Skip to main content
Mallory
Back to stories
enforcement-actioncryptocurrency-platform-riskidentity-impersonation-fraudstate-sponsored-espionage

US Nationals and Foreign Accomplices Plead Guilty in North Korean IT Worker Employment and Crypto Laundering Scheme

Updated 7d agoFirst seen Nov 14, 202534 sources

The US Department of Justice announced multiple guilty pleas from US citizens and a Ukrainian national for their roles in facilitating North Korean IT workers' fraudulent employment at US companies and laundering millions in illicit proceeds. The scheme involved US nationals providing their identities, hosting company laptops, and even taking drug tests on behalf of North Korean operatives, enabling them to bypass vetting processes and earn over $2 million in salaries. Ukrainian national Oleksandr Didenko also pleaded guilty to wire fraud and identity theft, having stolen and sold US citizen identities to North Korean IT workers, and operated a site that managed hundreds of stolen identities and coordinated laptop farms across several US states.

Authorities seized more than $15 million in cryptocurrency linked to North Korean facilitators, and Didenko agreed to forfeit over $1.4 million. The Justice Department highlighted these convictions and asset seizures as significant progress in disrupting North Korea's use of remote IT work and cryptocurrency theft to fund its regime. The cases underscore the complexity and international reach of North Korea's cyber-enabled financial schemes, as well as the ongoing efforts by US law enforcement to identify and prosecute both domestic and foreign enablers.

Share:
US Nationals and Foreign Accomplices Plead Guilty in North Korean IT Worker Employment and Crypto Laundering Scheme
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

10 events from the earliest known activity through the most recent confirmed update.

10 EVENTS
Jun 1, 20206y ago

North Korean IT worker scheme operates through U.S. facilitators

From at least June 2020, U.S.-based facilitators helped North Korean IT workers obtain remote jobs at American companies by using borrowed or stolen identities, hosting company laptops in the United States, and enabling remote access. One scheme described by the DOJ continued until August 2024 and affected dozens of U.S. firms.

Ukrainian broker steals and sells U.S. identities for the scheme

A Ukrainian national, Oleksandr Didenko, stole and sold U.S. identities that were used by overseas IT workers, including North Koreans, to fraudulently secure employment at U.S. companies. He later agreed to forfeit more than $1.4 million tied to the activity.

North Korean operatives infiltrate at least 136 U.S. companies

Across the fake IT worker operation, North Korean personnel used fraudulent identities and U.S.-based support networks to infiltrate at least 136 American companies. The activity generated roughly $2 million in illicit earnings, including about $1.28 million in salary payments in one laptop-farm scheme.

Jan 23, 20251y ago

DOJ indicts five in DPRK remote IT worker fraud scheme

The U.S. Department of Justice announced indictments against two North Korean nationals and three facilitators for a multi-year scheme that used stolen identities and U.S.-based laptop farms to obtain remote IT jobs at American companies. Authorities also arrested two U.S. defendants, searched a North Carolina laptop-farm location, and said Dutch authorities arrested another defendant on a U.S. warrant.

Office of Public Affairs | Two North Korean Nationals and Three Facilitators Indicted for Multi-Year Fraudulent Remote Information Technology Worker Scheme that Generated Revenue for the Democratic People’s Republic of Korea | United States Department of Justice
Nov 14, 20256mo ago

DOJ seizes over $15 million tied to APT38 crypto thefts

The U.S. Department of Justice announced the seizure or sequestration of more than $15 million in cryptocurrency proceeds linked to North Korean state-sponsored threat activity associated with APT38. Officials described the action as part of a broader effort to disrupt Pyongyang's cyber-enabled revenue streams.

Five defendants plead guilty in North Korean IT worker cases

The DOJ disclosed that five people, including multiple U.S. citizens and Ukrainian national Oleksandr Didenko, pleaded guilty for roles in helping North Korean IT workers evade sanctions and infiltrate U.S. companies. The charges included wire fraud conspiracy, aggravated identity theft, and related offenses tied to identity brokering and laptop-farm operations.

