Inside a “laptop farm” run by a 50-year-old US woman that let DPRK IT workers pose as US tech staff and illegally earn $17.1M from more than 300 US companies
A LinkedIn message drew a former waitress in Minnesota into a type of intricate scam involving illegal paychecks and stolen data Bluesky: @hatr and @martijnrasser . Forums: Slashdot Bluesky: Hakan / @hatr : „The workers had their company laptops sent to her address. She'd unpack them, install remote access software and power them on for the North Koreans to log on. She made sure connections ran smoothly and helped troubleshoot any issues. www.wsj.com/business/nor... Martijn Rasser / @martijnrasser : Broke and desperate for work, a former waitress finally found a side hustle: helping North Korea infiltrate U.S. tech companies — www.wsj.com/business/nor... Forums: Msmash / Slashdot : North Korean ‘Laptop Farm’ Operation Netted $17 Million Through Unwitting American Accomplice
Context & Ripple Effects
This case adds operational detail to a campaign authorities had already described as involving North Korean remote workers using false identities to collect U.S. wages, as in the earlier FBI and DOJ warning. It also connects to charges over hiring North Korea-linked remote IT workers at more than 300 companies, showing how a U.S.-based device intermediary could make remote impersonation workable.
The significance is not merely fraudulent hiring: company-issued machines, payroll access, and technical support created a physical bridge between U.S. employers and workers operating abroad, with alleged data theft alongside wage diversion.
First-order effects
- More than 300 affected employers face potential exposure from having corporate laptops and employee access operated through a U.S. intermediary on behalf of undisclosed workers.
- The reported setup turns laptop receipt, remote-access installation, and connection troubleshooting into evidence-bearing control points for investigators and immediate review points for employers.
Second-order effects
- Employers and staffing partners will face pressure to verify not just identity documents but device custody, location signals, and who administers remote access after onboarding.
- The model helps explain why enforcement later focused on a broader operation using U.S. laptop farms to support impersonated remote hires; domestic facilitators are a critical dependency rather than a peripheral detail.
Third-order effects
- If this pattern persists, remote-work security will increasingly treat identity assurance and endpoint custody as linked controls, rather than separate HR and IT responsibilities.
- The cases point to a durable enforcement focus on the domestic infrastructure that enables cross-border labor impersonation, potentially raising compliance costs for distributed hiring without eliminating the appeal of remote access.
The trend: Remote-work fraud is evolving from identity-document deception into an access-layer problem centered on who physically controls corporate endpoints and credentials.