How state-sponsored hacking groups are exploiting the OSS ecosystem to advance strategic objectives
On June 23, 2026, a GitHub account called Xpos587 pushed updates to several unrelated repositories within the same narrow window of time. At the time, it seemed innocuous. But weeks later, researchers at Socket, a software supply chain security firm, traced that account back to a campaign called PolinRider and linked it to North Korean state hackers. By the time Socket published its findings on July 6, the attackers had compromised more than 100 open source packages across four different ecosystems. Some of the affected code carried a backdoor—a hidden way for attackers to get back into a system later. Other packages carried an information stealer (malware designed to quietly pull data, like passwords and files, off an infected computer). Developers installed both, believing they were ordinary, run-of-the-mill packages. Socket later determined the campaign had been running since December 2025, seven months before anyone caught it.
The packages involved in that campaign were open source software (OSS): code that anyone can view, use, and contribute to, usually for free. It underpins most of the digital world, from consumer apps to the systems banks and government agencies run on. Historically, the community behind OSS operated on mutual trust, good-faith collaboration, and open exchange. Anyone could submit a change. A smaller group of maintainers decided what made it into the final product. Nobody had to prove their identity or disclose if they were contributing on behalf of an entity or a nation-state.
Strider examined this trust-based system in a report titled Lying in Wait. For organizations’ security, the report introduced what it calls a contributor-centric risk model. In addition to focusing on what the code does—and potential vulnerabilities or malicious code—the approach adds the dimension of understanding who is behind the code.
A System Built on Trust
State-sponsored hacking groups have spent years working their way into open source communities, using the same openness that makes these platforms function against them. According to Strider’s research, groups like Lazarus Group, tied to North Korea, and Cozy Bear, tied to Russia, have infiltrated software supply chains, stolen sensitive data, and run long-term cyber-espionage operations through open source platforms. GitHub, where most of the world’s open source code is hosted and where millions of developers collaborate daily, has become both a primary target and an unwitting tool for this activity.
These groups do not behave like ordinary, financially motivated cybercriminals. A typical criminal group wants a fast payout, and it will abandon an approach quickly if one isn’t coming. State-backed groups operate on a different timeline. They are directed and funded by government entities pursuing specific strategic goals, allowing them to spend years building credibility inside a project before ever putting that access to use.
A Pattern That Keeps Repeating
Strider’s report walks through several OSS incidents that show this is far from an isolated problem.
In 2024, attackers uploaded malicious packages to the Python Package Index, a central repository that millions of developers pull free code from routinely, disguising malware called JarkaStealer as regular tools and using AI chatbots to help the deception spread. Japanese cybersecurity officials attributed the attack to Lazarus Group—a hacking group linked to North Korea.
The discovery of the Log4Shell vulnerability in Log4j, a widely used logging tool that records what is happening inside an application, exposed a large number of organizations to potential attack because so many unrelated systems depended on the same piece of code. Government agencies and cybersecurity firms observed advanced persistent threat (APT) groups—government-backed hacking teams built for long-term, stealthy access—from the PRC, Iran, North Korea, and Turkey actively exploiting the flaw. The costs were enormous. Experts estimate the vulnerability cost organizations more than $90,000 in incident response support per incident, with total costs across industries reaching into the billions. One U.S. federal agency alone dedicated more than 33,000 staff hours to its response, and more than half of corporate security teams spent weeks or longer remediating the issue. Even more than four years later, 72 percent of affected organizations were still detecting active exploitation attempts.
A third approach relied on patience. An individual using the alias “Jia Tan” started contributing to XZ Utils, a popular open source data compression tool, gradually building trust within the project. In 2024, after maintaining a high level of operational security over a lengthy period and earning co-maintainer status, Jia Tan inserted a malicious backdoor into the software. The identity of Jia Tan, and the nation-state group behind the attack, have still never been identified.
Growth Without Guardrails
According to Strider’s research, OSS adoption by businesses and governments has accelerated faster than the security practices meant to protect it. The transparency, decentralized governance, and volunteer-driven collaboration that made open source successful for decades also make it vulnerable to manipulation by well-resourced groups working on behalf of adversarial governments.
