Urgent.News

What's breaking now, across thousands of outlets.

World

North Korean remote IT staffer worked for US government agency, says FBI

The investigation shows that North Koreans are able to infiltrate government agencies, as well as private organizations and crypto exchanges.

The Federal Bureau of Investigation (FBI) is currently probing an incident where a North Korean individual was employed by a U.S. federal government agency. This news surfaced first with the Federal News Network reporting on July 28, citing a senior FBI official speaking at a conference in Washington, D.C. The official confirmed the investigation to Federal News Network, revealing that the North Korean was working for an unspecified federal agency.

The exact hiring process remains uncertain, but North Korea is infamous for its persistent efforts to fraudulently obtain employment at entities across the globe. This specific case marks a singular confirmed instance of a sanctioned North Korean individual working within a government entity. It is believed that there are thousands of North Korean IT professionals who have found employment with U.S. and European organizations by exploiting loopholes in the hiring process.

Their objective is to secure remote positions, earn wages that are sent back to North Korea, while simultaneously pilfering intellectual property and other sensitive data. This information is then leveraged as leverage against the companies once they are inevitably discovered. Despite stringent vetting and security clearance measures, the regime's hackers have managed to infiltrate some government systems, although such incidents are rare.

In 2024, the Justice Department prosecuted a Maryland man who aided a North Korean hacker in obtaining a remote position as a contractor for the Federal Aviation Administration. The FBI did not provide further comment when contacted by TechCrunch. It is unclear which federal agency was targeted and whether any data or funds were stolen during this occurrence.

The U.S. has consistently cautioned about the dangers posed by North Korean IT workers' fraudulent activities. Authorities have taken numerous enforcement actions and sanctions against the networks operating from Pyongyang, as well as neighboring Russia and China, and the American facilitators who establish networks of laptops enabling North Koreans to work remotely as if they were in the United States.

North Korea functions more akin to a transnational criminal organization than a government, depending heavily on cybercrimes, including cryptocurrency thefts, to fund its globally sanctioned nuclear weapons program. Estimates suggest that North Korea is responsible for 76% of cryptocurrency thefts, generating at least $2 billion for the regime in 2025, despite being barred from the global financial system.

Written by urgent.news from TechCrunch's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at techcrunch.com →

More in World

More from Tuesday 11 August →