Summary
- North Korean operatives have quietly built a hidden workforce inside American companies.
- North Korea’s IT operatives typically rely on stolen American identities to pass candidate screening and background checks.
- The findings highlight how North Korea has adapted its sanctions-evasion tactics for the remote work era.
North Korean operatives have quietly built a hidden workforce inside American companies. They are using stolen identities, AI tools and fake profiles to secure remote jobs.
The money earned through this scheme is funneled straight back to North Korea. Investigators say it could be channeling millions of dollars annually to Kim Jong Un’s regime.
A new investigation pieced together leaked data, interviews and previously unseen videos to expose how the operation actually works. The findings offer a rare, detailed look at how Pyongyang’s undercover workers get recruited and placed.
According to the investigation, a single tracked operative applied to more than 1,000 companies in just three months. That volume points to a highly organized, large-scale effort rather than isolated cases.
Investigators also found that AI tools played a direct role in helping operatives write convincing cover letters and resumes. Screen recordings reportedly captured workers reading answers straight from ChatGPT during live hiring interviews.
North Korea’s IT operatives typically rely on stolen American identities to pass candidate screening and background checks. Many are said to juggle multiple jobs simultaneously, all operating under the same stolen name.
Some of these workers reportedly earn as much as $300,000 a year through these remote positions. The US Treasury Department has found that up to 90% of those earnings get funneled directly back to the regime.
Officials estimate the overall operation generates as much as $800 million annually for North Korea. That scale has made it one of the more lucrative sanctions-evasion schemes uncovered in recent years.
Investigators traced the flow of funds through a wider network involving North Korean IT workers and affiliated cybercriminals. That trail eventually led to a company being sanctioned by the US, reportedly tied to Pyongyang’s broader defence development program.
The findings highlight how North Korea has adapted its sanctions-evasion tactics for the remote work era. By blending stolen identities with AI-assisted job applications, the regime has found a modern, low-visibility way to bypass international restrictions on its economy.
As remote hiring becomes more common globally, cases like this are raising fresh questions about how companies verify who they’re actually hiring.
We welcome your contributions! Submit your blogs, opinion pieces, press releases, news story pitches, and news features to opinion@minutemirror.com.pk and minutemirrormail@gmail.com

