Thousands of North Korean IT workers are infiltrating corporate America
North Korea has deployed thousands of operatives disguised as remote IT professionals to gain employment at American corporations. Using stolen U.S. identities, distributed computing setups, and artificial intelligence tools to fabricate credible résumés and interview responses, these workers successfully secure positions and redirect earnings to Pyongyang.
The scheme operates as both an economic extraction and security vulnerability. Once hired, operatives obtain legitimate network credentials and insider access that facilitates data theft, corporate extortion, industrial espionage, and sophisticated cyberattacks. Treasury Department data shows the operation generated nearly $800 million during 2024 alone, providing substantial funding for North Korea's weapons development despite international sanctions.
- North Korean operatives posing as remote IT workers have infiltrated U.S. companies using stolen identities, artificial intelligence, and coordinated 'laptop farms'
- The 2024 operation generated approximately $800 million to fund Pyongyang's weapons programme, whilst creating network access for espionage and data theft