The FBI is investigating how a North Korean national was hired to work remotely for a U.S. federal government agency, according to a report from Federal News Network.

A senior FBI official reportedly confirmed the investigation during a cybersecurity conference held in Washington, D.C., on July 28.

It is not yet clear how the individual managed to get the job or which federal agency was involved. The case is particularly notable because North Korean IT workers have increasingly been linked to campaigns designed to fraudulently obtain remote jobs at companies and organizations around the world.

North Korea has operated long-running schemes in which IT workers use fake identities and other methods to secure employment with businesses in the United States, Europe, and other regions. Once hired, the workers can earn salaries that are eventually funneled back to the North Korean regime. In some cases, they have also been accused of stealing sensitive information and intellectual property and using the stolen data to pressure companies after their identities are discovered.

Thousands of North Korean IT workers are believed to have found jobs at organizations in recent years by taking advantage of weaknesses in hiring and identity-verification processes. Remote work has made these operations easier because workers can potentially appear to be located in another country while actually working from elsewhere.

Government agencies have generally been more difficult targets because of stricter background checks, identity verification, and security clearance requirements. However, North Korean employment schemes have previously reached the U.S. government.

READ
BdThemes WordPress Plugins Hit by Stealthy Supply-Chain Attack

In 2024, the U.S. Department of Justice charged a Maryland man who helped a North Korean individual pose as an American citizen and obtain a remote contractor position with the Federal Aviation Administration. The case showed how American-based facilitators can help North Korean workers bypass employment safeguards.

The FBI has not publicly identified the federal agency involved in the latest investigation. It is also unclear whether the individual gained access to sensitive government information or whether any data or money was stolen.

U.S. authorities have warned for years about the threat posed by North Korean IT worker schemes. The government has taken enforcement actions and imposed sanctions against networks operating from North Korea as well as facilitators in countries including Russia and China. Authorities have also targeted Americans and others who help North Korean workers obtain jobs by providing identities, addresses, and computer equipment.

In some cases, facilitators have operated laptop farms that allow North Korean workers to remotely control computers located inside the United States. This can make it appear to employers that the workers are physically present in the country when they are actually operating from overseas.


Buy ExpressVPN with PayPal or Credit Card

The employment schemes are part of North Korea’s broader efforts to generate revenue despite international sanctions. The regime has also been linked to major cyberattacks and cryptocurrency thefts, with stolen digital assets helping fund its government and weapons programs.

Advertisement