
A North Korean remote IT worker was reportedly employed by a U.S. federal government agency, prompting an FBI investigation and raising fresh concerns about how sophisticated remote-worker schemes can bypass hiring and security controls.
The FBI investigation was first reported by Federal News Network, which cited a senior FBI official speaking at a conference in Washington, D.C. The official confirmed that the bureau was investigating a North Korean national who had obtained employment with an unnamed federal agency.
The identity of the agency, the length of the person’s employment and whether sensitive information or government funds were accessed have not been publicly disclosed.
The case is particularly significant because North Korean IT worker operations have traditionally focused heavily on private companies. The apparent penetration of a federal workplace highlights the potential risks facing organizations that rely on remote hiring, contractors and third-party staffing arrangements.
Table of Contents
North Korean Remote IT Worker Found at a U.S. Federal Agency
The reported case is unusual because federal employment typically involves stronger identity verification and security procedures than ordinary private-sector hiring.
According to the reporting, the FBI discovered that a North Korean national had been working remotely for an unnamed federal agency. The FBI has not publicly identified the individual or the agency involved.
The investigation also leaves important questions unanswered.
It is currently unclear exactly how the person was hired, what position they held, whether they worked through a contractor, or what level of access they received.
The FBI has also not disclosed whether government data was stolen or whether money was transferred to North Korean networks.
That uncertainty makes the case an important warning rather than evidence that a particular government system was compromised.
The FBI has previously warned that North Korean IT worker can use stolen identities, U.S.-based intermediaries, fraudulent accounts and other methods to obtain remote employment.
How North Korean Remote IT Worker Schemes Operate
North Korea’s remote IT worker operation is designed to make workers appear to be legitimate professionals from another country.
Operatives may use stolen identities, false employment records, fraudulent online profiles and intermediaries located in the United States or other countries.
The FBI says these schemes can involve U.S.-based individuals who receive company equipment and then provide physical access to North Korean workers operating remotely. This can allow organizations to believe they are dealing with a U.S.-based employee while the actual worker is somewhere else.
Microsoft has also documented an ecosystem involving professional profiles, remote job applications, remote desktop tools, laptop farms, facilitators and money transfers.
The objective is not necessarily limited to obtaining a salary. According to U.S. authorities, access gained through employment can also create opportunities to steal proprietary information, access networks or conduct extortion.
Why Remote Hiring Creates a Security Challenge
Remote employment has expanded rapidly across the technology industry, making it possible for organizations to hire skilled workers without requiring them to appear physically at an office.
That flexibility can also create verification challenges.
A company may communicate with someone through video calls, send equipment to a particular address and conduct interviews entirely online. If identity verification is incomplete, the person operating the equipment may not be the individual listed on employment records.
The FBI has specifically warned companies to verify identities during interviews, onboarding and throughout employment. It has also warned that North Korean IT workers have used artificial intelligence and face-swapping technology during video interviews to conceal their identities.
This means a convincing résumé and successful video interview may not always be enough to establish someone’s true identity.
The Role of Fake Identities and U.S. Facilitators
One of the most important elements of the North Korean remote-worker model is the use of intermediaries.
U.S.-based facilitators can help receive laptops, manage equipment and create the appearance that an overseas employee is physically located in the United States.
The FBI has repeatedly warned about this practice.
In some cases, the intermediary may knowingly participate in the scheme. In others, individuals may be deceived into helping without understanding the connection to North Korea.
The FBI says organizations should pay particular attention when employees request unusual changes to shipping addresses or other onboarding arrangements.
U.S. authorities have continued taking enforcement actions against networks that help North Korean remote IT workers obtain employment using fraudulent identities.
Previous North Korean IT Worker Cases
The reported federal-agency investigation comes after years of enforcement actions involving North Korean remote workers.
In April 2026, the U.S. Department of Justice announced that two U.S. nationals had been sentenced for helping North Korean IT workers obtain jobs at more than 100 American companies.
According to the Justice Department, the operation used stolen identities belonging to at least 80 U.S. people and generated more than $5 million in illicit revenue for the North Korean government.
