/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Google researchers say DPRK's IT workers are fraudulently securing remote roles at companies in Germany, Portugal, and the UK, after facing sanctions in the US

North Korea's IT workers have expanded operations beyond the United States and are now increasingly targeting organizations across Europe.

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

This is a geographic extension of a long-running remote-work identity-fraud campaign. Earlier coverage described DPRK workers using false identities to obtain US roles and route wages back to North Korea; sanctions pressure appears to be shifting the same playbook toward European employers.

The risk has also moved beyond illicit payroll flows: the FBI previously warned that fraudulently hired workers could use their access to steal source code and extort employers. Google’s findings make hiring verification and device control a more immediate concern for companies in Germany, Portugal, and the UK.

First-order effects

  • European employers recruiting remote technical staff face a higher near-term risk that applicant identity, location, and work authorization do not match the person performing the job.
  • Companies that identify suspect hires may need to review access, credentials, and code repositories, given the previously reported risk of source-code theft and extortion through insider access.

Second-order effects

  • Recruiters, staffing firms, and employer-of-record providers will face pressure to strengthen identity and location checks without making legitimate cross-border hiring materially slower.
  • Security teams are likely to treat remote onboarding as an access-control issue as well as an HR process, emphasizing managed devices and clearer custody over corporate compute assets.

Third-order effects

  • If enforcement in one market repeatedly redirects these operations to another, identity assurance for distributed work may become a baseline requirement across international hiring rather than a US-focused sanctions control.
  • The pattern points to growing convergence between sanctions compliance, workforce screening, and insider-risk security, though the scale of European exposure remains unclear from this report alone.

The trend: Sanctions and enforcement are pushing state-linked remote-worker fraud into new labor markets, making trusted identity and managed access central to global hiring.

Discussion

  • @dannypalmer Danny Palmer on bluesky
    Tsk, can't believe I'm having to compete for work with the North Koreans these days. smh.  —  cloud.google.com/blog/topics/ ...
  • @bushidotoken Will on x
    Great new report from @Mandiant on 🇰🇵DPRK IT Workers expanding to the Europe, 🇬🇧UK included! It's my gut feeling that UK orgs are not prepared for this threat at all. Wonder if @acasorguk has guidance on terminating 🇰🇵 IT Workers 😬 https://cloud.google.com/...
  • @moo9000 Mikko Ohtamaa on x
    The best way to mitigate North Korean risk is to use professional software development languages like Python and PostgreSQL. North Koreans have low skill levels; they can only learn JavaScript, React, Node and MongoDB. https://cloud.google.com/... [image]
  • @lindseyod123 Lindsey O'Donnell Welch on x
    More fake North Korean IT worker things: -increase in active operations in Europe -intensified extortion campaigns -move to conduct operations within corporate virtualized infrastructure https://cloud.google.com/...
  • @mandiant @mandiant on x
    🚨 DPRK IT Workers Expanding! GTIG is seeing increased DPRK IT worker ops in Europe, confirming expansion beyond the U.S. Since our 2024 report, they've grown in scope and scale, with evolving tactics. Learn the risks: https://cloud.google.com/... [image]
  • r/europe r on reddit
    North Korean IT worker army expands operations in Europe
  • r/cybersecurity r on reddit
    North Korean IT worker army expands operations in Europe