FBI Probes North Korean Remote IT Worker Hired by U.S. Agency
The FBI is probing how a North Korean IT worker joined an unnamed U.S. agency, exposing remote hiring gaps and possible risks to federal data and funds.
Summary
The FBI is investigating how a sanctioned North Korean remote IT worker obtained employment at an unnamed U.S. federal agency, a rare confirmed breach of government hiring defenses. Federal News Network first reported the case after a senior FBI official disclosed it at a July 28, 2026 conference in Washington, D.C. The hiring method, affected agency, and any theft of data or funds remain unknown. The FBI declined TechCrunch’s request for comment on August 11.
Thousands of North Korean IT workers are believed to have used fraudulent identities to secure remote jobs at U.S. and European organizations, funnel wages to Kim Jong Un’s regime, steal intellectual property and data, and extort employers after discovery. Federal vetting and security clearances have largely blocked the campaign, although the Justice Department charged a Maryland man in 2024 with helping a North Korean hacker pose as an American contractor for the Federal Aviation Administration. U.S. enforcement actions and sanctions have targeted networks in Pyongyang, Russia and China, plus American facilitators operating laptop fleets that simulate domestic workers. Blockchain forensic firms attribute 76% of cryptocurrency thefts to North Korea, which allegedly netted at least $2 billion in 2025 to support its sanctioned nuclear weapons program despite exclusion from the global financial system.
Positives
- The FBI opened an investigation into the North Korean worker’s employment at an unnamed federal agency.
- Strict federal vetting and security clearance practices have largely kept North Korean operatives out of government agencies.
- Justice Department charges in 2024 targeted a Maryland facilitator who helped a North Korean hacker obtain Federal Aviation Administration contract work.
- U.S. enforcement actions and sanctions have targeted North Korean networks, overseas operations and American laptop fleet facilitators.
Risks & concerns
- A sanctioned North Korean remote IT worker secured employment inside an unnamed U.S. federal agency despite government hiring safeguards.
- The affected agency, hiring method, and possible loss of federal data or funds remain undisclosed.
- Thousands of North Korean IT workers are believed to have infiltrated U.S. and European organizations using fraudulent identities.
- North Korean employment schemes can combine wage diversion, intellectual property theft, data theft and extortion.
- Blockchain forensic firms attributed 76% of cryptocurrency thefts and at least $2 billion in 2025 proceeds to Kim Jong Un’s regime.