In the quiet hum of remote work, a hidden war has been waged: North Korean operatives, cloaked in stolen identities and forged credentials, embedded themselves inside American companies, turning ordinary paychecks into fuel for nuclear ambitions. On Thursday, the U.S. Treasury moved to name and freeze the architects of this scheme — six individuals and two companies spanning four countries — in recognition that the battlefield of modern statecraft now runs through corporate hiring portals. The operation, estimated to have generated nearly $800 million in a single year, is a reminder that econo
U.S. sanctions North Korean remote worker scheme that funneled $800M to weapons program
Patient money—steady wages flowing for months, harder to detect than a single hack.
Why would North Korea go to such lengths for remote IT work when they could just steal money through hacking?
Because the wages are steady and legitimate. A hacker might get caught and lose access. But a worker on payroll, earning $5,000 a month, can keep that flowing for months or years. It's patient money.
But someone had to notice. A person working remotely from Pyongyang would have a different timezone, different patterns.
That's the genius of the network. They weren't all in Pyongyang. Some were in Laos, Vietnam, other countries. They used VPNs, they rotated shifts, they built credible online histories. To a hiring manager in Houston, they looked like any other freelancer.
And the malware—that seems like a separate crime. Why risk it?
Because once you're inside a company network, you're not just stealing wages. You're stealing intellectual property, source code, trade secrets. That's worth far more than a salary. It's a two-for-one operation.
So the $800 million—is that just wages, or does it include the value of stolen data?
The Treasury's estimate is wages. The data theft is harder to quantify, but it's happening in parallel. Some workers are there to earn money. Others are there to steal. Often it's the same person doing both.
What happens to the companies that hired these people?
They're left exposed. Their networks have been compromised. Their data is in North Korean hands. And they may not even know it yet.
El Pulso
- North Korean operatives spent years posing as freelance IT workers, slipping past corporate vetting processes to collect wages that were quietly routed back to Pyongyang's weapons programs.
- The scheme escalated beyond wage theft — some embedded workers planted malware inside company networks, turning employers into unwitting sources of both cash and stolen trade secrets.
- The U.S. Treasury struck back Thursday, sanctioning six individuals and two companies across North Korea, Vietnam, Laos, and Spain, freezing their U.S.-held assets and cutting off American financial access.
- A Houston technology firm's exposure of suspected North Korean infiltration revealed how deeply the operation had burrowed into American corporate life, handling sensitive systems from the inside.
- Officials warn the threat is accelerating — as traditional sanctions tighten, North Korea is doubling down on cyber and remote work schemes, pushing corporate hiring and vetting practices to the front lines of national security.
In the quiet hum of remote work, a hidden war has been waged: North Korean operatives, cloaked in stolen identities and forged credentials, embedded themselves inside American companies, turning ordinary paychecks into fuel for nuclear ambitions. On Thursday, the U.S. Treasury moved to name and freeze the architects of this scheme — six individuals and two companies spanning four countries — in recognition that the battlefield of modern statecraft now runs through corporate hiring portals. The operation, estimated to have generated nearly $800 million in a single year, is a reminder that economic borders are only as strong as the vigilance of those who guard them.
On Thursday, the U.S. Treasury Department's Office of Foreign Assets Control moved against a global network of fake IT workers who had spent years funneling American corporate wages into North Korea's weapons programs. The scheme was deceptively straightforward: operatives assumed stolen identities, built fabricated online portfolios, and applied for remote positions at legitimate companies. Once hired, they worked the jobs, collected the paychecks, and sent the money back to Pyongyang. In some cases, they went further — planting malware to steal proprietary data and trade secrets. Treasury officials estimate the operation brought in nearly $800 million in 2024 alone.
