US Sentences 8 in North Korean Laptop-Farm Scheme That Netted More Than $5 Million
Updated
Updated · Financial Times · Jul 20
US Sentences 8 in North Korean Laptop-Farm Scheme That Netted More Than $5 Million
2 articles · Updated · Financial Times · Jul 20
Summary
Eight US-based individuals were sentenced in recent months for running “laptop farms” that let North Korean operatives pose as remote workers inside American companies.
More than 80 stolen US identities were used to land jobs at over 100 companies, generating over $5 million for Pyongyang while giving operatives access to corporate data.
The case highlights a broader rise in “synthetic insider” attacks, with AI deepfakes helping applicants fake faces, voices and locations during hiring for high-risk remote roles.
Verizon said internal actors accounted for 12% of roughly 22,000 incidents in its 2026 analysis, while Fortinet found 62% of insider incidents stemmed from human error or compromised accounts.
Companies are tightening hiring checks, device verification and behavior monitoring, even as cybersecurity experts warn excessive surveillance can create friction, bias and workarounds.
With foreign states recruiting US citizens online, is the next national security threat hiding inside America's remote workforce?
How can companies unmask AI-powered ghost employees who ace interviews, write code, and steal millions before they're ever discovered?
When autonomous AI agents with trusted access cause a data breach, who is legally and financially responsible for the damage?
North Korea’s Remote Work Deception: U.S. Crackdowns Reveal $1 Billion in Sanctions Evasion
Overview
U.S. authorities have recently intensified crackdowns on North Korea’s illicit remote IT worker schemes, leading to the sentencing of key facilitators like Kejia "Tony" Wang and Christina Marie Chapman. These individuals managed sophisticated 'laptop farms' by receiving company laptops at their U.S. addresses, enabling North Korean operatives to access them remotely and pose as legitimate employees. The scheme allowed North Korean IT workers to steal sensitive data, including source code from a California defense contractor, and attempt to infiltrate U.S. government agencies using stolen identities. In response, the U.S. has announced significant rewards for information to disrupt these operations.