Nov 17, 20256mo ago

FBI and DOJ urge stronger remote-worker vetting by employers

Following the guilty pleas and enforcement actions, U.S. authorities warned that North Korea's fake IT worker operations remain a growing threat to private-sector organizations. The FBI urged companies to strengthen hiring and remote-worker verification practices to detect fraudulent applicants and prevent further infiltration.

Apr 16, 20261mo ago

Two U.S. nationals sentenced in North Korean IT worker scheme

The U.S. Department of Justice announced the sentencings of Kejia Wang, 42, and Zhenxing Wang, 39, for helping North Korean remote IT workers fraudulently obtain jobs at more than 100 U.S. companies. Authorities said the operation used stolen identities from at least 80 U.S. persons and generated millions in revenue for North Korea.

Two U.S. Nationals Sentenced for Facilitating Fraudulent Remote Information Technology Worker Scheme that Generated $5M in Revenue for the Democratic People’s Republic of Korea - Infosec.Pub

U.S. offers $5 million reward on North Korean IT worker conspirators

Alongside the sentencing announcement, the U.S. government offered rewards of up to $5 million for information that could help disrupt North Korean fake IT worker schemes and identify additional people involved. The move expanded the response beyond prosecutions to incentivize new leads on the broader network.

Two Americans sentenced for helping North Korea steal $5 million in fake IT worker scheme | TechCrunch
May 7, 202611d ago

Two U.S. laptop-farm operators sentenced in DPRK IT worker scheme

U.S. federal courts sentenced Matthew Issac Knoot of Tennessee and Erick Ntekereze Prince of New York to 18 months in prison for operating laptop farms that helped North Korean IT workers pose as U.S.-based employees. Prosecutors said the scheme generated more than $1.2 million for Pyongyang after victim companies shipped work laptops to the defendants' residences.

US ‘laptop farmers’ get jail time for aiding DPRK IT workers scam local firms | NK News
SOURCE COVERAGE

Sources

34 references tracked. Mallory keeps watching after this page renders.

34 SOURCESView all
ItproNews
May 11, 2026

Two US nationals sentenced for role in prolific fake worker laptop farms | IT Pro

itpro.com

Open source
HackreadNews
May 10, 2026

Two US Men Sentenced for Helping North Korean Hackers Infiltrate US Firms

hackread.com

Open source
Toms HardwareNews
May 8, 2026

North Korean fake remote worker scam lands two Americans 18-month prison sentences for hosting laptops - US firms unknowingly shipped laptops to “employees” who secretly worked from overseas via remote desktop, generating $1.2 million for Pyongyang | Tom's Hardware

tomshardware.com

Open source
Help Net SecurityNews
May 8, 2026

Helping North Korean IT remote workers is becoming a fast track to prison - Help Net Security

helpnetsecurity.com

Open source
CyberscoopNews
May 7, 2026

American duo sentenced for hosting laptop farms for North Korean IT workers | CyberScoop

cyberscoop.com

Open source
Nk NewsNews
May 7, 2026

US ‘laptop farmers’ get jail time for aiding DPRK IT workers scam local firms | NK News

nknews.org

Open source
Bleeping ComputerNews
May 7, 2026

Americans sentenced for running 'laptop farms' for North Korea

bleepingcomputer.com

Open source
Us Department Of JusticeNews
May 6, 2026

Office of Public Affairs | Two U.S. Nationals Sentenced for Facilitating Fraudulent Remote Information Technology Worker Schemes to Generate Revenue for the Democratic People’s Republic of Korea | United States Department of Justice

justice.gov

Open source
ScworldNews
Apr 17, 2026

US imposes extended jail time on North Korean laptop farm facilitators | brief | SC Media

scworld.com

Open source
CyberscoopNews
Apr 16, 2026

US nationals sentenced for aiding North Korea’s tech worker scheme | CyberScoop

cyberscoop.com

Open source
Toms HardwareNews
Apr 16, 2026

Two US citizens get combined 16 years in prison for running North Korean laptop farms - fake remote IT work scheme netted DPRK $5 million in around three years | Tom's Hardware

