North Korea planted thousands of fake IT workers in US companies — some are still on payroll

The Wall Street Journal has uncovered a sprawling covert operation in which North Korea placed thousands of IT specialists inside American companies under stolen identities. These agents went through real hiring processes, collected salaries, and funneled up to 90% of their earnings back to fund the country's programs.
The scheme relied on purchasing or stealing personal data of US citizens — names, addresses, tax IDs — and building complete digital personas around them. To make it work on the ground, the operation used intermediaries inside the United States. These "laptop farms" were run by people who received company-issued computers at their home addresses and set them up for remote access. The North Korean specialist then connected to the machine over the internet, and from the employer's perspective, everything looked like a normal remote worker based in Texas or Florida.
As part of the investigation, reporters traced a single cell of several operatives that infiltrated eight American companies within a few months. The newsroom obtained an archive from the agents' actual work machines, containing browser history, correspondence, calendars, and even screen recordings. This data formed the foundation of the documentary investigation.
Artificial intelligence has been part of the scheme for a while, but its role has grown dramatically. Neural networks now help craft convincing resumes tailored to specific job openings, pass technical interviews, and maintain ongoing communication with HR departments. The technology makes it much harder for recruiters to spot the deception, as the AI can handle nuanced conversations and adapt to different hiring processes.
Some of these fake employees are still on the payroll of American companies today. The exposure of the operation carries serious consequences for the affected firms, including potential data breaches, legal liabilities, and reputational damage. The investigation highlights how state-sponsored actors have turned the remote work boom into an opportunity for large-scale infiltration of the US tech workforce.


