The United States and a coalition of allied nations have issued a global warning to businesses about a network of IT workers operating under false identities to funnel money into North Korea’s nuclear and ballistic missile programs.
The joint advisory was signed by Japan, South Korea, the United Kingdom, France, Germany and Canada, among others. It says North Korea has refined its methods for evading international sanctions, turning the global remote-work market into a revenue stream for the regime.
The warning states that hiring these workers, even unknowingly, could expose companies to serious criminal liability, financial penalties and lasting reputational damage as inadvertent funders of terrorism. The advisory consolidates agreements reached during 2025 by the Multilateral Monitoring Team.
Scale and finances
Intelligence assessments cited in the advisory estimate that this network of programmers generates roughly 800 million dollars per year for Pyongyang. The regime is said to confiscate up to 90 percent of the salaries these workers earn from foreign employers.
The advisory notes that the scheme violates United Nations Security Council Resolution 2397, which requires the immediate repatriation of North Koreans earning income abroad. North Korea also remains at the top of the Financial Action Task Force’s risk list for money laundering.
Recent actions by the US Treasury uncovered clandestine operations in Laos, where front companies controlled by an entity called Department 53, described as an arms-related arm of the Ministry of Defense, were found to be coordinating groups of coders.
Methods used
The advisory says most of these workers are based not in North Korea but in China, Russia, Southeast Asia and Africa. They target job openings in web design, blockchain, mobile applications and corporate software.
To pass hiring checks, they use stolen identities and artificial intelligence tools to manipulate interviews. They also use virtual private networks and so-called laptop farms, in which accomplices in Western countries host corporate devices and allow the infiltrators to connect remotely while appearing to be located in Europe or North America.
Payments are typically demanded through alternative gateways or cryptocurrency to obscure financial trails. Generative AI tools are also used to clone voices and pass automated screening tests.
Security risks beyond funding
Intelligence services warn that beyond indirectly financing weapons programs, these individuals pose a direct cybersecurity threat. Once inside a company with legitimate credentials, they are positioned to steal intellectual property, exfiltrate confidential data or carry out large cryptocurrency thefts.
The international alliance is calling on employment platforms to tighten access controls, including biometric verification, mandatory in-person interviews and advanced tools capable of detecting inconsistent geolocations or unusual network behavior.
