Blogs

FBI: North Korean IT worker scheme involves source code theft, extortion

Cybersecurity illustration related to North Korean remote IT worker threats

Summary: The FBI warned U.S. organizations that fraudulent North Korean IT workers are stealing source code and other sensitive data, then using the material to support extortion attempts after their employment ends.

The threat behind a legitimate login

These operators seek remote technology jobs using false or stolen identities. Once hired, they can receive company credentials, managed devices and routine access to development environments. The FBI said some workers have exfiltrated proprietary information, including source code, and retained credentials or browser session cookies for later access.

Extortion after termination

In some cases, the worker threatened to release the stolen information unless the former employer paid. This means offboarding must address more than the user account: organizations should also revoke active sessions, rotate exposed secrets and review recent downloads, repository activity and remote connections.

Recommended defenses

  • Validate remote applicants through live interviews and independent identity checks.
  • Restrict repository and cloud access to the minimum required for each role.
  • Use managed endpoints and block unapproved remote-access applications.
  • Monitor unusual bulk downloads, access from unexpected regions and session reuse from unmanaged devices.
  • Preserve evidence and report suspected activity to the appropriate law-enforcement channel.

The FBI advisory provides additional indicators and defensive guidance for companies that hire remote IT workers.


Original sources: FBI Internet Crime Complaint Center — North Korean IT worker data-extortion advisory; SC Media — FBI: North Korean IT worker scheme involves source code theft, extortion

Independently summarized and reviewed by CNB Telecom. Last reviewed: September 4, 2026.

Leave a Reply

Your email address will not be published. Required fields are marked *