Blog
North Korean Fake IT Workers More Aggressively Extorting Enterprises
Summary: U.S. authorities and incident responders warned that fraudulent North Korean remote IT workers have increasingly shifted from wage theft and sanctions evasion to stealing sensitive data and extorting their employers.
How the scheme works
Operators apply for legitimate remote technology roles using fabricated or stolen identities. Once hired, they may use U.S.-based facilitators, company laptops and remote-access tools to make their location appear credible. Because the initial access is granted through normal onboarding, the activity can bypass controls designed mainly for external attackers.
The escalation to extortion
The FBI said some workers have copied proprietary data and source code to personal or attacker-controlled systems. After discovery or termination, they may threaten to publish the stolen material unless the employer makes a payment. Investigators have also observed attempts to retain access through credentials, browser session cookies and remote connections.
Why it matters
The risk combines insider access, identity fraud, intellectual-property theft and potential sanctions exposure. Organizations hiring globally should treat identity assurance and continuous access review as security controls rather than one-time human-resources checks.
Practical takeaway
- Perform live identity verification and independently validate employment and education records.
- Block unapproved remote-control software and investigate inconsistent geolocation or working patterns.
- Use least privilege, managed devices and short-lived sessions for sensitive repositories.
- Revoke credentials, tokens and active sessions immediately when employment ends.
Original sources: SecurityWeek — North Korean Fake IT Workers More Aggressively Extorting Enterprises; FBI Internet Crime Complaint Center — January 2025 public service announcement
Independently summarized and reviewed by CNB Telecom. Last reviewed: September 4, 2026.