The sanctions targeted six individuals and two companies operating across North Korea, Vietnam, Laos, and Spain. Among them was Amnokgang Technology Development Company, the North Korean IT firm that served as the operation's recruitment and dispatch hub. Also designated was a Vietnam-based company whose CEO helped convert roughly $2.5 million into cryptocurrency for North Korean handlers. Several money movers and facilitators were named as well, including figures connected to an already-sanctioned nuclear procurement specialist and a coordinator running freelance IT workers out of Boten, Laos.
The operation's reach into American corporate life had already surfaced in prior reporting — a Houston technology firm was found to have unknowingly employed suspected North Korean operatives tied to nuclear funding. The case illustrated how the scheme had matured from simple wage diversion into a sophisticated form of corporate espionage.
Under the new sanctions, U.S.-held assets of the designated parties are frozen, and American businesses are barred from transacting with them. Financial institutions face steep penalties for knowingly facilitating such transactions. Officials caution that as conventional sanctions tighten, North Korea will lean harder on cyber operations and remote work infiltration — making how companies hire, vet, and monitor their workforce a matter of national defense.
On Thursday, the U.S. Treasury Department's Office of Foreign Assets Control moved against a sprawling criminal operation that had been funneling hundreds of millions of dollars from American companies directly into North Korea's weapons arsenal. The target: a global network of fake IT workers, operating under stolen identities and forged credentials, who had infiltrated legitimate firms across the United States and beyond.
The scheme was audacious in its simplicity. North Korean operatives would pose as freelance information technology specialists, complete with fabricated online portfolios and stolen identities, then apply for remote positions at real companies. Once hired, they would work the jobs, collect the wages, and funnel the money back to Pyongyang. In some cases, they went further—planting malware in company networks to steal proprietary data and trade secrets. Treasury officials estimate the operation generated nearly $800 million in 2024 alone, making it one of the regime's most lucrative revenue streams outside of traditional state enterprises.
Thursday's sanctions targeted six individuals and two companies spread across North Korea, Vietnam, Laos, and Spain. Among the designated entities was Amnokgang Technology Development Company, a North Korean IT firm that served as the operation's nerve center, recruiting workers and dispatching them to positions overseas. Also sanctioned was Nguyen Quang Viet, the CEO of a Vietnam-based services company that helped convert approximately $2.5 million into cryptocurrency for North Korean handlers between mid-2023 and mid-2025. The Treasury also went after several money movers and facilitators, including associates of Kim Se Un, an already-sanctioned nuclear procurement specialist, and Yun Song Guk, a North Korean national who coordinated a group of freelance IT workers operating out of Boten, Laos.
The operation's reach extended into American corporate life. CBS News had previously reported on hiring practices at a Houston technology firm that exposed suspected North Korean infiltration tied to funding Pyongyang's nuclear ambitions. The discovery underscored how the scheme had evolved beyond simple wage theft into a sophisticated corporate espionage operation, with workers embedded inside companies handling sensitive technology and information.
Under the new sanctions, any assets held by the designated individuals and companies within U.S. jurisdiction are now frozen. American citizens and businesses are prohibited from conducting transactions with them. Financial institutions that knowingly facilitate transactions with sanctioned entities face severe penalties—a deterrent meant to choke off the money flows that have sustained the operation.
The Treasury's action reflects a broader shift in how North Korea finances its weapons development. As traditional sanctions have tightened, the regime has increasingly turned to cyber operations and remote work schemes to generate hard currency. Officials warn that this trend is likely to accelerate, making corporate security and vetting practices a frontline defense against what amounts to state-sponsored economic infiltration. The remote worker scheme represents not just a theft of wages, but a vulnerability in how American companies hire, vet, and monitor their workforce—one that a determined adversary has learned to exploit with precision.
Citas Notables
The program has become a major revenue stream for Pyongyang, with the regime tapping most of the wages earned by these remote IT workers to rack up funds supporting North Korea's nuclear weapons and ballistic missile development.— U.S. Treasury officials
North Korea has increasingly turned to cyber-powered operations and remote technology work to generate hard currency for development of its nuclear weapon and ballistic missile program.— U.S. officials