The DPRK IT worker scheme is a North Korean state program that places trained software developers into remote jobs at Western companies using stolen or fabricated identities.
Salaries are funneled back to the regime which the UN says finances up to 40% of its weapons programs through cyber operations while the workers themselves gain insider access that has escalated into data theft, supply-chain compromise, and extortion. The FBI, U.S. Treasury, and State Department have issued joint advisories on the scheme since May 2022.
That's the definition. Here's what it looks like from the inside.
The company that hired a North Korean spy
In July 2024, a security company did something companies almost never do: it publicly admitted to hiring a North Korean spy.
KnowBe4 a firm whose entire business is training employees to spot deception had run a textbook hiring process for a remote principal software engineer. The candidate's resume checked out. His background check came back clean. He appeared, live and personable, in four separate video interviews, and his face matched the photo on file. Then the company shipped him a laptop, and twenty-five minutes after it came online, it started loading malware.
The "engineer" was a North Korean IT worker operating through a stolen American identity. The profile photo was a stock image blended with his real face by AI. The laptop's delivery address was not a home but a way station one node in a network of American "laptop farms" that make operatives on the other side of the world appear to be logging in from Dallas or Denver. Everything about the hire had been manufactured, and every standard control had approved it.
What makes this story important is not that it's shocking. It's that it isn't rare.
What is the DPRK IT worker scheme and how does it work?
The Democratic People's Republic of Korea runs what may be the strangest revenue program in the history of sanctions evasion: it trains software developers, manufactures Western identities for them, and dispatches them to get hired. Legitimately hired, with offer letters and onboarding calls and 401(k) enrollment forms at companies across the United States and Europe.
Their salaries flow back to the regime. The FBI, the U.S. Treasury, and the State Department have been issuing joint advisories about the scheme since May 2022; the Justice Department has been indicting its participants ever since.
The workers operate in coordinated teams, typically based in China, Russia, or Southeast Asia, each cell carrying revenue quotas set by the state. A single worker often holds several remote jobs simultaneously, and the personas are shared: the person who aces your interview may not be the person who shows up to your standups, and the profile you shortlisted may be a costume worn by whoever on the team is available. Increasingly, the costume is machine-made AI-polished resumes, AI-generated profile photos, real-time answer-feeding during interviews, and, at the frontier, live deepfake face-swaps on video calls.
The scheme scaled for a simple reason: in 2020, the world decided that meeting your employees in person was optional. Before the pandemic, DPRK IT workers mostly hustled on freelance platforms under fake names. After it, a well-built persona could hold a salaried senior engineering position at a Fortune 500 company without anyone ever sharing a room with it.
We can not say that remote work created the fraud but it removed the last control that contained it.

In recent years, two developments transformed this scheme from a medium-size operation into an industrial one expanding both its scale and its sophistication.
The first is artificial intelligence, which multiplied the bandwidth of every individual operative. What once required a team member's time and imperfect English now runs through end-to-end AI pipelines: generating tailored resumes and cover letters by the hundreds, managing inboxes and recruiter conversations across dozens of parallel personas, translating in real time, polishing profile photos or swapping faces live on video calls, and even carrying much of the technical workload once a job is landed. One worker can now sustain a volume of applications, interviews, and concurrent employment that would have required an entire cell a few years ago.
The second development is human rather than technological: the growth of a Western facilitator layer. Recruited online and paid a cut, ordinary residents of the target countries supply what no algorithm can a real local address to receive corporate laptops, a domestic IP for the "laptop farms" that make foreign operatives appear stateside, a face for notarized ID checks, and bank accounts through which salaries can flow without alarm. Together, the two changes solved the scheme's historical bottlenecks in one stroke: AI removed the ceiling on how many personas a worker can operate, and facilitators removed the last physical evidence that the persona isn't real.
How much money does North Korea make from hacking and fake IT workers?
North Korea's cyber operations are unusual among state programs in that we can partially count them. Cryptocurrency theft happens on public ledgers, and blockchain analytics firms Chainalysis, Elliptic, TRM Labs independently track it. Their estimates converge on roughly $3 billion stolen by DPRK-linked groups between 2017 and 2023, in yearly waves that crest whenever a mega-heist lands: about $1.7 billion in 2022, the year of the Axie Infinity/Ronin hack. But in 2025 they struck a new record, anchored by the $1.5 billion Bybit theft, the largest cryptocurrency heist ever recorded, attributed by the FBI to the Lazarus Group.

The fake-employment scheme is smaller but steadier: U.S. government estimates and Justice Department filings put it at several hundred million dollars per year. And the two lines of business feed the same ledger. The UN Panel of Experts, before Russia vetoed its mandate in 2024, reported that cyber operations supplied roughly half of North Korea's foreign currency earnings and funded about 40% percent of its weapons-of-mass-destruction programs. The White House's then-deputy national security advisor for cyber, Anne Neuberger, put the missile-program share at about half.

