VMTech
Discuss a project

FBI probes North Korean remote worker at a US federal agency

FBI probes North Korean remote worker at a US federal agency

The FBI is investigating how a North Korean national was hired to work for an unnamed US federal government agency, a senior FBI official said at a conference in Washington, DC, on July 28. Federal News Network first reported the disclosure. The agency involved has not been identified, and it is not known whether data or funds were stolen.

The case is notable because it is a rare confirmed instance of a sanctioned North Korean gaining employment at a government agency. The route through which the worker was hired remains unclear. Federal hiring vetting and security-clearance practices have generally limited this type of infiltration, although the record shows that such controls are not infallible.

A remote-employment fraud model

North Korea has run coordinated, long-term campaigns to obtain remote IT roles at private companies and multinationals using fraudulent identities. Thousands of North Korean IT workers are believed to have secured jobs with US and European organizations in recent years by exploiting weaknesses in hiring processes.

The model is designed to generate wages that are routed back to the regime. It can also expose employers to intellectual-property theft and other data loss, followed by extortion when the workers are discovered. The reported federal-agency case places that established risk model in a setting where access controls and personnel screening are expected to be more stringent.

Facilitators and enforcement actions

US authorities have repeatedly warned employers about networks that support these schemes from North Korea, as well as from Russia and China. American facilitators can operate fleets of laptops that make remote workers appear to be located in the United States, complicating checks based solely on a worker’s apparent endpoint or time zone.

In 2024, the Justice Department charged a Maryland man accused of helping a North Korean hacker pose as an American to obtain a remote contractor role at the Federal Aviation Administration. That case illustrates how an intermediary and a false domestic identity can be used to reach government-related work.

Why continuous verification matters

The FBI did not respond to a request for comment, and the available account does not establish the hiring mechanism or the impact of the current incident. Still, the investigation reinforces that remote hiring is not a one-time administrative task when access to systems, data or payments is involved.

For businesses and public-sector organizations, the practical implication is to treat identity, location, device use and payment arrangements as controls that require ongoing validation throughout a remote engagement, alongside the initial hiring and access-approval process.

#cybersecurity#identitysecurity#remotehiring#nationstate
Open analytics
On the site 1 views
min read 3 12.08.2026
Instagram

FBI probes North Korean remote worker at a US federal agency

Open the post on Instagram ↗