The State Department issued a global advisory on July 30, warning that North Korean nationals are systematically obtaining remote-work employment under false identities. The scheme funnels wages to Pyongyang’s weapons programs in violation of international sanctions, the department said.
The alert, released by State Department spokesperson Thomas “Tommy” Pigott, urged employers worldwide to implement stronger identity verification and hiring protocols to detect North Korean operatives concealed in their workforces. The scheme targets technology, finance, and defense-adjacent firms, among other sectors.
North Korean IT workers have been documented operating at U.S. technology companies, using stolen or fabricated identities to secure remote positions that pay wages ultimately channeled to the regime’s ballistic missile and nuclear weapons programs, according to the advisory. The normalization of remote work globally has created conditions Pyongyang has aggressively exploited.
The advisory reflects growing intelligence concern about the scale and sophistication of the infiltration operation. North Korean workers often use virtual private networks, fake credentials, and intermediaries in third countries to disguise their true locations and identities, the State Department said.
American companies are prime targets due to their high wage levels and the prevalence of remote work arrangements in the U.S. technology sector. Hiring a North Korean IT worker — even unknowingly — exposes U.S. employers to potential sanctions violations, criminal liability, and national security risks.
The State Department recommended that employers verify identities through video interviews, cross-reference identification documents, monitor for unusual work patterns, and be alert to requests for payment through unconventional channels. The advisory also encouraged companies to report suspected North Korean IT worker activity to federal law enforcement.