North Korea has significantly expanded a sophisticated operation to embed fraudulent IT professionals within American and international technology corporations, according to an NBC News investigation published in September 2026 based on US government sources and cybersecurity specialists.
The scheme relies on third-party accomplices in Nigeria, South Africa, Iran, India, and Latin America who assist North Korean agents in clearing job interviews and bypassing verification processes. North Korean technology workers submit applications for remote positions, and after securing contracts, operatives from North Korea assume the actual work responsibilities while compensation is transferred to the North Korean government.
How the Operation Functions
Cybersecurity organization Flare documented that North Korean handlers recruit software developers through professional networking sites like LinkedIn, offering approximately $500 monthly compensation to serve as "interview stand-ins." Selected individuals appear via video conferencing during hiring processes while impersonating the actual candidates.
Researchers examined communications in which a North Korean handler told a prospective accomplice: "You're from a country that is under sanctions. If you're still interested in the role, I need to confirm whether you're comfortable working under someone else's identity."
Nations such as Iran represent prime recruitment targets because developers there face restricted opportunities for legitimate international employment due to existing sanctions regimes, making them more susceptible to these proposals.
Security research organizations Kudelski Security and DTEX have independently verified that software professionals in South Africa, Syria, Iran, Nigeria, Pakistan, and Latin America have been contacted through this recruitment network.
Financial Scale and Impact
United Nations analysts calculate that North Korea's remote technology worker operations generate approximately $600 million annually, with a sanctions monitoring report coordinated by US authorities estimating the total reached $800 million throughout 2024.
US intelligence evaluations place North Korea's combined yearly revenue from cyber activities, encompassing both IT worker schemes and digital currency theft, at no less than $1 billion. During May 2026, cybersecurity firm CrowdStrike documented that state-sponsored North Korean hacking groups accounted for more than $2 billion in cryptocurrency theft throughout 2025, representing a 51% increase compared to the previous year.
Intelligence agencies believe these funds directly support programs under international sanctions, particularly North Korea's nuclear and ballistic missile initiatives.
In July 2026, the US State Department and Justice Department released a coordinated advisory with international partner agencies, noting that North Korea employs "increasingly sophisticated" methods to enlist individuals beyond its borders for concealing operative identities. Blockchain technology company Consensys publicly acknowledged it had inadvertently contracted development work to a North Korean operative without detection.


