U.S. authorities sentenced Oleksandr Didenko, a Ukrainian national, to five years in prison for running a scheme that provided stolen U.S. identities to North Korean IT workers so they could fraudulently obtain remote jobs at U.S. companies. He pleaded guilty in November 2025 to charges including aggravated identity theft and wire fraud conspiracy, and was also ordered to forfeit more than $1.4 million (including seized cash and cryptocurrency). Prosecutors and the FBI described the activity as both a fraud operation and a national security threat, alleging it helped fund the North Korean regime.
Court records say Didenko stole identities and sold “proxy” identities/accounts via UpWorkSell / upworksell.com (seized by the U.S. Justice Department), creating thousands of fraudulent accounts across freelance job platforms and related services. The operation supported North Korean workers in securing roles at 40 U.S. companies and relied on “laptop farms” and other infrastructure to make activity appear U.S.-based; Didenko facilitated at least 871 proxy identities and helped coordinate multiple laptop-farm locations (including in Virginia, Tennessee, and California, with additional locations reported elsewhere). One laptop-farm operator cited in reporting was Christina Marie Chapman in Arizona, who allegedly hosted systems from her home and was separately charged/arrested in connection with the broader scheme.

See the reporting duties and controls this puts on the clock.
14 events from the most recent confirmed update back to the earliest known activity.
On March 20, 2026, the Justice Department announced sentences for three American men who helped North Korean IT operatives obtain remote jobs by supplying identities, hosting laptops, and enabling remote access from their homes. The case highlighted continued U.S. efforts to target domestic facilitators of the broader scheme.
On February 19, 2026, the U.S. Justice Department announced that Oleksandr Didenko was sentenced to five years in prison for facilitating North Korea's remote IT worker scheme. Prosecutors said he managed hundreds of stolen identities, supported laptop farms in multiple U.S. states, and helped North Korean workers obtain jobs at about 40 U.S. companies.
In a related prosecution, Christina Marie Chapman was sentenced to 102 months in prison for operating a laptop farm that supported North Korean IT worker fraud. Her case was repeatedly cited alongside Didenko's as part of the same enforcement campaign.
In December 2025, researchers reported that Famous Chollima/WageMole operators linked to North Korea were using AI tools, stolen identities, and even real LinkedIn accounts of impersonated people to improve fraudulent job applications. The reporting showed the scheme was continuing to evolve despite law-enforcement action.
In November 2025, Didenko pleaded guilty to charges including wire fraud conspiracy and aggravated identity theft in connection with the Upworksell scheme. He also agreed to forfeit more than $1.4 million and pay restitution.
By the end of 2024, Didenko had been extradited from Poland to the United States to face charges related to wire fraud conspiracy and aggravated identity theft. The extradition followed the seizure of his website and his arrest abroad.
Polish authorities arrested Oleksandr Didenko in late 2024 for his role in the identity theft and fraud scheme that enabled North Korean workers to obtain remote jobs at U.S. companies. He was later extradited to the United States.
In May 2024, U.S. authorities seized the Upworksell.com domain and redirected it to FBI-controlled servers. Law enforcement also seized 17 laptops tied to the infrastructure used to make overseas workers appear to be operating from the United States.
In May 2024, the Justice Department unsealed a broader case alleging the DPRK coordinated a large-scale remote IT worker fraud operation using stolen U.S. identities. The case tied the activity to revenue generation for Pyongyang and widespread victimization of U.S. companies.
A related U.S. case targeted Christina Marie Chapman, accused of running a laptop farm from her Arizona home to support North Korean IT workers posing as U.S.-based employees. She was arrested in 2024 as part of the broader enforcement effort.
U.S. authorities and the FBI had publicly warned since at least 2023 that North Korean IT workers were infiltrating U.S. firms using false identities and related deception. Those warnings framed the activity as both financial crime and a national security threat.
Prosecutors said Oleksandr Didenko operated Upworksell.com from 2021, selling or renting stolen or borrowed U.S. identities and related accounts to overseas workers, including North Koreans. The service also supported proxy identities and logistics used to fraudulently obtain U.S. remote jobs.
A later-unsealed DOJ case alleged that from 2020 to 2023, the North Korean government coordinated a large-scale scheme using stolen U.S. identities to place overseas IT workers into remote roles at hundreds of companies. U.S. authorities described it as the largest such scheme they had charged.
According to later DOJ disclosures, three American men helped North Korean IT operatives obtain remote jobs at U.S. companies by supplying U.S. identities, hosting company laptops, and enabling remote access. The activity generated about $1.28 million in salary payments from victim companies between September 2019 and November 2022.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See what this changes for your reporting obligations and which controls it puts on the clock.
11 references tracked. Mallory keeps watching after this page renders.
bsky.app
Open sourcetherecord.media
Open sourcecyberscoop.com
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourcetechcrunch.com
Open sourcetherecord.media
Open sourcecyberscoop.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.