North Korean IT operatives posing as foreign remote developers at Western companies secretly funnel millions in wages to Kim Jong Un’s regime to help fund its nuclear weapons program.

North Korean IT operatives posing as foreign remote developers at Western companies secretly funnel millions in wages to Kim Jong Un’s regime to help fund its nuclear weapons program.
WSJ
Revision history

3 recorded changes

Want your article here?

Promote with Leviathan News

U.S. and allied security agencies say North Korea has built a large, state-directed network of information technology workers who secretly obtain remote jobs at Western companies under false identities, then send most of their earnings back to Pyongyang to help finance the regime and its sanctioned nuclear and missile programs. These operatives typically pose as foreign or U.S.-based developers on major recruiting and freelance platforms, using stolen or purchased identities, forged documents, and AI-enhanced profiles and interview deepfakes to pass background checks and video interviews at firms ranging from startups to Fortune 500 companies. Once hired, they access company systems through laptops shipped to U.S. “laptop farms” or other proxy locations, and route six‑figure annual salaries through complex payment chains that ultimately deliver millions of dollars to the Kim Jong Un regime despite U.S. and U.N. sanctions. According to U.S. government advisories and independent cybersecurity researchers, this scheme has grown significantly with the rise of post‑pandemic remote work and persistent shortages of skilled IT talent. A standard playbook has emerged: North Korean workers assume hijacked or synthetic identities, mass‑apply for software engineering, DevOps, and support roles, rely on accomplices in countries like China and the United States to receive hardware and payments, and sometimes use their access not only to earn salaries but to steal corporate data and conduct further fraud. The FBI, State Department, and Treasury warn that each worker can earn up to roughly $300,000 per year, and collectively these operations may generate tens of millions of dollars annually in hard currency that North Korea uses to circumvent sanctions and support weapons development. For Western firms, the phenomenon is both a sanctions and compliance risk and a security threat, prompting governments and experts to urge tighter identity verification, closer coordination between HR and security teams, and more scrutiny of remote hires and third‑party IT contractors to detect red flags such as AI‑generated headshots, unverifiable work histories, unusual working hours, and frequent changes in banking details. "entities":["Democratic People’s Republic of Korea (North Korea)","Kim Jong Un","North Korean IT workers / operatives","U.S. Federal Bureau of Investigation (FBI)","U.S. Department of State","U.S. Department of the Treasury","Fortune 500 companies","Christina Chapman","NISOS (cybersecurity firm)","U.S.-based \"laptop farms\"","Axios","Politico","PBS NewsHour"]}`

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on nuclear

Comments