North Korea’s fake-worker scheme reached the US government, and its crypto pipeline just lost $212,700 to a federal judge
A BBC investigation exposes the organized system behind North Korea’s fake IT workers, while fresh cases show how the scheme is evolving into a threat involving stolen identities, AI, cryptocurrency and corporate data.
A US federal judge ordered the forfeiture of roughly $212,700 in USDC and USDT tied to North Korean IT workers on September 3, 2026, the latest confirmation of a global fake-employment scheme that intelligence agencies say has infiltrated hundreds of companies and at least one US federal agency.
It is an organized employment system.
And governments are increasingly warning that the consequences can go far beyond a fraudulent salary.
Behind one “freelancer” may be an entire operation
The BBC said it examined more than 100 pages of internal messenger conversations involving what investigators described as a North Korean cyber unit.
Cybersecurity analysts who reviewed the material identified at least 27 IDs and more than 33 computers.
The alleged structure included different levels of personnel responsible for managing workers, assigning tasks, preparing fake identities and accounts, and carrying out the actual IT work.
That distinction matters.
To an employer, the operation may appear to be a single remote developer applying for a job.
Behind that developer, however, could be people handling identities, accounts, payments, communications and technical infrastructure.
A North Korean defector interviewed by BBC Korea described a similar structure from his experience working overseas, saying teams could live and work together while being monitored.
The BBC reported that some workers operated several computers and identities simultaneously, allowing them to work for multiple companies.
Photo source,Getty Images Photo caption,Kim Hyun-kyu, a North Korean defector who was dispatched to China to work as a North Korean IT worker, said that he lived in a shared house with about 10 colleagues at the time. He stated, “I worked all day long under surveillance with no privacy.”
This makes the scheme much closer to an organized employment-fraud ecosystem than an ordinary case of someone lying on a résumé.
The stolen identity is part of the business model
One of the most striking elements of the BBC investigation is the search for people willing to lend their identities and online accounts.
The targets can be approached through platforms such as Telegram, Discord and other social networks.
The proposition can sound deceptively simple: allow someone to use your identity or employment account and receive a percentage of the income.
But that identity can become the foundation for an entire fraudulent employment operation.
The FBI has previously warned that North Korean IT workers have used stolen identities, pseudonymous email addresses, social-media accounts, payment accounts and job-platform profiles to obtain employment. The agency says thousands of North Korean workers have been deployed internationally as part of the scheme.
The infrastructure can go even further.
According to the FBI, facilitators have helped provide U.S.-based internet connections, receive company laptops, create job-platform accounts, establish financial accounts and even assist with virtual interviews.
In some cases, companies may therefore believe that they are hiring someone located in one country while the actual worker is somewhere else entirely.
A recruitment post for ‘disguised employment partners’ uploaded on Telegram. It promotes that one can easily make money by lending Upwork and LinkedIn accounts.Photo source,BBC/Arvin Supriyadi
That is what makes the operation so difficult to detect.
The fraud is not necessarily happening at the moment the worker begins coding. It can begin much earlier with the construction of a believable identity.
A joint alert issued in July by the United States, South Korea, Britain, Australia, Canada, France, Germany, Italy, Japan, the Netherlands and New Zealand warned that North Korean IT workers are increasingly incorporating AI into their operations.
The governments said AI is being used to help obscure identities and expand the scheme globally.
That means the traditional signs of a suspicious applicant may become less reliable.
A candidate can potentially have polished English, an impressive résumé, convincing written communication and carefully prepared interview responses without necessarily being the person or being in the location that the employer believes.
The BBC also reported that the North Korean workers it examined used ChatGPT for activities ranging from improving English to preparing interview responses and assisting with coding tasks.
The important point is not that AI created the scheme. It didn’t. The scheme existed long before today’s generative AI boom.
AI simply gives an already sophisticated operation another tool for scaling and improving deception.
The real danger begins after the hiring
Calling this a “fake-job scam” can actually underestimate the danger.
The most serious risk may begin after the fraudulent worker has been hired.
Once inside a company, an employee can have access to source code, cloud infrastructure, internal communications, databases, credentials and sensitive corporate information.
The FBI has warned that North Korean IT workers have used legitimate employment access to exfiltrate proprietary information and company data.
In some cases, the agency says workers have copied company code repositories to personal accounts and later attempted to extort companies using stolen information.
There is evidence of an even more direct connection to cryptocurrency.
The FBI currently lists North Korean IT workers accused of obtaining employment under fraudulent identities and allegedly using their access to steal cryptocurrency from two companies. The alleged theft was valued at more than $900,000 at the time.
