Overview
- The FBI disclosed on July 28 that it identified a North Korean remote IT staffer working for an unnamed U.S. federal agency and is actively investigating how the hire occurred.
- Officials have not revealed which agency was affected or whether any sensitive data or funds were accessed or stolen, leaving the scope of the breach unclear.
- The FBI and U.S. State Department issued a joint global alert on July 31 that urges stronger identity verification and stricter screening for remote IT roles.
- Investigators say North Korea uses forged identity documents, AI-generated credentials and deepfake video, plus U.S.-based facilitators and laptop farms, to pass hiring checks and appear to work from abroad.
- U.N. and security firms estimate these schemes generate hundreds of millions of dollars a year for Pyongyang, and prosecutors continue to build cases against domestic enablers as international partners step up coordination.