The case demonstrates how the remote-worker model can operate on a large scale.
It also shows why organizations cannot treat identity verification as a one-time hiring step.
The FBI has created a dedicated information page for victims and organizations that believe they may have encountered a North Korean remote IT worker scheme.
What the FBI Recommends
The FBI investigation shows why North Korean remote IT workers remain a serious concern for both private companies and government institutions.
The FBI recommends stronger identity verification throughout the employment lifecycle rather than relying solely on an initial background check.
Organizations should verify an applicant’s identity during interviews and onboarding, carefully examine changes to addresses or payment arrangements, and review third-party staffing companies.
The bureau has also advised companies to educate hiring managers, HR teams and technical staff about the warning signs associated with North Korean IT worker schemes.
For organizations with remote employees, these measures can become part of a broader cybersecurity strategy.
Companies should also limit system access according to job requirements and monitor unusual account activity after employees begin work.
Why Government Agencies Are Especially Concerned
A North Korean remote IT worker entering a government environment creates a different level of concern from an ordinary corporate hiring fraud case.
Federal agencies can hold sensitive information involving government operations, citizens, infrastructure and national security.
Even when an employee does not have access to classified information, legitimate credentials can potentially provide access to internal systems or sensitive administrative data.
The FBI itself describes DPRK IT worker schemes as a counterintelligence and national security concern. Its current overview says North Korean operatives have targeted both private companies and U.S. government agencies by using false identities to obtain remote positions.
That makes the latest investigation important beyond the individual case.
A Growing Problem for Remote Work
The issue also comes at a time when North Korean cyber operations are becoming more sophisticated.
Recent cybersecurity reporting has highlighted the use of artificial intelligence and other technologies to improve social engineering, identity deception and cyber operations. Reuters reported this month that the North Korean-linked Kimsuky group has been developing and using AI-related tools as part of its cyber capabilities.
Meanwhile, recent research has continued to uncover the scale of North Korea’s broader cyber ecosystem.
The lesson for employers is straightforward: remote hiring needs strong security controls.
The goal is not to eliminate remote work. Instead, organizations need to make sure that the person receiving access to their systems is actually the person they hired.
What the FBI Investigation Could Reveal
The biggest unanswered question is how the reported North Korean worker passed the federal agency’s hiring and security procedures.
Investigators will likely need to determine whether the individual used a stolen identity, worked through a contractor, received assistance from a U.S.-based facilitator or exploited another weakness in the recruitment process.
It will also be important to establish what systems the worker could access and whether any information or money was taken.
At this stage, those details have not been publicly confirmed, so claims about a specific breach or stolen government data should be treated cautiously.
What This Means for Companies Hiring Remote IT Workers
The case offers an important warning to businesses, government contractors and other organizations that rely heavily on remote technical workers.
Strong cybersecurity is no longer limited to firewalls, endpoint protection and network monitoring.
Human identity has become part of the security perimeter.
Organizations need to verify applicants, monitor unusual changes after hiring and make sure contractors follow the same security standards as direct employees.
The FBI’s guidance on North Korean IT worker threats provides detailed information for businesses reviewing their hiring procedures. FBI guidance on North Korean IT worker threats
For organizations concerned they may already have been targeted, the FBI also provides a dedicated reporting and victim-information resource. FBI North Korean Remote IT Worker Investigation page
Final Takeaway
The reported discovery of a North Korean remote IT worker inside a U.S. federal agency shows how employment fraud can become a serious cybersecurity and national security issue.
The investigation is still developing, and many details remain undisclosed. However, the case fits a broader pattern documented by U.S. authorities involving stolen identities, remote employment, intermediaries and unauthorized access to organizational systems.
For employers, the message is clear: verifying a worker’s identity should not stop after the interview. Remote hiring, contractor management and ongoing access monitoring all need to be treated as part of the organization’s security strategy.
Related reading: DoorDash Air and the rise of autonomous delivery and Facebook Marketplace’s latest seller updates



