The Invisible, Illicit Workforce: How North Korea Uses Remote IT Workers to Evade Sanctions
For years, sanctions against long-time international opponents of the U.S.; a group including Iran, Russia, and North Korea, amongst others have focused heavily on restricting weapons development and illicit trade, while targeting the very financial networks which continue to provide a lifeline to these countries in wake of these stringent penalties. With respect to North Korea in particular, to counter these widenings sanctions, the country has developed new sanctions-evasion strategies outside of the traditional use of smuggling routes and hidden bank accounts to allow their criminal economy to continue growing unabated. This strategy has seen the growing use of sophisticated information technology (IT) workers deployed within and outside of North Korea to obtain false identities and remotely earn income to fund North Korea’s unlawful nuclear weapons and ballistic missile programs.1
In July 2026, the United States, Japan, the Republic of Korea, and several other countries across the globe issued a renewed, joint warning to governments, businesses, technology companies, and financial institutions about North Korean IT workers who conceal their identities and locations to obtain employment with foreign companies across a number of sectors. These IT professionals are reportedly hand-picked by members of the North Korean government to infiltrate legitimate companies around the world, with their work-specific duties allowing them to generate significant revenue for the North Korean regime while exploiting the global remote-work economy to bypass international sanctions. Furthermore, their operations within these respective spaces have also allowed them to gain access to the critical infrastructure of top firms across the globe, facilitating cyber theft and hacking ploys that are also significant fundraisers for the embattled country. This threat represents a growing intersection between cybercrime, financial fraud, and traditional white-collar crime with analysts estimating these tactics could soon spread to other heavily sanctioned countries, creating new national security risks for America and its international counterparts.
According to analysis of these developments run by the U.S. government, highly skilled North Korean software developers, programmers, and technology specialists often apply for remote positions in high-demand fields using stolen identities, fabricated résumés, false employment histories, and third-party intermediaries to appear legitimate. To an employer, the applicant may appear to be a highly qualified developer living in the United States, Europe, or another allied country. In reality however, the potential worker may be operating from North Korea or another restricted jurisdiction while sending earnings back to entities connected to the regime. By fabricating their identities, these operatives are able to bypass the fundamental aspects of client onboarding checks and Know Your Employee (KYE) screens for verification of their identity, while also failing to be detected during sanctions and PEP database screenings or while assessing their potential criminal history.
The primary difference between these operations and traditional cybercrime is that the IT workers involved in these activities actually perform legitimate technical tasks and provide real services for the businesses that employ them. However, these operations do frequently involve multiple layers of traditional financial crime. Identity theft itself, one of the more traditional financial crime methods that still remains prevalent today, is at the core of these ploys. In using faux records, fraudulent applications and false statements ultimately deceive companies into hiring individuals they would otherwise be prohibited from employing; effectively making these companies complicit in their own right. Payroll payments to hired individuals may then be routed through intermediaries, shell companies, or overseas accounts to disguise their ultimate destination, all while avoiding detection from authorities monitoring illicit financial activity of this nature. Additional offenses discovered within these operations have also included wire fraud through false employment representation, money laundering to conceal financial transfers, sanctions violations involving prohibited North Korean entities, export-control violations involving access to sensitive technology, and the ultimate theft of intellectual property or corporate data. Further, investigators have also identified tactics including AI-enhanced online profiles, fabricated professional histories, fake references, and “laptop farms”; locations where company-issued computers remain physically inside the United States while overseas workers remotely access them. The latter allows companies to see what appears to be a domestic employee accessing their systems, while the actual worker may be thousands of miles away, creating a false sense of legitimacy used to exploit oblivious entities. As a result, many companies unknowingly become targets because these schemes are designed to blend into normal business operations. The U.S. State Department has also found that in addition to obtaining IT-related work, North Korean IT workers may obtain foreign currency by engaging in fraudulent foreign exchange trading using automated trading systems that they themselves developed.1
As these financial crime patterns continue to emerge and their sophistication level grows, U.S. authorities have increasingly targeted these networks, prosecuting individuals located within the United States who have been involved in facilitating North Korean remote-worker schemes, with several of these apprehended individuals providing infrastructure, financial services, and access to company equipment. However, these prosecutions have seemingly done little thus far to deter additional activity in this regard from spawning across Europe and other parts of the developed world. Through their enforcement efforts however, the State Department has also identified specific characteristics for companies operating in online platforms to look out for that may apply to a job applicant of this variety. These developments have also created new expectations for human resources departments, technology teams, finance departments, and legal compliance officers in the modern age to better prevent exposure to these crimes. As a result, financial institutions and technology companies are increasingly expected to strengthen their identity verification procedures, complete adequate employee location verification, monitor remote systems access, complete thorough background screening protocols, and maintain appropriate payment and payroll controls to avoid falling victim to these operations.
All told, North Korea’s new remote-worker strategy represents a broader evolution in global financial crime. Modern sanctions evasion increasingly relies on digital infrastructure rather than physical smuggling networks, with the same technologies that enable global commerce also being exploited by criminal organizations and sanctioned governments at exponential rates. The lesson to be taken by American businesses from these developments is clear: a sanctions violation may not begin with an illegal transaction, instead, it may begin with nothing more than a fraudulent résumé.
Citations
1. U.S. Department of State. Alert to Countries, Companies, and Other Entities Regarding North Korean IT Workers. Office of the Spokesperson. 31 July 2026.
