FBI investigates North Korean IT worker who infiltrated US federal agency
The FBI is investigating a North Korean remote IT worker who successfully infiltrated an unnamed US federal agency as a contractor using fraudulent credentials. FBI Deputy Assistant Director Todd Hemmen revealed the breach, which highlights critical vetting gaps in government support roles. The incident is part of a broader campaign generating $250 million to $600 million annually for North Korea's weapons program through sophisticated remote work fraud and laptop farms.
North Korean federal contractor infiltration
▪The FBI declined to comment on which federal agency was affected by the North Korean IT worker or whether any sensitive data or funds were stolen.
▪FBI Deputy Assistant Director Todd Hemmen disclosed the active investigation into the North Korean worker during a panel discussion at a conference on July 28, 2026.
▪The FBI is investigating a North Korean remote IT worker who obtained contract work supporting an unnamed US federal government agency.
Remote IT worker fraud
▪North Korean IT workers have been observed using network access to steal sensitive data, proprietary technology, and credentials to facilitate further cyberattacks.
▪North Korean remote IT workers rely on US-based proxy networks and laptop farms to make it appear as though they are logging in from American soil.
▪North Korean IT workers use artificial intelligence, deepfakes, and stolen identities to bypass background checks and secure remote employment.
Government contractor vetting gaps
▪A white paper by the Intelligence and National Security Alliance recommended establishing a joint working group under the Defense Counterintelligence and Security Agency to set new standards against synthetic identity threats.
▪Security experts state that support and IT contract roles in the public sector often bypass the rigorous vetting and security clearance processes required for direct federal employees.
North Korean sanctions evasion
▪United Nations estimates indicate that North Korea's remote IT worker schemes generate between $250 million and $600 million annually to fund the regime's weapons programs.
▪North Korea relies heavily on cryptocurrency thefts to evade global sanctions, with blockchain forensic firms reporting the regime was responsible for 76% of all crypto hack value in 2026.
US enforcement actions
▪A Maryland man was previously sentenced to 15 months in prison for helping a North Korean national obtain remote software development contracts with the Federal Aviation Administration and other agencies.
▪In 2026, eight individuals were sentenced for facilitating North Korean remote IT operations, including US nationals who operated laptop farms.
Global security alert
▪The FBI, the US State Department, and over a dozen foreign partner agencies issued a joint global security alert on July 31, 2026, warning of North Korean remote IT worker risks.
▪The July 31, 2026 global alert urged employers to implement enhanced identity verification protocols and more rigorous screening measures for remote IT roles.
Story comments
Loading comments…