The agency involved, the duration of the placement, what systems the individual reached and whether any sensitive information was compromised have not been made public. Experts assess the placement was most likely a contract role, since permanent federal positions require background investigations.

Fake IT Worker Infiltration
Confirmed2 sources
April 2025·TechnologyCampaign

North Korean operatives adopt real-time deepfakes to pass remote job interviews

Companies hiring remote IT staff, including a Polish AI firm that nearly hired a synthetic candidate · United States

In an April 2025 report, Palo Alto Networks Unit 42 documented North Korean IT workers' shift to real-time deepfakes during video job interviews, allowing one operator to interview repeatedly for the same role under different synthetic identities while frustrating law enforcement identification. Researchers showed a working real-time deepfake could be produced in just over an hour on a consumer GTX 3070 with no prior experience. Reporting alongside the research described a Polish AI company that encountered two apparently synthetic candidates believed to be operated by the same person.

Fake IT Worker InfiltrationConfirmed AI-enabledAttempt blocked
Confirmed2 sources
May 2025·Cryptocurrency

Kraken advanced a North Korean fake job applicant to unmask his tradecraft

Kraken (Payward, Inc.) · United States

Kraken disclosed in May 2025 that an applicant for an engineering role was a North Korean operative. Rather than reject him, the security team advanced him through the hiring process to study the tradecraft. Red flags included a name that differed from the resume during the first call, voice switching mid-interview, remote colocated Mac desktops behind VPNs, a GitHub profile tied to a breached email address, and an ID that appeared altered. An industry partner's list of email addresses linked to the group contained the exact address he had applied with.

Fake IT Worker InfiltrationAttempt blocked
Confirmed2 sources
March 26, 2024·Cryptocurrency

Munchables loses $62.5M to a developer it hired who was linked to North Korea

Munchables (NFT game on Blast) · Unknown

Munchables, a game on the Blast network, lost about $62.5 million in ether on March 26, 2024. Blockchain investigators traced the exploit to a developer the project had hired, who had been given privileged access to the contracts. ZachXBT assessed the developer as likely North Korean based on GitHub commit patterns and links to other accounts. After public pressure the developer handed over all private keys and the funds were recovered.

Fake IT Worker Infiltration
$62.5M funds lostReported2 sources

Entry types: Incident, Campaign, Benchmark. Aggregate agency statistics are kept as benchmarks and are never summed into the counters. Methodology. Machine-readable version of this page: global-social-engineering-impact-da.vercel.app/api/incidents?q=DPRK+IT+worker+network.