And this is where the employment scheme intersects directly with the crypto industry.
The salary can become a crypto pipeline
The money generated through these jobs does not necessarily remain in the traditional banking system.
A 2025 U.S. Justice Department civil forfeiture case alleged that North Korean IT workers generated revenue through remote employment, including at blockchain development companies.
According to prosecutors, employers sometimes paid workers in stablecoins such as USDC and USDT, after which the funds were moved through laundering mechanisms. The Justice Department sought to seize more than $7.74 million allegedly laundered on behalf of the North Korean government.
And on September 7, 2026, a U.S. federal judge ordered the forfeiture of cryptocurrency linked to another North Korean IT-worker laundering operation.
According to NK News, the case involved nearly $8 million in virtual assets. Prosecutors said one wallet received approximately 158,123 USDC from at least 10 North Korean IT-worker payment addresses and another 54,574 USDT from at least four addresses.
That development is significant because it shows the employment operation is not merely about circumventing hiring rules.
There is an identifiable financial infrastructure connecting remote employment, cryptocurrency payments and alleged efforts to move proceeds toward North Korea.
Governments now see an insider threat
The international response has consequently changed.
In July, 11 governments issued a joint warning saying North Korean IT workers are obtaining false identities and remotely earning income through employment and contracting platforms.
The governments said the workers pose an insider threat, with activities that can include data exfiltration, cryptocurrency theft and theft of sensitive information. They also warned that the revenue is intended to support North Korean government agencies and, according to the statement, the country’s unlawful nuclear and ballistic-missile programs.
The FBI’s own description is similarly stark: companies may unknowingly hire North Korean workers who generate millions of dollars for Pyongyang while gaining access to corporate systems.
And the threat is no longer confined to ordinary private companies.
In August, the FBI was reported to be investigating how a North Korean remote IT worker obtained employment at a U.S. federal agency.
The case was described as a rare example of the scheme reaching the U.S. government sector.
That raises a much bigger question.
If an operation can penetrate a government hiring process, how many ordinary companies can reliably identify it?
What companies should learn from the scheme
The lesson is not that companies should distrust remote workers.
It is that identity verification cannot end with a résumé and video interview.
The FBI recommends measures including stronger identity verification, monitoring unusual login activity and network connections, restricting unnecessary privileges, monitoring data transfers and investigating unusual remote-access software.
Companies should also pay attention to inconsistencies between a worker’s claimed location and their digital activity.
Multiple logins from different countries, unexplained remote-access tools, unusual account behaviour and attempts to circumvent normal onboarding procedures can all become warning signs.
Most importantly, companies should apply the principle of least privilege.
A newly hired developer does not automatically need access to everything.
The uncomfortable human story
There is another side to the story that can easily disappear beneath the cybersecurity headlines.
The BBC investigation described North Korean IT workers operating under intense surveillance and financial pressure.
One defector interviewed by BBC Korea described long working hours, strict monitoring and financial targets. He said workers could be punished or repatriated if they failed to meet expectations.
That complicates the simplistic image of a sophisticated cybercriminal sitting comfortably behind a laptop.
Some of these workers may themselves be operating inside a coercive system.
The money may ultimately serve the North Korean state, but the people producing that money can also be subject to surveillance, exploitation and punishment.
That does not erase the harm caused to companies and victims.
It does, however, reveal the uncomfortable reality behind the screen: the person committing the deception may simultaneously be a victim of the system ordering them to do it.
The fake employee problem is getting harder to ignore
North Korea’s IT-worker operation has evolved from what might once have looked like a niche employment scam into a broader security problem.
It combines identity theft, employment fraud, social engineering, remote-access infrastructure, cryptocurrency and increasingly sophisticated uses of AI.
The most dangerous part may be the simplicity of the entry point.
There may be no spectacular hack.
No flashing warning.
No mysterious malware.
Sometimes, the initial intrusion is simply a person applying for a job.
And by the time a company realizes that its “employee” is not who it thought they were, that person may already have access to the company’s most valuable systems.
The question businesses should therefore be asking is no longer simply:
“Can this person do the job?”
It is:
“Who is actually doing the job — and what did we give them access to?”
Moses Edozie is a writer and storyteller with a deep interest in cryptocurrency, blockchain innovation, and Web3 culture. Passionate about DeFi, NFTs, and the societal impact of decentralized systems, he creates clear, engaging narratives that connect complex technologies to everyday life.