tomshardware.com

Open source
Cyber Security NewsNews
Apr 16, 2026

Two U.S. Nationals Sentenced for Running Laptop Farm for DPRK Remote Workers

cybersecuritynews.com

Open source
Nk NewsNews
Apr 16, 2026

Two Americans sentenced for helping North Korean IT workers steal from US firms | NK News

nknews.org

Open source
BlueteamsecNews
Apr 16, 2026

Two U.S. Nationals Sentenced for Facilitating Fraudulent Remote Information Technology Worker Scheme that Generated $5M in Revenue for the Democratic People’s Republic of Korea - Infosec.Pub

infosec.pub

Open source
Bleeping ComputerNews
Apr 16, 2026

US nationals behind DPRK IT worker 'laptop farm' sent to prison

bleepingcomputer.com

Open source
Help Net SecurityNews
Apr 16, 2026

Two US nationals jailed over scheme that generated $5 million for the North Korean regime - Help Net Security

helpnetsecurity.com

Open source
Techcrunch Com SecurityNews
Apr 16, 2026

Two Americans sentenced for helping North Korea steal $5 million in fake IT worker scheme | TechCrunch

techcrunch.com

Open source
The Record MediaNews
Apr 16, 2026

New Jersey men given lengthy sentences for running North Korean laptop farms | The Record from Recorded Future News

therecord.media

Open source
Register SecurityNews
Apr 16, 2026

Americans behind Nork IT fraud sentenced to 200 months • The Register

go.theregister.com

Open source
Us Department Of JusticeNews
Apr 15, 2026

Office of Public Affairs | Two U.S. Nationals Sentenced for Facilitating Fraudulent Remote Information Technology Worker Scheme that Generated $5M in Revenue for the Democratic People’s Republic of Korea | United States Department of Justice

justice.gov

Open source
Security Online InfoNews
Nov 18, 2025

DOJ Seizes $15M in Crypto from APT38, Unveils Guilty Pleas in North Korean IT Worker Fraud Scheme

securityonline.info

Open source
Arstechnica SecurityNews
Nov 17, 2025

5 plead guilty to laptop farm and ID theft scheme to land North Koreans US IT jobs

arstechnica.com

Open source
Register SecurityNews
Nov 17, 2025

Selling your identity to North Korean IT scammers isn't a sustainable side hustle

go.theregister.com

Open source
Dark ReadingNews
Nov 17, 2025

US Citizens Plead Guilty to Aiding North Korean IT Worker Campaigns

darkreading.com

Open source
ScworldNews
Nov 17, 2025

US makes headway on North Korean cyber threat crackdown

scworld.com

Open source
Help Net SecurityNews
Nov 17, 2025

Five men admit helping North Korean IT workers infiltrate US companies

helpnetsecurity.com

Open source
SecurityaffairsNews
Nov 16, 2025

Five admit helping North Korea evade sanctions through IT worker schemes

securityaffairs.com

Open source
The Hacker NewsNews
Nov 15, 2025

Five U.S. Citizens Plead Guilty to Helping North Korean IT Workers Infiltrate 136 Companies

thehackernews.com

Open source
The Record MediaNews
Nov 14, 2025

Multiple US citizens plead guilty to helping North Korean IT workers earn $2 million

therecord.media

Open source
CyberscoopNews
Nov 14, 2025

DOJ lauds series of gains against North Korean IT worker scheme, crypto thefts

cyberscoop.com

Open source
Bleeping ComputerNews
Nov 14, 2025

Five plead guilty to helping North Koreans infiltrate US firms

bleepingcomputer.com

Open source
Bank Info SecurityNews
Nov 14, 2025

DOJ Continues Crackdown on North Korea's Cyber Schemes

bankinfosecurity.com

Open source
GovinfosecurityNews
Nov 14, 2025

DOJ Continues Crackdown on North Korea's Cyber Schemes

govinfosecurity.com

Open source
Us Department Of JusticeNews
Jan 23, 2025

Office of Public Affairs | Two North Korean Nationals and Three Facilitators Indicted for Multi-Year Fraudulent Remote Information Technology Worker Scheme that Generated Revenue for the Democratic People’s Republic of Korea | United States Department of Justice

justice.gov

Open source
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.