Each of the incidents above followed a different path. A vulnerability in one case, a compromised package in another. But in every one, the code passed the same review process every other contribution passes, and no scan or audit caught what was happening. The attackers had spent time earning a position inside the project, and that standing let their changes go through without a second look.
Security tools have grown considerably more capable at detecting the contents of code. They often flag known vulnerabilities, suspicious patterns, and malware signatures before a package ever reaches production. But Strider’s report argues that traditional software security focuses on the code itself while overlooking the people contributing to it. A scan can tell you a package is clean. It cannot tell you who wrote it, or whether that person has ties to a government with a reason to want the code approved.
Strider built a tool called Open Source Software Search to answer exactly that question. By analyzing contributor behavior, affiliations, and activity patterns across open source platforms, the tool helps organizations uncover hidden risks that traditional vulnerability scans completely miss.
Using OSS Search, Strider examined contributors to two widely used repositories: an AI toolkit that makes it possible to run generative AI models on consumer devices and a Python library used to organize data into tree structures. In both cases, it found individuals with direct ties to sanctioned entities and state-backed institutions, whose contributions were embedded inside code that companies rely on every day.
In one of the most infamous scandals in international banking, Deutsche Bank helped move an estimated $10 billion out of Russia without anyone inside the institution raising a flag. Between 2011 and 2015, the bank’s Moscow desk executed what came to be called “mirror trades”: Russian clients, including some tied to politically exposed and sanctioned networks, bought securities in Moscow while related counterparties sold the identical securities through the bank’s London office. Each individual trade looked routine. But the aggregate was a covert pipeline that moved billions in funds out of Russia through London and into offshore accounts, exposing the bank to regulatory penalties on three continents.
This case underscores a reality the financial industry is now grappling with. Banks, fintechs, digital asset platforms, and investment firms face risks today that have outgrown the tools built to detect them. The gap between what traditional compliance can protect against, and the evolving tactics and techniques of adversarial nations, is where strategic intelligence becomes essential.
A Growing Target
Governments in Western countries (including the United States, Canada, United Kingdom, Japan, Australia, and throughout Europe) have designated the financial services and banking sectors as critical infrastructure. When a sector is classified as critical infrastructure, it signifies that its assets, systems, and networks are essential to national security, the economy, or public health. Failure or compromise of that sector would cause debilitating effects for society.
Because financial institutions sit at the center of global capital flows, regulatory scrutiny, and geopolitical competition, their systems, people, and partnerships are persistent targets for state-sponsored actors. The PRC’s systemic emphasis on data as a driver of national power ensures that banks and financial services companies will remain high-priority intelligence targets, valued less for their role as financial intermediaries than for their visibility into the broader ecosystems of strategic industries and capital flows. Banks serve clients in defense, energy, advanced technology, and critical infrastructure. They sit at the center of cross-border trade and investment. And they play a pivotal role in enabling corporate strategy, allocating capital, and shaping risk assessments, giving adversaries a window into the decision-making processes of global firms and governments—and the people who lead them.
State-sponsored actors seeking to infiltrate hiring pipelines, exploit third-party relationships, and influence deals are targeting enterprise banks whose innovation units are building AI, quantum, and cybersecurity capabilities. In the fintech and digital asset space, payment platforms, digital wallets, and crypto-processing environments hold high-value data and assets that adversarial governments are actively pursuing for leverage. And investment firms face growing enforcement from regulatory agencies, where even indirect exposure to sanctioned entities can trigger scrutiny and jeopardize funding.
The pressure is showing up across the sector. North Korean operatives have used fabricated identities to secure remote IT roles inside U.S. financial firms, funneling salaries back to the regime while gaining access to sensitive systems. Those schemes have helped the DPRK steal more than $6 billion in cryptocurrency. At Coinbase, overseas support contractorswere bribed by cybercriminals to exfiltrate customer data from inside the company. The result was a $20 million ransom attempt that affected tens of thousands of users. Cases like the Bitzlato CEO arrest and the JPEX exchange scandal tell a different but related story: undisclosed foreign control and executive-level misconduct at crypto platforms can trigger sanctions exposure, money laundering investigations, and lasting reputational damage.
