How much money have North Korean fake IT worker scams stolen from companies?

TL;DR: DOJ and Microsoft dismantled 29 laptop farms (~200 computers) tied to North Korean fake IT worker operations in a single coordinated action, and one facilitator was sentenced to 8.5 years for running a $17M scheme. Independent reporting on the broader network puts annual earnings in the hundreds of millions of dollars, funneled through remote IT roles secured using stolen identities and manipulated interview credentials.

The claim

This isn't a handful of isolated fraud cases — it's an organized, sanctions-evading revenue operation that specifically targets the remote-hiring interview process as its entry point, because a video interview is far easier to fake than an in-person one.

The evidence

The Department of Justice and Microsoft's joint action identified 29 "laptop farms" — U.S. locations where roughly 200 company-issued laptops were run remotely by overseas operatives — tied to this scheme. One U.S.-based facilitator was sentenced to 8.5 years in prison for enabling a $17M fraud. Separate investigative reporting on the wider network estimates it has placed operatives in tens of thousands of remote roles and generates revenue in the hundreds of millions of dollars annually, funding weapons programs under UN sanctions.

How the scam gets through the interview

StepWhat actually happens
SourcingStolen or synthetic identity used to apply
Screening callA skilled English-speaking operative interviews on the candidate's behalf
Technical roundSometimes the same person, sometimes a different specialist
Day oneA different person (or rotating shift of people) logs in to actually do the work
OngoingLaptop shipped to a US "farm" so IP/location looks domestic

Step-by-step: reducing exposure

  1. Verify government ID against a live selfie at the start of every remote-hire interview, not just at offer stage.
  2. Continuously re-verify identity through the session, not with a single photo check.
  3. Compare voice and face across every round the candidate attends — screening call through final round.
  4. Confirm the person who joins onboarding matches the person who was interviewed, before granting system access.

FAQ

Is this only a risk for large enterprises? No — smaller companies with less mature verification are frequently targeted precisely because they have fewer checks in place.

Does a standard background check catch this? Rarely on its own — the identities used are often stolen or fabricated well enough to pass a basic check; the interview itself is where the mismatch is easiest to catch.

What industries are most affected? Remote IT, software engineering, and crypto/fintech roles are the most frequently targeted, based on DOJ case filings.

By Pinal Dave Last updated: 2026-08-03