North Korean IT Workers Used Stolen Identities for Jobs
Federal authorities uncovered a scheme where remote workers leveraged stolen American identities to infiltrate U.S. companies.
Updated on Oct. 8, 2026 in Remote Work

Live Poll
Do you trust that employers sufficiently verify the identity of their remote employees?
North Korean IT workers have used stolen identities to secure remote roles at more than 100 U.S. companies. The FBI identified a North Korean national working within a federal agency as recently as September 2026.
Why it matters
Remote hiring processes often rely on automated systems that struggle to verify the true identity of applicants. This scheme allowed unauthorized workers to bypass standard background checks and gain access to corporate networks.
ID.me blocks two to three fraudulent North Korean applicants weekly among its 900 corporate clients. The illicit scheme has targeted over 100 U.S. firms, with operators often housing dozens of laptops in single residences to manage multiple contracts.
The players
FBI
The Federal Bureau of Investigation is the domestic intelligence and security service of the United States and the primary agency investigating these employment schemes.
ID.me
This digital identity network provides verification services to businesses and government agencies to confirm that applicants are who they claim to be.
Justice Department
The United States Department of Justice is responsible for the enforcement of federal laws and the administration of justice in the country.
The details
Facilitators obtain company laptops at their homes, which they then allow overseas users to access remotely. This setup enables bad actors to maintain dozens of concurrent employment contracts from racks of devices located in single residential houses.
Timeline
A Ukrainian man received a five-year prison sentence in February 2026 for selling stolen identities.
The Justice Department sentenced two U.S. facilitators in April 2026 for their roles in the scheme.
The FBI discovered a North Korean national employed within a federal agency in September 2026.
Market Landscape
This activity exploits the rapid adoption of remote work, forcing companies to reconsider how they verify employees who are never seen in person. The trend highlights a growing arms race between corporate security teams and sophisticated groups using stolen identities to secure high-paying roles.
Companies may implement stricter identity verification requirements, which could lead to longer onboarding times for remote candidates. Individuals who have had their identities compromised may face long-term difficulties regarding their personal credit and employment records.
The takeaway
Businesses should consider using multi-factor biometric authentication to verify employees throughout their tenure, not just during the hiring process. Remote workers should remain vigilant about protecting their digital identity and personal information from potential theft.
Further reading
Learn more about securing remote hiring practices on our Remote Work hub.
Source note: This article includes information reported by Inc..
Live Poll
Do you trust that employers sufficiently verify the identity of their remote employees?