All of these figures deserve their asterisks; they are estimates built on estimates, describing a country that publishes no verifiable numbers and whose entire GDP is itself a guess (the Bank of Korea puts it somewhere between $23 and $30 billion). But even at the cautious end, the arithmetic is startling: in peak years, cyber theft alone equals several percent of North Korea's entire economy. No other state on earth depends on hacking and employment fraud the way this one does. That dependence is why the scheme keeps evolving, and why it will not stop on its own.
Why web3 and blockchain companies are the primary target
For the Web3 industry the picture looks even worse. At any given time, an estimated 15,000 identities are under DPRK management, and they are not distributed evenly across the job market: security researchers at the Security Alliance estimate that 3–5% of all Web3 developers are, in fact, North Korean operatives, and that as many as one in three job applications for blockchain engineer roles originates from DPRK-managed personas.
Read those numbers together and the implication for hiring teams is stark: a crypto company posting a remote blockchain engineering role should assume, before the first resume is opened, that a meaningful share of its pipeline is adversarial. The targeting logic is sound from Pyongyang's perspective: the roles are highly paid, remote-native, staffed through fast and informal hiring processes, and sit closest to the assets the regime ultimately wants: treasury keys, smart contract privileges, and the infrastructure of protocols holding user funds. For a blockchain engineer opening, screening is therefore not an edge-case precaution but a base-rate necessity; when a third of the queue may be fraudulent, verification stops being paranoia and becomes arithmetic.

What are laptop farms?
The scheme's most counterintuitive feature is how much of it is physically located inside the United States.
A remote worker who claims to live in Texas has a problem: his laptop needs to connect from Texas. The regime's solution is the laptop farm an ordinary American home where a paid facilitator receives corporate laptops by the dozen, connects them to remote-access software, and keeps them humming so that workers in Shenyang or Vladivostok appear, to any IT department checking IP addresses, to be exactly where they said they were.
The court records read like absurdist fiction. Christina Chapman, an Arizona woman recruited online, ran a farm that serviced North Korean workers embedded in more than three hundred U.S. companies laundering over $17 million before her arrest; she was sentenced in 2025 to more than eight years in prison. A December 2024 indictment of fourteen DPRK nationals detailed state-run front companies in China and Russia that banked $88 million over six years, with workers who escalated to extortion, stealing source code on the way out and ransoming it back to their ex-employers. In June 2025, the Justice Department conducted a coordinated sweep across sixteen states: 29 suspected laptop farms searched and more than 200 computers seized. There was even a marketplace layer managed by Oleksandr Didenko, an Ukrainian operator whose "UpWorkSell" service sold ready-made freelancer accounts with verified U.S. identities to North Korean buyers, the way one might sell aged social media accounts.
Each prosecution documents the same architecture: foreign workers, American infrastructure, stolen or purchased identities, and an employer, hundreds of employers, who never suspected a thing.
Why HR is the control point?
The risk cannot be reduced to simply paying a salary to a DPRK agent, or even to being hacked. Those are only the opening scenes. The documented cases show that the damage compounds along several independent fronts at once.
There is the extortion pattern: workers who are caught or fired have increasingly turned out to have been exfiltrating source code and customer data from day one, returning weeks later with ransom demands, the 2024 indictment of fourteen DPRK nationals describes exactly this escalation from wage-earning to blackmail.
There is the supply-chain dimension: a fake developer with commit access doesn't just endanger your systems but everyone downstream who depends on your software. The Bybit hack was executed not through Bybit itself but through a compromise touching Safe{Wallet}'s infrastructure.
There is the legal exposure: paying a sanctioned entity's operative is a sanctions violation regardless of intent, which means the same incident can trigger OFAC scrutiny, frozen or seized assets, de-banking by financial institutions wary of secondary exposure, and criminal investigations into the organization itself.
And running underneath all of it is the reputational cost, explaining to customers, partners, and regulators that a hostile state's employee sat inside your systems for months.

In other words, one bad hire is not one risk; it is a bundle of them, and most of the bundle detonates after the person is already gone.
If companies file this threat under cybersecurity scope, it means their defenses activate only after the hire: network monitoring, device telemetry, anomaly detection. Those controls matter, they are what saved many companies already, but they engage at the most expensive possible moment, when the operative is already on payroll (itself a potential sanctions violation) and already inside the systems.
Every earlier signal lives in the hiring pipeline, and the hiring pipeline belongs to HR.
An unusual conclusion
There is a version of this story that ends with better software: deepfake detectors, identity-verification vendors, AI screening the AI. Some of that will help. But the scheme's actual innovation was never technical. It was the recognition that the modern hiring process: remote, fast, polite, and allergic to friction, had become an attack surface, and that nobody was defending it because nobody thought of it as one.
The defense, correspondingly, may not be a product this time. It might just be a recruiter who spends three extra minutes per candidate, an interviewer comfortable going off-script, a shipping policy with no exceptions, and an escalation path that treats a strange application the way a SOC treats a strange login.
Figures cited are estimates drawn from public sources like Chainalysis, Elliptic, and TRM Labs crypto-crime research; UN Panel of Experts reports (2019–2024); FBI–Treasury–State joint advisories (2022– ); U.S. Department of Justice indictments and press releases (2024–2025); the KnowBe4 public disclosure (July 2024); the Security Alliance (SEAL) DPRK IT Workers framework; and Bank of Korea GDP estimates. They are revised as new incidents are attributed and prosecutions unseal; verify against current releases before republication.