Google researchers say DPRK's IT workers are fraudulently securing remote roles at companies in Germany, Portugal, and the UK, after facing sanctions in the US
North Korea's IT workers have expanded operations beyond the United States and are now increasingly targeting organizations across Europe.
Context & Ripple Effects
This is a geographic extension of a long-running remote-work identity-fraud campaign. Earlier coverage described DPRK workers using false identities to obtain US roles and route wages back to North Korea; sanctions pressure appears to be shifting the same playbook toward European employers.
The risk has also moved beyond illicit payroll flows: the FBI previously warned that fraudulently hired workers could use their access to steal source code and extort employers. Google’s findings make hiring verification and device control a more immediate concern for companies in Germany, Portugal, and the UK.
First-order effects
- European employers recruiting remote technical staff face a higher near-term risk that applicant identity, location, and work authorization do not match the person performing the job.
- Companies that identify suspect hires may need to review access, credentials, and code repositories, given the previously reported risk of source-code theft and extortion through insider access.
Second-order effects
- Recruiters, staffing firms, and employer-of-record providers will face pressure to strengthen identity and location checks without making legitimate cross-border hiring materially slower.
- Security teams are likely to treat remote onboarding as an access-control issue as well as an HR process, emphasizing managed devices and clearer custody over corporate compute assets.
Third-order effects
- If enforcement in one market repeatedly redirects these operations to another, identity assurance for distributed work may become a baseline requirement across international hiring rather than a US-focused sanctions control.
- The pattern points to growing convergence between sanctions compliance, workforce screening, and insider-risk security, though the scale of European exposure remains unclear from this report alone.
The trend: Sanctions and enforcement are pushing state-linked remote-worker fraud into new labor markets, making trusted identity and managed access central to global hiring.