US, Japan, and Allies Issue Alert on North Korean IT Workers Fraudulent Employment

According to a joint advisory issued on July 31 by the National Cyber Directorate (NCD) alongside 11 nations including the United States, Japan, and South Korea, North Korean IT workers are systematically forging identities on remote freelance platforms to fund Pyongyang’s illicit nuclear and ballistic missile programs. The multi-country alert warns that operatives use proxy accounts and stolen credentials to secure high-paying technical jobs while concealing their true locations.

Global Threat Landscape and Joint Advisory

The July 31 multinational warning builds on extensive prior actions by international law enforcement and security bodies. According to the United Nations Security Council Committee established pursuant to resolution 1718 concerning the Democratic People’s Republic of Korea (UNSC 1718 Sanctions Committee) panel of experts, state-sponsored IT personnel represent a major revenue stream for the regime.

National efforts to counter this threat have accelerated globally. In March 2024, the National Police Agency of Japan issued a formal warning regarding these deceptive hiring practices. This was followed by a trilateral joint advisory from Japan, the United States, and South Korea in September 2025, culminating in the broader 11-nation coalition alert that now includes Australia, Canada, France, Germany, Italy, the Netherlands, New Zealand, and the United Kingdom.

How Proxy Networks and Laptop Farms Operate

North Korean IT operatives rely heavily on third-party intermediaries and technical workarounds to bypass traditional KYC (Know Your Customer) protocols. According to the joint advisory, workers regularly use stolen or forged identity documents provided by proxies residing in third countries to register accounts on online freelance marketplaces.

How North Korean IT Workers Infiltrate U.S. Companies: FBI Alert

Did You Know?
North Korean workers often utilize “laptop farms”—arrangements where foreign proxies host company-issued laptops in their homes while the actual developers remotely access the hardware from locations like China, Russia, or Southeast Africa, effectively masking their true IP addresses.

Operatives also utilize virtual private networks (VPNs) and automated trading software to engage in foreign exchange (FX) transactions independently, generating additional hard currency. When receiving payments for software development or blockchain engineering contracts, these workers actively avoid direct bank transfers, pushing instead for alternative payment gateways and cryptocurrency services.

Red Flags for Employers and Platform Operators

The advisory outlines distinct behavioral and technical indicators to help freelance platforms and corporate hiring managers identify fraudulent accounts. According to the NCD document, platform operators should watch for accounts that frequently alter usernames or banking details, display mismatched names between the profile and the receiving account, or show multiple logins originating from a single IP address.

For companies directly hiring remote contractors, warning signs include candidate profiles containing awkward grammar or誤訳 (mistranslations), noticeable inconsistencies or audio-video lag during web conferencing interviews, and a willingness to accept rates far below the standard market average to secure quick placement.

Frequently Asked Questions

What is the primary goal of North Korean IT workers abroad?

According to the 11-nation advisory, these workers generate illicit revenue to directly fund North Korea’s nuclear weapons and ballistic missile programs.

Which countries signed the July 31 advisory?

The advisory was jointly signed by 11 nations: Japan, the United States, South Korea, Australia, Canada, France, Germany, Italy, the Netherlands, New Zealand, and the United Kingdom.

What is a laptop farm in this context?

A laptop farm refers to a setup where a proxy in a third country operates an employer-issued laptop locally, while the North Korean worker remotely accesses the device to hide their actual geographic location.

How do these workers typically receive their wages?

They frequently avoid direct bank transfers and instead request payments via online money transfer services or cryptocurrencies.


Call to Action: Have you encountered suspicious contractor profiles on freelance platforms? Share your insights in the comments below, or subscribe to our newsletter for the latest updates on international cybersecurity threats and compliance alerts.

Leave a Comment