North Korean operatives are using stolen identities, AI-generated documents and US-based facilitators to secure remote IT jobs, generating millions of dollars for Pyongyang while raising security concerns.

North Korean operatives are using stolen identities, artificial intelligence and US-based facilitators to secure remote technology jobs at American companies, generating hundreds of millions of dollars for Kim Jong Un’s regime while creating a growing security threat, according to a Wall Street Journal investigation and US officials.

The operation has now reached the US government. The FBI is investigating a case involving a North Korean remote IT worker who obtained employment with a US federal agency, highlighting how the scheme can extend beyond private companies and potentially expose sensitive government systems.

The FBI has warned that North Korean IT workers can use fraudulent identities and credentials to disguise their real location. US-based facilitators may help receive company laptops and place them at locations known as “laptop farms”, allowing North Korean workers to remotely operate the devices.

AI helps North Koreans pass as American workers

Artificial intelligence is making the operation harder to detect. According to FBI officials, AI can be used throughout the recruitment process, including creating résumés, identity documents and other materials used to support fake identities.

AI-generated images and deepfakes can also help operatives appear to be the people whose identities they have stolen during job interviews or remote meetings.

Todd Hemmen, deputy assistant director of the FBI’s Cyber Capabilities Branch, said the agency is seeing AI being used “across that entire spectrum” of the North Korean remote-worker operation.

worldMore from World

The financial incentive for Pyongyang is substantial. US officials and international investigators have estimated that North Korean IT workers generate hundreds of millions of dollars annually for the regime, providing badly needed foreign currency despite international sanctions.

From fake jobs to potential security threat

The operation is not limited to collecting salaries. Investigators have found cases in which North Korean workers stole proprietary information, credentials and other data after gaining access to company networks.

The FBI’s investigation into the federal employee has therefore raised concerns that the employment scheme could evolve into a broader insider-security threat.

For Pyongyang, the strategy offers a lucrative way to obtain foreign currency. For US employers, it exposes the growing challenge of verifying whether a remote worker is really the person and is really located where they claim to be.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *