Canada and ten of its closest allies issued a joint advisory Friday warning that North Korean IT workers pose a significant “insider threat” by using remote work arrangements to generate income abroad and support the country's nuclear and ballistic missile programs. The advisory highlights how these workers exploit digital platforms to bypass international sanctions and maintain financial ties with Pyongyang. The warning comes amid growing concerns over the evolving tactics used by North Korean operatives to circumvent restrictions. According to the advisory, these workers frequently falsify their nationality or identity to register for online accounts and secure employment opportunities. Increasingly, they rely on third-party proxies to create such accounts and engage in job interviews, sometimes even establishing in-person contact to build a false sense of trust and obtain legitimate work contracts. These actions enable them to operate under the radar while still contributing financially to North Korea’s military ambitions. The advisory emphasizes that North Korean IT workers are employing increasingly sophisticated methods, including the integration of artificial intelligence, to obscure their identities and expand their global reach. These individuals are described as having high-level technical skills and are targeting sectors such as web development, mobile application creation, software engineering, and blockchain services. Once hired, they often avoid receiving direct deposits and instead request payment via money transfers or cryptocurrencies. Payments are typically funneled through third-party bank accounts before being transferred to a designated foreign account, often with a fee added. The advisory notes that these workers may also utilize virtual private networks (VPNs) and other software tools to mask their real locations or operate “laptop farms”, networks of computers rented or provided by employers to facilitate remote work. These operations allow workers to access company systems from anywhere in the world, making detection and prevention more challenging. Many of these workers reside in North Korea, China, Russia, and parts of Southeast Asia and Africa. A recent case involving an American woman who operated a laptop farm on behalf of North Korean IT workers underscores the scale of this issue. She was convicted of federal charges and received an eight-and-a-half-year prison sentence. Prosecutors estimated that her operation generated over $17 million in illegal revenue over several years. This case illustrates the potential financial impact of the scheme and the lengths to which North Korean operatives will go to sustain their activities. Since at least 2022, officials in the United States, Canada, South Korea, Japan, and other allied nations have raised alarms about the North Korean IT worker scheme. The latest advisory references multiple warnings issued last year, including reports from the UN-mandated Multilateral Sanctions Monitoring Team and the G7’s Financial Action Task Force. These organizations have documented the diversification of North Korea’s revenue streams, noting that the country has significantly enhanced its connection to the international financial system despite ongoing sanctions and efforts to tighten them. To help identify potential threats, the advisory urges companies with online platforms to monitor for specific red flags. These include frequent changes to account information, contact details, and banking data; mismatched names on an applicant’s bank account; and the creation of multiple accounts using the same identification documents. By recognizing these patterns, businesses can better protect themselves against the risks posed by North Korean cyber operatives.
★
Keep the news honest.
ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €5/month.
Become a Supporter