North Korea Is Secretly Working Remote U.S. Tech Jobs — and the Government Is Cracking Down

The FBI believes thousands of North Korean nationals have been pretending to be Americans to get remote IT jobs at U.S. companies, earning hundreds of millions of dollars for the North Korean government. The numbers are specific: North Korean workers collected at least $17.1 million in paychecks from more than 300 American companies, according to WSJ. The FBI's updated guidance, published July 2025, describes a threat involving thousands of workers across many industries, with wages flowing back to North Korea through networks of middlemen (FBI).
The scheme works like this. North Korean operatives, often working from China and Russia, make up identities, forge qualifications, and apply for remote jobs in software development, data entry, and IT support at U.S. firms. Some use stolen American identities. Once hired, they do the work well enough to stay employed while sending their salaries to the regime. The jobs also give them access to company computer networks, opening the door to theft of trade secrets and sensitive information (WSJ. A defector interviewed by the Wall Street Journal in February 2026 explained how the remote-work scam generates large revenue for North Korea, including money for its nuclear program (WSJ.
One specific group has been publicly named. WageMole, identified as a North Korean government-backed hacking team, uses manipulation and technical tricks to support the fake IT worker operation, according to a U.S. State Department alert issued August 6, 2026, in coordination with international partners (State Department.
The Enforcement Response
The U.S. government has responded with coordinated actions across multiple agencies. On June 30, 2025, the Justice Department announced nationwide enforcement actions targeting North Korean remote IT workers' illicit revenue (DOJ. The FBI followed with updated guidance on July 23, 2025, adding to its earlier alerts to U.S. businesses on how to detect and protect against the scheme (FBI.
The Treasury Department's sanctions office has also taken a series of actions. On July 8, 2025, it sanctioned an individual named Asatryan for trying to help move North Korean workers overseas (Treasury. Two weeks later, on July 24, it sanctioned a hidden network that moved workers and obtained supplies for North Korea's nuclear program (Treasury. On August 27, 2025, Treasury sanctioned a fraud network whose overseas IT workers steal data from American businesses (Treasury. A broader action on November 4, 2025, sanctioned eight individuals and two entities connected to North Korean banking (Treasury. Most recently, on March 12, 2026, the sanctions office targeted a network of facilitators involved in the IT worker fraud schemes against American companies (Treasury.
The pattern is worth noting. Each sanction peels back another layer of the support structure — from individual recruiters to banking channels to supply networks. The March 2026 action suggests the government is still uncovering the full network, not wrapping up.
The Financial and Security Stakes
The revenue figures matter because North Korea is one of the most heavily sanctioned economies in the world, meaning it has very limited access to U.S. dollars. The FBI's estimate of hundreds of millions in total earnings, even compared to the $17.1 million tied to those 300+ companies, is a significant source of foreign money for the regime. Think of it this way: every paycheck a U.S. company sends to one of these fake employees, which then gets routed through a U.S. bank and eventually sent to North Korea, works as a way around the sanctions designed to cut the regime off from the global financial system.
For companies, the risk is twofold. First, the direct financial hit: salaries paid to fake employees, potential legal penalties, and the cost of investigating what went wrong. Second, and more serious, the data access problem. Remote IT workers with valid login credentials can quietly copy and walk away with source code, customer data, proprietary models, and infrastructure details before anyone notices. The Treasury's August 2025 sanction explicitly called out data theft from American businesses as a goal of the network.
The identity-fraud angle also exposes a gap in how companies vet new hires. Standard background checks are designed to confirm that someone is who they say they are, not to figure out whether that person might actually be a foreign operative. The FBI's guidance update reflects this gap, but the practical work of catching these workers falls on HR, IT security, and compliance teams coordinating together — something most companies are not set up to do well.
The broader context here is that the threat appears to be growing faster than the defenses against it. The shift from scattered warnings in 2024 to a sustained, multi-agency enforcement campaign through 2025 and into 2026 suggests as much. The involvement of a named government-backed hacking group (WageMole) in the fake worker pipeline elevates this from a simple fraud problem to a state-run operation. Companies that treat these hires as a payroll mistake rather than a network-security breach are underestimating the danger. The gap between hiring processes and security monitoring is where this threat thrives, and most corporate security systems are not built to cover it.