Where the Financial Sector is Most Exposed
Understanding where adversaries are finding their way into organizations starts with understanding how exposure accumulates. It comes through hiring decisions made without full visibility, deal counterparties whose ownership structures aren’t fully traceable, and supply chain dependencies that no one has examined closely enough. For organizations across financial services, markets, and banking, the risk concentrates in three places.
The first is people. Financial institutions need to screen applicants, employees, vendors, and contractors for risky affiliations and falsified resumes, especially in high-trust roles across cybersecurity, fraud, money-movement operations, AI, quantitative research, and cyber R&D. These are the positions state-sponsored actors are working hardest to access, and they are doing so through falsified credentials, hidden affiliations, and ties to foreign programs that conventional background checks were not designed to detect. Rapid hiring cycles and remote-first work have expanded the surface area, making continuous vetting of both candidates and existing personnel essential.
The second is deals and partnerships. Every M&A transaction, IPO, fund onboarding, investment deal, and joint venture pulls new entities into a financial institution’s orbit, and each one can carry hidden ties, foreign control, or sanctions exposure that is rarely visible from the outside. Financial institutions need to be able to identify these risks across counterparties, customers, investors, LPs, board members, and global partners before a deal closes or a relationship deepens. Even indirect exposure, like adversarial capital or a sanctioned co-investor on a cap table, can trigger regulatory reviews and jeopardize investments. The Deutsche Bank mirror trading scandal is a case in point: the clients and counterparties behind the scheme were closely related entities with common owners, but the bank’s KYC (Know Your Customer) processes failed to surface those connections until billions of dollars had already moved.
The third is open source software and supply chain dependencies. Financial institutions increasingly rely on open source tooling in internal platforms and quantitative systems, as well as third-party crypto-processing centers, liquidity partners, and external infrastructure providers. Contributors to these tools and organizational dependencies can carry hidden nation-state ties, and without visibility into who is contributing to the code and infrastructure these institutions depend on, the risk compounds silently.
Case Study: Tracing an IRGC-Linked Network into European Real Estate
In 2025, reporting by Bloomberg and the Financial Times identified more than 400 million euros worth of European properties linked to Ali Ansari, an Iranian national sanctioned by the UK that year for providing economic resources to the Islamic Revolutionary Guard Corps (IRGC). Despite the designation, his holdings, which include London properties, hotels in Germany, and a resort in Spain, largely remain intact. They are held through a web of offshore companies and proxy individuals spread across at least eight jurisdictions. Any financial institution that encountered this network through a deal, a counterparty, or a vendor relationship would have had no way of knowing what sat behind it using standard screening tools.
Strider traced the network from beginning to end. Inside Iran, Ansari built a sprawling empire under the Tat Group name, with holdings in banking, finance, and construction. Tracing Tat Bank’s ownership through Iran’s corporate registry leads through his core construction entity, through multiple U.S.-sanctioned holding companies, and finally to Bonyad Taavon Sepah, the IRGC Cooperative Foundation. From there, the money moved west along a deliberately layered route. Iranian oil revenues, sold to China through sanctioned crude channels, passed through UAE intermediaries, into offshore holding companies in Saint Kitts and Nevis and the Isle of Man, then into Luxembourg and Dutch corporate vehicles, and finally into European real estate. By the time the capital arrived, it looked like legitimate Western investment on paper.
The network also depended on trusted individuals who could operate without drawing attention. Iman Rahimi Aloughareh held senior roles across Ansari’s Iranian businesses while simultaneously serving as founding managing director of the Luxembourg entities and the German operating company that anchored the European structure. Despite sitting at the center of a network with direct ties to the IRGC, Aloughareh has never been sanctioned. His name would not appear in any due diligence screen. This is exactly the kind of hidden ownership, foreign control, and sanctions exposure that financial institutions need visibility into, and exactly the kind that regulators, once they uncover it, treat as the institution’s responsibility.
