ArticleslgStudy

science

North Korean remote worker scheme

North Korean remote worker scheme is a science topic covered in the lgStudy science library. This page brings together a partial reference excerpt, illustrations, worked examples, real-world applications and a short study plan, so you can understand North Korean remote worker scheme rather than just read about it. In short: North Korean operatives have posed as remote workers in Western companies under stolen or fabricated identities, primarily targeting information technology and technical roles. They generate revenue for the North Korean government, particularly to fund its weapons programs.

North Korean remote worker scheme — main illustration
North Korean remote worker scheme — illustration

Key takeaways

  • North Korean remote worker scheme belongs to science; place it in that map before memorising details.
  • Learn the definition first, then one example that makes the definition concrete.
  • Connect North Korean remote worker scheme to a quantity you can measure, compute or draw — that is where exam questions come from.
  • Reproduce the core statement of North Korean remote worker scheme from memory before moving on to harder problems.

Reference excerpt

North Korean operatives have posed as remote workers in Western companies under stolen or fabricated identities, primarily targeting information technology and technical roles. They generate revenue for the North Korean government, particularly to fund its weapons programs.

Operations The operation emerged as part of North Korea's broader cybercrime strategy under Kim Jong Un, who made information technology a national priority after assuming power in 2011. The COVID-19 pandemic significantly expanded remote work opportunities, which North Korean intelligence services exploited to scale up their operations. According to South Korea's National Intelligence Service, the number of people working in North Korea's cyber divisions grew from 6,800 in 2022 to 8,400 in 2024, including IT worker infiltrators, cryptocurrency thieves, and military hackers. The operations are run by North Korea's Department 53. It is behind front companies including Korea Osong Shipping Co. and Chonsurim Trading Corporation, that sent IT workers to Laos.

Recruitment and training North Korean intelligence services, including the Reconnaissance General Bureau, recruit top graduates from prestigious institutions such as Kim Chaek University of Technology and the University of Sciences in Pyongsong. These operatives are trained in hacking techniques, foreign languages, and are promised higher wages and internet access as incentives.

Methodology The scheme typically follows a standardized process:

Operatives create fake profiles using stolen personal information, including Social Security numbers, addresses and other credentials from real people. Using platforms like LinkedIn and freelance sites like Upwork, operatives apply for high-paying, fully remote positions, with a focus on IT roles such as software engineering, web design, and full-stack development, though the scheme has expanded to other technical and some non-technical roles. Operatives use artificial intelligence tools, including deepfake technology, to pass video interviews and coding assessments while impersonating their stolen identities. After being hired, operatives request that company laptops be sent to addresses controlled by facilitators outside North Korea, who maintain "laptop farms" containing dozens of devices that can be controlled remotely.

Income According to US government estimates, a typical team of North Korean IT workers can earn up to $3 million annually. Individual workers can earn an average of $300,000 per year, with the funds being funneled directly to North Korea's government and weapons programs. Some operatives work multiple jobs simultaneously to maximize earnings.

Notable cases

Christina Chapman case In 2025, Christina Marie Chapman, a 44-year-old American citizen from Arizona, pleaded guilty to federal charges related to operating a laptop farm that facilitated North Korean operatives for three years. Chapman's operation involved over 300 American companies and generated more than $17 million for the North Korean government. She was sentenced to 8 years in federal prison.

KnowBe4 incident In July 2024, KnowBe4, a US cybersecurity training company, discovered that a new employee identified as "Kyle" was actually a North Korean operative who had passed background checks and ID verification.

Nisos incident In June 2025, Nisos, a US security company, determined that a job applicant known as "Jo" was a North Korean operative. The company ran an operation to gain insight into the cell's full operations.

Impact According to Mandiant (now part of Google Cloud), nearly every Fortune 500 company chief information security officer interviewed about the issue has admitted to hiring at least one North Korean IT worker. SentinelOne, a cybersecurity firm, reported receiving approximately 1,000 job applications linked to North Korean operatives. North Korean operatives generally target software engineer, front-end developer and full-stack developer jobs, though the scheme extends to roles beyond traditional IT. The impact of these schemes includes data theft, as operatives often steal sensitive company data and intellectual property; the installation of malware for future access or ransomware attacks; and compliance violations, since unknowingly employing North Korean operatives violates international sanctions. While initially focused on US companies, the scheme has expanded globally. CrowdStrike reports tracking similar operations in the United Kingdom, Poland, Romania and other European countries, as well as organizations in South Asian countries.

