1 Oct 2026

North Korea Using Fake IT Workers, Stolen Identities and AI to Target Global Businesses, U.S. and Allies Warn

0

By Tiffany Williams –

blackandredvibrantpodcastyoutubethumbnail_20250508_224112_000038847242454298412031155146395308658650 North Korea Using Fake IT Workers, Stolen Identities and AI to Target Global Businesses, U.S. and Allies Warn

A coalition of governments from North America, Europe, and the Indo-Pacific is warning that North Korea continues to rely on a sophisticated global network of information technology workers using stolen identities, fake documents, third-party proxies, artificial intelligence and other deceptive tactics to infiltrate companies, generate revenue and support the country’s nuclear weapons and ballistic missile programs.

The joint alert was issued by the U.S. Department of State and the Federal Bureau of Investigation alongside government agencies from Japan, the Republic of Korea, Australia, Canada, France, Germany, Italy, the Netherlands, New Zealand and the United Kingdom.

According to the alert, North Korean IT workers obtain false identities and impersonate citizens of other countries to secure remote jobs through online employment, procurement and contracting platforms. Authorities say the workers seek legitimate employment opportunities with the intent of funneling their salaries back to North Korean government agencies.

Officials warned that the threat extends beyond fraudulent employment. The alert states that North Korean IT workers also pose insider threats to businesses and have been linked to data exfiltration, cryptocurrency theft and the theft of sensitive information.

Authorities said the workers are using increasingly sophisticated techniques to conceal their identities, including integrating artificial intelligence into their operations while expanding their activities worldwide.

The governments said they have repeatedly warned the international community and private sector about the threat posed by North Korean IT workers. They pointed to previous joint statements and sanctions monitoring reports issued over the past year documenting North Korea’s cyber operations and sanctions evasion efforts.

The alert also highlights international legal obligations under United Nations Security Council Resolution 2397, stating that U.N. member states must repatriate North Korean nationals earning income within their jurisdictions, subject to limited exceptions. Officials warned that hiring North Korean IT workers or paying them for services could violate the domestic laws of multiple countries, including Japan, the United States and the Republic of Korea, potentially resulting in legal consequences or financial penalties.

Officials further noted that the Financial Action Task Force continues to classify North Korea as a high-risk jurisdiction subject to a call for action. The alert states that North Korea has expanded its access to the international financial system through diversified revenue-generating activities, including IT worker schemes that authorities say help fund weapons of mass destruction programs.

The coalition urged governments, businesses and online employment platforms to strengthen safeguards against fraudulent applicants. Recommended measures include stronger identity verification procedures, stricter reviews of identification documents, in-person interviews when appropriate and systems capable of detecting suspicious account activity.

According to the alert, North Korean IT workers frequently register online accounts using forged identification documents or stolen identities supplied by third-party proxies living in other countries. Authorities also warned that proxies may participate in job interviews or make in-person contact with employers to create a false sense of legitimacy while the actual work is performed by North Korean nationals.

Officials said payment requests can also serve as warning signs. Rather than receiving wages through direct deposit, workers may request payment through money transfer services or cryptocurrency while directing employers to send funds to bank accounts controlled by third parties.

The alert states that many of the workers possess advanced technical skills and actively seek employment involving website development, mobile applications, software engineering and blockchain technologies. While many operate from North Korea, China, Russia, Southeast Asia and Africa, authorities said they frequently conceal their locations by using virtual private networks, remote desktop software and third-party proxies.

Investigators also warned about so-called “laptop farms,” in which facilitators located overseas receive company-issued computers that are then remotely accessed by North Korean workers, masking their true location.

The coalition outlined numerous indicators that could signal fraudulent activity. Those include frequent changes to account information, payment accounts that do not match account holder identities, multiple accounts created with the same identification documents, suspicious IP address activity, unusually long login sessions, abnormally high work activity, self-generated positive reviews and identification documents that appear to have been digitally altered.

Officials also advised employers to watch for applicant profiles containing unnatural language or translation errors, discrepancies during video interviews, refusals to participate in video meetings, offers to work well below prevailing market rates, signs that multiple individuals are operating the same account and requests for payment in cryptocurrency.

The governments said they encourage countries, private companies and online service providers to deepen their understanding of North Korea’s IT worker schemes and strengthen measures designed to detect and prevent these increasingly sophisticated operations.

Leave a Reply

Discover more from NewsTalk New England

Subscribe now to keep reading and get access to the full archive.

Continue reading