How Strider Helps Financial Institutions
Strider is the leading provider of strategic intelligence for identifying and mitigating nation-state risk. The platform equips CISOs, insider threat teams, fraud and FinCrime leaders, compliance organizations, and investment teams with visibility into workforce risk, third-party exposure, and malicious communications.
For personnel risk, People Search and Falsified Resume Screening verify identities and surface risky affiliations before and after hire. Insights surfaces targeted technologies and associated employees most at risk from state-sponsored actors and provides tailored briefings to reduce recruitment risk across AI, quantum, and cyber R&D programs.
For deals, partnerships, and supply chain risk, Organizations Search maps multi-tier ownership and personnel ties for deal counterparties, investors, LPs, board members, joint-venture partners, and crypto-processing vendors. It supports M&A, investment banking, and strategic transactions by identifying foreign ownership, sanctions exposure, and hidden affiliations, and helps organizations better align with compliance requirements.
For open source software risk, OSS Search detects state-linked contributors across open source repos and assesses contributors and dependencies in tooling used in internal platforms or quantitative systems, helping prevent supply chain compromise. Shield feeds curated selectors into SIEM and DLP tools to identify, flag, and monitor geopolitical threats, including malicious emails, domains, and multilingual terms tied to state-sponsored cyber or recruitment activity targeting employees. Strider also provides expert analysis within its Intelligence Center on threats facing the financial sector—offering additional context on state-sponsored recruitment initiatives and efforts to identify and exploit vulnerabilities.
Looking Ahead
The financial services sector is operating in a rapidly changing risk environment—where the threats are geopolitical, the exposure is structural, and the cost of finding out too late keeps rising. Strider gives financial institutions the strategic intelligence to see what’s coming and act before it arrives.
“Nearly every Fortune 500 company has grappled with how to safeguard their workforce from the threat of infiltration by DPRK actors posing as IT workers.”
This observation from Strider CEO and Co-Founder Greg Levesque captures a sobering reality for companies operating in this new geopolitical era: the global talent market is being exploited by adversarial nation-states looking to gain advantage. Strider’s Inside the Shadow Network report reveals how this new threat has direct consequences for businesses—not as abstract geopolitical risk, but as measurable sources of legal, financial, and reputational exposure.
In the first and second blog posts in this series, we examined how North Korea’s remote IT worker scheme operates and the infrastructure that enables it, including the use of falsified identities, freelancing platforms, and PRC-based intermediaries. With that foundation in place, the remaining question for business leaders is: What does this mean for my company?
Answering that question requires moving beyond awareness to insight—understanding where exposure actually exists and how it shows up inside companies.
Risks to Businesses
As North Korea’s remote IT worker scheme has expanded, so too has the scope and scale of its impact on Western and Japanese companies. This risk surfaces across multiple dimensions of business, often incrementally, and often before companies even recognize they are exposed.
Regulatory and legal risks are often the first to emerge. Companies that unknowingly hire or contract North Korean nationals posing as remote IT workers may find themselves in direct violation of U.S. and international sanctions against the DPRK. Companies that violate these sanctions could face severe penalties, including hefty fines, legal action, and restrictions on their ability to operate internationally.
Reputational damage can follow quickly once exposure becomes public. Any degree of association with North Korean nationals can do irreparable damage to the public image of Western and Japanese companies. It can give the perception of weak oversight or insufficient controls, which would be especially harmful for companies in sensitive industries such as defense, technology, and finance. And worse, it can erode trust among customers, partners, regulators, and investors.
Intellectual property theft presents a more subtle but consequential risk. By embedding themselves in legitimate IT roles, North Korean nationals may gain access to a company’s proprietary software, internal tools, and trade secrets. The result is the quiet removal and relocation of intellectual property back to the DPRK, where it can be used to advance its technological capabilities or transferred to other hostile nation-states and criminal organizations.
