North Korean IT Workers Have Infiltrated Hundreds of U.S. Companies — Here's What's Happening

The FBI believes thousands of North Korean nationals have infiltrated the U.S. workforce by assuming American identities to land remote IT jobs, generating hundreds of millions of dollars in illicit revenue for the DPRK regime. The numbers are concrete: North Korean workers collected at least $17.1 million in paychecks from more than 300 American companies, according to WSJ. The FBI's updated guidance, published July 2025, describes a threat spanning thousands of workers and broad sector exposure, with wages flowing back to Pyongyang through layered facilitation networks (FBI).
The scheme's mechanics are relatively simple. North Korean operatives, often working from China and Russia, fabricate identities, forge credentials, and apply for remote software development, data entry, and IT support roles at U.S. firms. Some use stolen American identities. Once hired, they perform the work well enough to keep their jobs while funneling salary to the regime. Beyond wages, the positions grant network access, creating opportunities for intellectual property theft and corporate espionage (WSJ). A defector interviewed by the Wall Street Journal in February 2026 detailed how the remote-work scam generates large revenue for Pyongyang, including funding for its nuclear program (WSJ.
One actor has been publicly named. WageMole, identified as a North Korean state-sponsored advanced persistent threat (APT) group — a category of highly skilled, government-backed hacking operation — employs social engineering and technical methods to support the IT worker fraud pipeline, according to a U.S. State Department alert issued August 6, 2026, in coordination with international partners (State Department).
The Enforcement Response
The U.S. government has responded with coordinated actions across multiple agencies. On June 30, 2025, the Justice Department announced nationwide enforcement actions targeting North Korean remote IT workers' illicit revenue generation (DOJ. The FBI followed with updated guidance on July 23, 2025, supplementing its earlier alerts to U.S. businesses on detection and mitigation (FBI.
OFAC — the Treasury Department's Office of Foreign Assets Control, which administers U.S. economic sanctions — has conducted a series of designations targeting the facilitation infrastructure. On July 8, 2025, the agency designated an individual named Asatryan under Executive Order 13722 for attempting to facilitate the exportation of DPRK workers (Treasury. Two weeks later, on July 24, OFAC designated a clandestine IT worker network that facilitated the movement of overseas workers and procurement for the DPRK's nuclear program (Treasury. On August 27, 2025, Treasury sanctioned a fraud network whose overseas IT workers steal data from American businesses (Treasury. A broader action on November 4, 2025, designated eight individuals and two entities connected to DPRK banking and institutions (Treasury. Most recently, on March 12, 2026, OFAC sanctioned a network of facilitators involved in DPRK IT worker fraud schemes targeting American companies (Treasury.
The pattern across these actions is worth noting. Each designation peels back another layer of the facilitation stack — from individual recruiters to banking channels to procurement networks. The March 2026 action suggests OFAC is still mapping the full topology, not winding down.
The Financial and Security Stakes
The revenue figures matter in context. The FBI's estimate of hundreds of millions of dollars in aggregate earnings, even measured against the $17.1 million attributed to a specific cohort of over 300 companies, is a meaningful hard-currency stream for a heavily sanctioned economy. The DPRK's access to dollars is constrained by multilateral sanctions; remote-work fraud converts Western corporate payrolls into a sanctions-evasion mechanism. Every paycheck processed through a U.S. payroll system, routed through a domestic bank account controlled by a facilitator, and ultimately remitted to Pyongyang functions as a de facto sanctions bypass.
For corporate compliance teams, the operational risk is twofold. First, the direct financial exposure: salaries paid to fraudulent employees, potential forfeitures, and the investigative costs of remediation. Second, and more consequential, the data access dimension. Remote IT workers with legitimate credentials can exfiltrate — meaning secretly copy and remove — source code, customer data, proprietary models, and infrastructure configurations before detection. The Treasury's August 2025 designation explicitly flagged data theft from American businesses as a purpose of the network.
The identity-fraud angle complicates standard KYC (Know Your Customer) and employment verification. Workers using stolen American identities pass background checks designed to verify identity, not to assess geopolitical provenance. The FBI's guidance update reflects this gap, though the practical detection burden falls on HR, IT security, and compliance functions working in coordination — an organizational design most firms have not optimized for.
The broader context here is one of escalation outpacing defense. The shift from scattered warnings in 2024 to a sustained multi-agency enforcement campaign through 2025 and into 2026 suggests the threat has grown faster than mitigation has matured. The involvement of a named APT group (WageMole) in the IT worker pipeline elevates this from a fraud problem to a state-sponsored, cyber-enabled revenue operation. Firms that treat these hires as a payroll anomaly rather than a network-access incident are underestimating the exposure. The intersection of HR onboarding, identity verification, and insider-threat monitoring is where this threat lives, and it is a seam that most corporate security architectures do not cover well.


