Security News

Countries Crack Down on North Korean IT Worker Fraud Network

The Record · 19 Sept 2026
Key Takeaway Australian SMBs hiring remote IT contractors should strengthen identity verification and due diligence processes to avoid unknowingly engaging fraudulent workers linked to sanctioned schemes.

A UN-linked sanctions monitoring body has released a new report detailing how several countries have responded to North Korea's ongoing scheme of placing IT workers under false identities in companies worldwide. The scheme, first detailed in an October report, involves North Korean nationals stealing or buying identification documents to secure high-paying remote IT roles, with proceeds funnelled back to the regime.

According to the latest findings, Argentina opened an investigation into a woman accused of laundering funds earned by North Korean IT workers through payment accounts, and froze related assets. In Pakistan, authorities launched a case against an alleged document forger and two others accused of helping North Koreans secure IT work in the country. The United States also sanctioned companies and individuals in Vietnam and Laos in March for helping North Korean workers open bank accounts and launder earnings, while Laos confirmed that 19 North Korean workers identified in the original report had entered the country between 2018 and 2019 and left by 2025.

The report highlights that this fraud extends well beyond North Korea's borders, with facilitators operating in dozens of countries to help workers pose as legitimate employees. For businesses that hire remote IT contractors or freelancers, this is a reminder that identity verification failures can have serious geopolitical and financial consequences.

North Korea IT worker fraud sanctions identity theft insider threat

Summarised by CISO AI from The Record. We link back to every original so you can read it yourself.