Actor
North Korean overseas IT worker networks
North Korean overseas IT worker networks are state-directed arrangements through which DPRK nationals seek remote technology work using false, stolen or borrowed identities and location-masking infrastructure. US and multilateral authorities assess that proceeds are remitted to DPRK state bodies, including bodies connected with prohibited weapons programmes. The category does not establish that every North Korean worker used fraud, knew the ultimate destination of funds or belonged to the same command chain.
Operating model
Government advisories describe workers operating from third countries, particularly China and Russia, while presenting themselves as residents of the employer's jurisdiction. Facilitators may obtain identity documents, receive company laptops, operate local "laptop farms", open accounts and route pay. Proxy connections and remote administration make a foreign worker appear locally present. The model converts ordinary payroll and contracting systems into revenue channels and can also create access to source code, credentials and proprietary data.
These functions should be separated. Identity fraud supports placement; a facilitator supplies infrastructure; a worker performs or appears to perform labour; a state-linked recipient may receive part of the earnings. Theft, extortion or espionage requires additional evidence. The North Korean remote IT-worker revenue schemes (2022-present) records the campaign, while this entry identifies the network as an actor.
Evidence and enforcement
The October 2025 Multilateral Sanctions Monitoring Team report attributed a broad cyber and IT-worker programme to the DPRK using participating governments' information. Its estimates remain assessments tied to defined periods, not audited state accounts. The FBI's May 2024 guidance described indicators and mitigation steps rather than adjudicating any particular employee's conduct.
Court records provide narrower proof. In April 2026, the US Justice Department reported that Kejia Wang and Zhenxing Wang were sentenced after guilty pleas for a scheme that used at least 80 stolen identities, placed workers at more than 100 companies and generated more than USD 5 million. A separate February 2026 sentence concerned Oleksandr Didenko and placements at 40 companies. Those convictions establish the charged schemes and defendants' conduct, not a universal penetration rate.
The case records also identify distinct victims and facilitators.
Assessment
The network is an intermediary, enabler and adapter for sanctions-constrained revenue generation, and a target of enforcement. Its state nexus is recorded as proxy because official reporting supplies evidence of DPRK direction at programme level. Attribution must still be rebuilt for each worker, facilitator, company and payment chain. No evidence places every such network under Office 39, and that bureau should not be used as a catch-all for DPRK illicit finance.
For employers, the control problem combines identity verification, device custody, payment tracing and privileged-access management. For sanctions authorities, the activity illustrates Sanctions evasion as system design because lawful salary payments can carry illicit identity and beneficiary risk. Publication-day review should refresh indictments, pleas, convictions, designations and estimates separately.
See also
North Korea · North Korean remote IT-worker revenue schemes (2022-present) · Office 39 · Sanctions evasion as system design
Sources
- Multilateral Sanctions Monitoring Team, *The DPRK's Violation and Evasion of UN Sanctions through Cyber and Information Technology Worker Activities*, MSMT/2025/2 (22 October 2025).
- Federal Bureau of Investigation, "Democratic People's Republic of Korea Leverages U.S.-Based Individuals to Defraud U.S. Businesses and Generate Revenue" (16 May 2024).
- US Department of Justice, "Two U.S. Nationals Sentenced for Facilitating Fraudulent Remote Information Technology Worker Scheme that Generated $5M in Revenue for the Democratic People's Republic of Korea" (15 April 2026).
- US Attorney's Office for the District of Columbia, "Ukrainian National Sentenced in 'Laptop Farm' Scheme That Generated Income for North Korean IT Workers" (19 February 2026).
Recommended citation
Cite this entry
Tennant, James J., ed. 'North Korean overseas IT worker networks.' The Encyclopedia of Economic Statecraft, version 2.0, last reviewed 30 July 2026. https://jamesjtennant.com/entries/north-korean-overseas-it-worker-networks/.
Suggest an edit