Data breaches and espionage add another dimension of exposure. Access to corporate systems can allow embedded workers to interact with sensitive data, including personal information, financial records, and confidential corporate communications. That data may be exfiltrated for intelligence purposes or monetized through illicit channels, leaving companies and employees exposed. In some cases, organizations only uncover the extent of these breaches well after the data has left their control.
Financial losses from cybercrime round out the risk landscape. North Korean IT workers have been linked to ransomware attacks, hacking operations, and other cyber activity targeting Western and Japanese companies. The resulting costs for companies have been substantial—from ransom payments and system recovery to business interruption and increased security spending, totaling hundreds of millions of dollars.
Why Traditional Due Diligence Misses This Threat
What this scheme ultimately exposes is a gap between how companies assess risk and how adversarial nation-states are operating in this new geopolitical era. Traditional hiring practices were not designed to detect actors operating through falsified identities, layered intermediaries, and global platforms.
Mitigation begins with visibility. Companies need a clearer understanding of who they are hiring and contracting with—particularly across remote roles, third-party vendors, and outsourced IT services. That means moving beyond surface-level identity verification to in-depth assessments of potential affiliations, linkages, and exposure to networks that may not be immediately apparent through conventional due diligence.
Enter Strider.
Strider helps companies solve the visibility problem by turning open-source data into strategic, actionable intelligence. That means providing companies a faster way to screen both the individuals applying for work and the organizations behind them.
Strider’s People Search screens individuals for nation-state ties, falsified resumes, or hidden risks so teams can make better decisions across hiring and access workflows. It also supports resume verification by flagging inconsistencies and suspicious credentials that can be missed in standard checks.
Strider’s Organizations Search helps companies identify state-sponsored threats across third-party relationships by revealing hidden connections across parent companies, subsidiaries, suppliers, customers, and key personnel. By prioritizing high-risk connections with risk-only filtering, it allows companies to identify potential threats quickly and act before exposure spreads.
Strider brings these insights into the decisions that matter most: when companies are evaluating candidates, approving vendors, or expanding access for contractors. In this new threat landscape, increased visibility is necessary.
Conclusion
Today, it is North Korean workers infiltrating companies while posing as remote IT workers. Tomorrow, it may be other state-backed actors using new tools, methods, or operations to target private industry. The bottom line is that this type of threat isn’t going away. As long as innovations and new technologies are happening in this sector, adversaries will keep looking for ways to access and exploit them.
Companies that recognize this shift now—and invest in intelligence-led approaches to secure their workforce—will be the ones better equipped to protect their operations, their reputations, and their long-term resilience.
How falsified identities, front companies, and intermediaries enable DPRK remote worker operations
Over the past several years, thousands of North Korean nationals—often posing as remote IT workers—have infiltrated Western and Japanese companies and generated billions of dollars for the DPRK regime.
As Strider’s Inside the Shadow Network report details, North Korea has developed an operational model that actively exploits the structure of the global talent market. Understanding how this model works—and why it continues to succeed—is a critical step for Western and Japanese companies seeking to protect their revenue, innovation, and reputation, while also avoiding U.S. and UN sanctions violations.
Tactics, Techniques, and Procedures (TTPs) in Practice
One of the primary tactics underpinning these schemes is the use of disguised identities and front companies. North Korean IT workers routinely operate under aliases, supported by forged documents and fabricated credentials, to secure employment with foreign firms. In many cases, they establish front companies that appear to be legitimate IT services firms that allow these individuals to interact with global clients without raising suspicion.
Freelancing platforms are also an entry point for North Korean nationals targeting Western and Japanese companies. Sites like Upwork, Freelancer, and Fiverr are popular platforms where companies can connect with skilled freelancers looking for remote technical work. These platforms typically require some form of identity verification based on information provided by freelancers, but they make clear that they cannot guarantee a user is who they claim to be. This creates opportunities for North Korean nationals—often using stolen identities—to infiltrate the talent pool of global companies under the guise of remote IT work.
