The FBI is investigating how a North Korean national using a fraudulent identity was hired as a remote IT worker for an unnamed U.S. federal agency, marking a notable expansion of a scheme that has more commonly targeted private companies. Authorities say these operations use fake personas to secure remote jobs, generate revenue for Pyongyang, and in some cases steal data, intellectual property, or extort employers; it remains unclear which agency was affected in this case or whether any government data or funds were compromised.
The case follows earlier U.S. enforcement against facilitators who helped North Korean operatives penetrate American organizations, including a Justice Department prosecution of a Maryland man tied to a contractor role supporting the Federal Aviation Administration. Security researchers and industry reporting say the broader pattern increasingly exploits hiring, contractor onboarding, delegated access, and supplier trust relationships rather than relying solely on phishing or malware, exposing gaps across HR, procurement, identity and access management, finance, asset management, and security teams.

See the actors and campaigns active against you right now.
6 events from the most recent confirmed update back to the earliest known activity.
On July 31, U.S. agencies and more than a dozen foreign partner agencies issued a global alert warning that North Korean remote IT workers pose risks to private companies, governments, and individual citizens. The alert expanded official warning of the scheme beyond the previously disclosed federal-agency investigation.
At a conference in Washington, D.C. on July 28, a senior FBI official said the FBI is investigating how a North Korean national was hired by an unnamed U.S. federal government agency. The affected agency was not publicly identified, and it remained unclear whether any data or funds were stolen.
In June 2025, Nisos said a suspected North Korean operative applied for a remote AI architect role using a stolen identity, prompting an investigation. Nisos reported finding signs of AI-assisted interview responses and traced the operation to a U.S.-based laptop farm using PiKVM devices and a Tailscale mesh VPN to support multiple fraudulent worker personas.
In March 2025, Nisos reported a likely North Korean-affiliated IT worker network that used GitHub personas posing as Vietnamese, Japanese, and Singaporean nationals to seek remote engineering and blockchain developer jobs in Japan and the United States. Nisos said two personas appeared to have obtained employment at companies with fewer than 50 employees and assessed the scheme was intended to generate revenue for Pyongyang.
Between late 2024 and early 2025, a PurpleDelta cluster linked to North Korean IT-worker activity applied to jobs at more than 1,100 companies using at least 22 fabricated personas and was assessed as highly likely to have gained employment at at least ten organizations. Recorded Future said the operators, likely based in China, used AI-generated profile photos, custom ChatGPT assistants, illicit identity documents, and facilitators handling company-issued hardware.
In 2024, the U.S. Justice Department charged a Maryland man who helped a North Korean operative pose as an American to obtain remote employment. The operative secured a contractor role tied to the Federal Aviation Administration.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
10 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcesecuritymagazine.com
Open sourcebsky.app
Open sourcetechcrunch.com
Open sourcefederalnewsnetwork.com
Open sourceinfosecurity-magazine.com
Open sourcejustice.gov
Open sourcenisos.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.