The FBI and the DOJ say thousands of IT workers sent by North Korea to work remotely for US companies using false IDs have sent millions in wages to North Korea
And this wouldn't be happening if US companies would invest in training for local workers. They want cheap labor, and they don't care about the dangers of giving hostile nations access to tech. Bluesky: Conrad Ohashi / @conrado.bsky.social : Wow that's some James Bond stuff but for doing IT work in Silicon Valley designing apps that make custom handbags for microdogs. [embedded post] X: @dojnatsec : Justice Department Announces Court-Authorized Action to Disrupt Illicit Revenue Generation Efforts of Democratic People's Republic of Korea Information Technology Workers https://www.justice.gov/... Kim Zetter / @kimzetter : In 2022 and 2023 the gov seized $1.5 million of the revenue earned by the workers and this week it shut down 17 domains. “Employers need to be cautious about who they are hiring and who they are allowing to access their IT systems,” https://www.justice.gov/... Kim Zetter / @kimzetter : Thousands of IT workers contracting with US companies have for years secretly sent millions of dollars of their wages to North Korea to fund its weapons programs. They worked remotely with companies around US and used false identities to get jobs, per FBI https://apnews.com/... LinkedIn: Gina Moore : Yikes! Know your remote workers! Roger Grimes : North Korea had thousands of NK IT workers work for companies around the world. — https://lnkd.in/eMFK945a Forums: r/technews : DoJ says North Korean IT workers were sent abroad to help finance weapons programs | The FBI says companies employing freelance IT workers “more than likely” hired one of these bad actors. r/worldnews : FBI says North Korea deployed thousands of IT workers to get remote jobs in US with fake IDs r/cybersecurity : FBI: Thousands of remote IT workers sent wages to North Korea | AP News r/technology : FBI says North Korea deployed thousands of IT workers to get remote jobs in US with fake IDs r/LateStageCapitalism : Thousands of remote IT workers sent wages to North Korea to help fund weapons program, FBI says r/antiwork : Thousands of remote IT workers sent wages to North Korea to help fund weapons program, FBI says r/geopolitics : FBI: Thousands of remote IT workers sent wages to North Korea to help fund weapons program r/law : FBI: Thousands of remote IT workers sent wages to North Korea to help fund weapons program r/news : FBI: Thousands of remote IT workers sent wages to North Korea to help fund weapons program
Context & Ripple Effects
This enforcement action sits in a longer record of North Korean operatives using remote-work identities to access U.S. employers; related coverage had already described infiltration of U.S. crypto firms through purported remote hires.
Later cases show the mechanism becoming more operationally visible, including a U.S. takedown of an impersonation network that relied on domestic “laptop farms” to support remote-job fraud. That makes this early seizure and domain disruption a meaningful marker of how law enforcement began treating hiring infrastructure as part of the revenue pipeline.
First-order effects
- The DOJ’s seizure of $1.5 million and shutdown of 17 domains directly interrupt identified payment and coordination channels used by the North Korean IT-worker scheme.
- U.S. employers that hired through false identities face an immediate need to review worker identity, device access, and payroll relationships, while the FBI and DOJ gain an enforcement precedent for targeting the supporting infrastructure.
Second-order effects
- Recruiters, staffing intermediaries, and remote-work platforms are likely to face stronger customer demands for identity verification and clearer audit trails, since fraudulent employment can create both sanctions and security exposure.
- The disruption raises the cost of operating intermediary networks; subsequent allegations that hundreds of companies were deceived by North Korea-linked hires underscore the potential scale of employers’ screening problem.
Third-order effects
- If enforcement and employer controls continue to mature, remote hiring will increasingly be treated as a security-control surface rather than solely an HR process, linking identity proofing to endpoint and access governance.
- The broader structural risk is that globally distributed digital labor can be repurposed as a state-linked revenue channel; effective mitigation will depend on coordinated employer, platform, and law-enforcement controls rather than isolated company checks.
The trend: This is one data point in the securitization of remote hiring, as governments and employers confront identity fraud as a route to privileged digital access and illicit cross-border revenue.