But that initial access is just the beginning. Once a national is embedded in a company, their access to critical systems often expands. Additional permissions are granted. Credentials are issued. Over time, what began as limited work on one or two projects can evolve into broad visibility across a company’s core systems.
In some cases, that access is leveraged directly for cybercrime activities. This can include the deployment of ransomware, phishing campaigns, and hacking operations coordinated with North Korean state-sponsored groups such as the Lazarus Group. The proceeds from these cybercrimes are funneled back to the DPRK regime, helping fund its nuclear and missile programs.
Other nationals focus on application and software development, creating apps and programs marketed to global audiences, often under the banner of foreign companies. At first glance, these apps and programs can appear legitimate and innocuous. They can cover many different fields, including business, health and fitness, social networking, sports, entertainment, and lifestyle. But these apps and programs can also serve as a Trojan horse for malicious code that allows North Korean nationals to conduct surveillance, steal data from users, and generate illicit revenue.
The DPRK has also shown a growing interest in cryptocurrency markets as a mechanism to evade international sanctions. A recent report from the blockchain watchdog company Chainalysis found that North Korea stole more than $2 billion in cryptocurrency last year. That amounts to over half of all crypto stolen globally in 2025 and brings the DPRK’s total identified haul since 2016 to nearly $7 billion. These markets are prime targets for North Korean IT workers, who create and deploy malware to mine cryptocurrencies, hack exchanges, and participate in initial coin offerings.
The Broader Threat Ecosystem
This operational model goes beyond the tactics, techniques, and procedures of individual actors. It depends on a broader ecosystem that allows North Korean nationals to work outside the DPRK and remain connected to global platforms and markets.
Strider is shedding light on how this ecosystem operates. Powered by a dataset spanning nearly 20 billion global open-source documents, Strider is using advanced AI technology and proprietary methodologies to uncover and map complex threat networks and identify potential intermediaries. That research shows that intermediaries based in the People’s Republic of China (PRC) play a particularly important role in this ecosystem. In practical terms, these intermediaries help solve the logistical challenges of operating overseas for North Korean workers.
One example is the Liaoning China Trade Industry Co., Ltd., which was sanctioned by the United States last year after it was discovered that the company had shipped equipment—including computers, graphics cards, HDMI cables, and more—to Department 53, an entity subordinate to the DPRK Ministry of National Defense. It is this type of support that allows North Korean nationals to remain fully equipped and functioning without raising any alarms or jeopardizing their identities.
Strider’s data allows even deeper analysis of PRC operational support. Using Organizations Search, its proprietary third-party due diligence platform, Strider identified 35 additional organizations linked to Liaoning China Trade that could also be supporting Department 53. In many cases, these organizations appear to operate in normal commercial sectors and present themselves as legitimate businesses. But beneath the surface, they pose a significant risk to Western and Japanese companies, which may engage with these organizations and unknowingly expose themselves to potential sanctions violations and serious reputational harm.
While the PRC plays a central role in this scheme due to its proximity and vast digital economy, Strider’s research shows that North Korean IT workers also operate from Russia, Southeast Asia, parts of Africa, and the Middle East. These regions differ in regulatory and political context, but they offer similar advantages: access to the global internet, uneven oversight, and distance from the DPRK.
Conclusion
Government entities are working to uncover and eliminate the DPRK remote worker threat, but the scope and scale of this operation are already far greater than most companies recognize. Addressing this network requires coordinated vigilance across both public and private sectors. To help combat threats like this, Strider developed a tool—Falsified Resume Screening—to help organizational leaders detect fabricated or inconsistent credentials in job applicants.
Moving forward, business leaders must take a proactive approach to safeguarding their organization from unwittingly hiring a remote worker from the DPRK—because the integrity of their workforce, sanctions compliance, and reputation are at stake.
How remote hiring is creating new risk vectors for Western and Japanese companies
On paper, there is nothing unusual about your company’s new hire.
A remote contractor with an impressive resume of relevant experience. A credible background that passes the test. They reside in a location that doesn’t raise concern. They are exactly the kind of employee your company is looking for amid the growing demand for technical talent and the continued rise of remote work.
