← Back to blog
20 July 2026·4 min read·By Daniel McClure

How North Korea turned remote IT jobs into a $500 million operation

North Korea runs a documented, ongoing fraud operation that places IT workers in remote roles under false identities, and U.S. prosecutors have already tied it to more than 300 companies.

A laptop arrives by mail at a house in the suburbs. Nobody who lives there is going to use it for work. Someone signs for the package, and later plugs the laptop in alongside a small device that lets it be operated from anywhere in the world. In exchange for a modest monthly fee and keeping the machine online, that person's only job is to not ask questions. Thousands of miles away, the person actually doing the work logs into that laptop every morning, joins company standups under an assumed name, and collects a paycheck that eventually makes its way back to North Korea.

This is not a hypothetical dreamed up to sell security software. It is a fraud operation that U.S. prosecutors have been documenting for years, and it has scaled well past the point where any single company can assume it is someone else's problem.

Remote IT roles are a natural target for this kind of operation. They are among the most commonly filled remote positions at any given company, they pay well relative to other remote work, and the entire hiring pipeline built around them, resume, technical screen, video call, was never designed around anyone meeting in person. That is exactly the kind of pipeline this scheme is built to exploit.

The scale is larger than most hiring teams assume

Estimates place the number of North Korean IT workers operating this way at more than 100,000, working across roughly 40 countries under false identities. Collectively, the scheme is believed to generate approximately $500 million a year for the regime, some of which has been tied to funding for weapons programs. A single team of operatives can bring in up to $3 million a year; an individual working alone can earn around $300,000, most of which flows back to the state rather than the worker.

The methods have kept pace with the tools available to remote workers generally. Operatives use deepfake video during interviews to mask their real appearance, obfuscate their actual location, and submit references and work portfolios that are fabricated or generated with AI. None of this requires unusual sophistication anymore. It requires the same software that is freely available to anyone hiring or job hunting today.

The Department of Justice has tied coordinated versions of this scheme to more than 300 U.S. companies. That number alone should recalibrate how seriously hiring teams treat basic identity verification, particularly for remote roles where a video call and a set of documents are often the only checkpoints a candidate ever passes through.

The people renting out their identity are being prosecuted too

In May 2026, the DOJ announced that two U.S. nationals had been sentenced to 18 months in prison for their role in hosting company laptops at their homes, the laptop farm arrangement described above. Their job was never to write code. It was to make a remote worker on the other side of the world look, on paper, like an employee sitting in a normal American residence, on a normal American network, with a normal American IP address.

That is the detail worth sitting with. The infrastructure supporting this scheme is not exotic. It runs through unremarkable homes, ordinary shipping addresses, and people willing to take a few hundred dollars a month to babysit a laptop. It works because most of the hiring process it exploits, resume, interview, reference check, was built for a world where showing up on a video call and sounding competent was a reasonable proxy for being who you said you were.

What actually helps

None of this argues for treating every remote candidate as a suspect. Most people applying for remote IT roles are exactly who they say they are, and paranoia has its own hiring cost. But there is a short list of patterns that recur across the cases prosecutors have made public, and they are worth having on hand:

  • Reluctance to turn on video, or video quality that stays suspiciously poor throughout an entire interview process
  • Requests to ship company equipment to an address that doesn't match the candidate's stated location, or repeated changes to that shipping address
  • Payment details, banking information, or identity documents that shift after the offer stage
  • References who are vague about specific projects or dates, or who are difficult to reach through any channel other than the one the candidate provided
  • A portfolio or GitHub history that looks complete but can't be traced back to a verifiable, independent account

Individually, any one of these has an innocent explanation. Together, they are the pattern that keeps showing up in the cases that eventually became prosecutions. The fix isn't more suspicion. It's verification that happens at the source, identity documents checked against issuing authorities, employment history confirmed with the companies that issued it, rather than taken on faith because someone sounded right on a call.