FBI, State Department, and 10 Nations Warn About North Koreans Posing as IT Workers

Authorities across 11 countries have warned employers to watch for fake applicants after North Korean IT workers used deception to secure remote jobs and access corporate networks.
Published: 8/5/2026, 3:46:56 AM EDT
FBI, State Department, and 10 Nations Warn About North Koreans Posing as IT Workers
People stand before computer screens in a lobby of the Grand People's Study House in Pyongyang, North Korea on April 18, 2019. (Ed Jones/AFP via Getty Images)
The FBI, U.S. Department of State, and government agencies across 10 other nations are warning companies that North Koreans are using false identities to land remote technology jobs and generate money for Pyongyang’s nuclear weapons and ballistic missile programs.

“North Korean IT workers impersonate nationals of other countries to obtain work and income through online platforms operated by private companies for employment, procurement, and contracting of services,” according to the 11-nation joint alert.

The warning came from government agencies in the United States, Japan, South Korea, Australia, Canada, France, Germany, Italy, the Netherlands, New Zealand, and the United Kingdom. The alert was issued in the United States by the FBI and the State Department.

According to the alert, North Korean workers are employing increasingly sophisticated techniques to disguise their identities and locations. The methods include the use of artificial intelligence (AI), forged identification, stand-ins for interviews, and computers located in the United States. Once hired, they gain access to sensitive company systems and engage in data or cryptocurrency theft.

In some cases, another person may create the applicant’s account, appear for a video interview, or even meet an employer in person. The North Korean worker then performs the job remotely under that false identity.

“While many North Korean IT workers reside in North Korea, China, and Russia, as well as Southeast Asian and African countries, they may conceal the fact that they are working from abroad using third-party proxies, VPNs, remote desktop software, and similar tools,” states the alert.

In the United States, one method involves “laptop farms.” These locations receive company-issued laptops, and North Korean IT workers then access them remotely to hide their true location.

The alert says many of the job seekers have strong technical skills and are willing to work for less pay than at market rates. Meanwhile, what looks like one worker is actually a whole team sharing a single account.

Red flags that hiring companies should watch out for include: job applicants who avoid video calls, IDs that don’t match the person on screen, fake-looking video, changes in account details, mismatched payment names, or requests to pay with cryptocurrency or someone else’s bank account.

Governments urged employers and job sites to check identities closely and watch for suspicious accounts. They warned that hiring or paying North Korean workers is illegal in the United States as well as in other countries, and carries civil penalties or criminal prosecutions.
A North Korean foreign ministry spokesperson told KCNA, a North Korean state media outlet, that Pyongyang would not tolerate what it called politically motivated attempts to use cyber issues as a means of pressure on other countries. The spokesperson accused Washington of militarizing cyberspace through cyber warfare capabilities and joint cyber exercises with allies.

Separately, a North Korean military commentator, writing in KCNA on Tuesday, accused the United States, South Korea, and Japan of using the U.S.-led RIMPAC naval exercise as practice for aggression. The commentator said their closer military ties were fueling a new security crisis in the Asia-Pacific region.

The U.S.-hosted exercise brought together 30 nations and more than 30,000 personnel for five weeks of maritime training around Hawaii, according to the Navy.
Reuters contributed to this report.