US government response The FBI, State Department, and Treasury Department have issued joint advisories warning companies about the threat, and initiated multiple prosecutions. In December 2024, the Justice Department indicted 14 North Koreans for generating at least $88 million over six years. The Department of Justice announced indictments in January 2025 against two Americans for operating a six-year scheme that placed North Korean operatives in over 60 US companies, generating more than $800,000 in revenue. The U.S. Treasury's Office of Foreign Assets Control (OFAC) announced sanctions in January 2025 against two individuals and four entities involved in North Korea's illicit remote IT worker schemes that generate revenue for the country's weapons programs. The sanctioned entities include two front companies (Korea Osong Shipping Co. and Chonsurim Trading Corporation) that sent IT workers to Laos, Chinese company Liaoning China Trade Industry Co. for supplying technological equipment, and individuals Jong In Chol and Son Kyong Sik who ran the front operations.

See also

Illicit activities of North Korea Lazarus Group Remote work Identity theft Sanctions against North Korea

References

Illustrations

North Korean remote worker scheme: a laptop farm in Litchfield Park, Arizona, US, photographed by the FBI in 2023
a laptop farm in Litchfield Park, Arizona, US, photographed by the FBI in 2023

Worked examples

Example 1 — a first encounter with North Korean remote worker scheme

Start with the simplest possible case. Write down what North Korean remote worker scheme claims or describes in one sentence, then invent the smallest concrete situation in which that sentence is true. In science, the smallest case is usually a single object, a single equation or a single measurement. Check that every symbol or term in your sentence has a meaning in that case.

Example 2 — changing one variable

Take the situation from Example 1 and change exactly one quantity: double it, halve it, or set it to zero. Predict what should happen to North Korean remote worker scheme before you calculate. Comparing your prediction with the result is the fastest way to find out whether you understand the idea or only the words.

Example 3 — an exam-style question

Typical questions about North Korean remote worker scheme ask you to (a) state it precisely, (b) apply it to given data, and (c) explain a limitation. Practise writing all three answers in under five minutes; the third part is what separates a full-mark answer from an average one.

Applications of North Korean remote worker scheme

In research
North Korean remote worker scheme appears in science research whenever the underlying quantities have to be modelled precisely. Papers usually cite it as a starting assumption and then explore where it breaks down.
In technology and industry
Engineering practice reuses North Korean remote worker scheme in design rules, simulations and safety margins. Knowing the idea lets you read a specification sheet and understand why the numbers look the way they do.
In the classroom
North Korean remote worker scheme is common in secondary-school and first-year university syllabi. It links to neighbouring topics Crime in North Korea, Cybercrime, Identity theft, so understanding it makes those chapters shorter.
In everyday life
Look for North Korean remote worker scheme outside the textbook — in sport, cooking, traffic, electronics or the sky above you. An example you found yourself is remembered far longer than one you were given.
Ask Teacher Smith questions about this articleOpens your AI tutor with a question about “North Korean remote worker scheme” →

Affiliate

Preply — study more efficiently by working with a personal tutor. 50% off.

How to study North Korean remote worker scheme in 20 minutes

  1. Read the reference excerpt below once, without taking notes.
  2. Close the page and write down what North Korean remote worker scheme means in your own words.
  3. Compare your version with the excerpt and mark what you missed.
  4. Work through the three examples above with pen and paper.
  5. Explain North Korean remote worker scheme out loud to somebody else — or to Teacher Smith in the lgStudy chat.

Frequently asked questions

What is North Korean remote worker scheme in simple terms?

North Korean operatives have posed as remote workers in Western companies under stolen or fabricated identities, primarily targeting information technology and technical roles. They generate revenue for the North Korean government, particularly to fund its weapons programs.

Why does North Korean remote worker scheme matter?

Because it connects several science ideas at once: it gives you a definition you can apply, a quantity you can calculate, and a way to check whether a result is plausible.

How should I study North Korean remote worker scheme?

Read the excerpt, restate it from memory, then work through the examples and applications listed on this page. The five-step study plan above takes about twenty minutes.

What does this page cover?

It gives you a compact reference excerpt plus original lgStudy explanations, examples, applications and study material on North Korean remote worker scheme.

Tags

  • Crime in North Korea
  • Cybercrime
  • Identity theft
  • Money laundering
  • North Korea
  • Telecommuting

Keep exploring