North Korea's $800 million remote-work infiltration puts corporate IT hiring in focus
The catalyst is a paycheck, not a breach. The Treasury Department's accounting shows North Korean operatives running a state-directed IT workforce that generated nearly $800 million in 2024, money the regime routes toward weapons programs. Treasury Secretary Scott Bessent said the operatives "weaponize sensitive data and extort businesses for substantial payments" after gaining trusted access from the inside.
Key takeaways
- North Korean state-directed IT operatives generated nearly $800 million in 2024 by using stolen American identities to land remote jobs, with the money routed toward the regime's weapons programs.
- Threat hunter Michael Barnhart sampled 20 Fortune 500 companies and found evidence North Korean workers had applied to, worked for, or targeted 18 of them.
- The workers route company laptops through U.S.-based 'laptop farms' and now use generative AI during live job interviews to answer questions in real time.
- Christina Chapman, an Arizona resident who ran a laptop farm helping workers land jobs at more than 300 U.S. companies, was sentenced in 2025 to more than eight years in federal prison.
- Barnhart recommends companies run identity checks alongside traditional background checks to confirm the person in a video interview matches the credentials on file.
The catalyst is a paycheck, not a breach. The Treasury Department's accounting shows North Korean operatives running a state-directed IT workforce that generated nearly $800 million in 2024, money the regime routes toward weapons programs. Treasury Secretary Scott Bessent said the operatives "weaponize sensitive data and extort businesses for substantial payments" after gaining trusted access from the inside.
The mechanism is straightforward. Workers apply to remote jobs using stolen American identities, route company laptops through U.S.-based addresses called laptop farms, and now use generative AI in live job interviews to answer questions in real time. Michael Barnhart, a threat hunter at cybersecurity firm DTEX and former Army intelligence specialist who built Mandiant's North Korea operation before the firm was acquired by Google, sampled 20 Fortune 500 companies and found evidence the workers had applied to, worked for, or targeted 18 of them.
Inside the operation
The remote-work shift accelerated the threat, but the operation has been running for more than a decade. North Korea identifies children as young as seven with aptitude in math, science, and technology and routes them into specialized training pipelines that can end in overseas IT placement or, for the most capable, elite hacking units including APT43 and APT45.
Revenue is where the threat analysis used to stop. Barnhart said investigators eventually found IT workers intertwined with North Korea's more sophisticated hacking operations. He has confirmed workers with placement inside critical infrastructure and defense-related organizations. A worker at a retail company collects a paycheck. A worker inside a defense contractor can hand credentials directly to North Korea's cyber units without those units ever breaking through an exterior firewall.
What to watch
Christina Chapman, an Arizona resident who operated a laptop farm, helped North Korean IT workers land jobs at more than 300 U.S. companies and was sentenced in 2025 to more than eight years in federal prison. U.S. Attorney Jeanine Ferris Pirro said in a statement that North Korea "is an enemy within" perpetrating fraud on American companies, citizens, and banks.
Treasury says wages from the operation fund North Korea's weapons and ballistic missile programs. Ukrainian President Volodymyr Zelenskyy said Russia is preparing to deploy an additional North Korean contingent and has received ballistic missiles from Pyongyang. Barnhart draws the line between those two data points directly: American payroll flows to Pyongyang, and Pyongyang supplies Moscow.
For companies, Barnhart recommends running identity checks alongside traditional background checks to verify that the person in a video interview matches the credentials on file. Federal enforcement will only reach so far given the scale and the fact that most of the workers operate beyond U.S. jurisdiction. "We have to rely on our own policies," he said.
Related reading
Filed by the digital assets desk of MarketPR on August 19, 2026. Source: foxnews.com. Indicative figures are not investment advice.