But beneath the surface is something far more malicious.
A fabricated identity. A borrowed work history. And a quiet connection to one of the most dangerous and authoritarian regimes in the world.
This scenario is not hypothetical.
A recent Strider report, Inside the Shadow Network, reveals how North Korean operatives, with the support of entities in the People’s Republic of China (PRC), have successfully secured work with companies across the U.S., Japan, and Western nations. By operating under false—or sometimes stolen—identities and posing as freelance developers or engineers, these operatives have led targeted efforts to:
- Access sensitive information of Western and Japanese companies
- Advance geopolitical goals
- Skirt sanctions and generate illicit revenue for the DPRK (Democratic People’s Republic of Korea)
This threat points to an alarming new reality: the global talent market itself is being weaponized by adversarial nation-states to advance objectives.
The Global Talent Market Has Become a Strategic Battleground
We have entered a new geopolitical moment.
Industry and academia have now joined governments on the frontlines for this global battle for technological and data superiority. Supply chains and the global talent market have become part of the terrain.
This shift has fundamentally changed where risk resides for Western and Japanese companies, making it harder to separate legitimate business activity from state-directed operations. Instead of attacking systems from the outside, state actors are finding ways to embed themselves within global systems, using ordinary commercial activity to pursue strategic goals with less visibility and greater reach.
The rapid normalization of remote work has accelerated this threat. Distributed teams have expanded access to talent, scaled technical capacity, and accelerated growth across industries. At the same time, they have created new opportunities for nefarious actors to exploit unsuspecting organizations and plant insider threats. As a result, the line between innovation and infiltration has never been thinner.
One recent case brings this into sharper focus. Last year, a woman from Arizona was sentenced to more than eight years in prison for running a laptop farm that helped North Korean operatives gain employment at over 300 U.S. companies. Over the span of three years, she helped North Korean operatives steal the identities of U.S. citizens, pose as remote IT workers, and illegally funnel more than $17 million back to the DPRK government.
This case reflects a broader pattern of remote hiring fraud tied to North Korea already identified by U.S. authorities.
U.S. government investigations have uncovered fraud campaigns carried out by North Korean operatives that span years and continents. According to the U.S. Department of the Treasury, up to 90 percent of the earnings generated through these schemes were then funneled back to the North Korean government, where they were used to support weapons of mass destruction and ballistic missile programs.
In response, U.S. authorities have escalated enforcement efforts. New sanctions have been imposed by the U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) targeting multiple individuals and entities involved in this scheme. Meanwhile, the FBI and U.S. Department of Justice continue to release indictments and public service announcements to increase awareness about these schemes and the importance of due diligence in the hiring process.
This isn’t Happening in Isolation
These schemes are not confined to a single country or actor. They are part of a broader illicit ecosystem that provides the infrastructure and support needed to operate across borders and markets.
As detailed in Strider’s report, many of the DPRK operations uncovered in U.S. government indictments and sanctions involve facilitators and front companies based in the PRC, where North Korean operatives often reside and access the global internet. These PRC-based intermediaries allow access to digital platforms, payment systems, and employment marketplaces, creating a cross-border infrastructure that helps North Korean operatives to work outside the DPRK while obscuring their true origins.
But the DPRK is not the only actor exploiting this dynamic. Strider’s research also found cases of remote workers from the PRC, India, and Pakistan using fake identities, fabricated work histories, and falsified credentials to secure roles inside Western and Japanese companies.
In a world increasingly reliant on remote work and globalized talent pools, this activity is no longer a fringe risk or a series of isolated incidents. It is being normalized by state actors to infiltrate the global talent market and exploit business as usual.
Conclusion
This challenge reflects a major shift in the threat landscape Western and Japanese companies now operate in. Geopolitics have become an integral part of global business operations, particularly in how companies source their talent.
Understanding how these fraudulent worker schemes take shape inside hiring pipelines—how identities are constructed, how roles are secured, and how activity is sustained across borders—is critical for business leaders to secure their company from the inside.