FBI Investigates North Korean Remote IT Worker Infiltrating US Federal Agency
The FBI is investigating how an unidentified federal agency was recently compromised by a North Korean remote IT worker as part of a yearslong campaign to infiltrate organizations worldwide. This incident highlights significant gaps in vetting processes for remote positions, especially in IT support.
The Discovery
During a July 28 conference, Todd Hemmen, deputy assistant director of the FBI’s Cyber Capabilities Branch, revealed, "We identified just this past week a [Democratic People’s Republic of Korea] remote IT worker that was working for the federal government." He expressed bafflement at the agency's vetting process, noting that while most cases are in the private sector, government impact is now confirmed.
The Broader Threat
This case is part of a larger campaign where North Korean IT workers use forged identities and "laptop farms" to secure remote jobs, generating $250-$600 million annually for the regime. The FBI warns these workers also steal sensitive data and credentials, posing a cybersecurity threat to national security.
Vetting Gaps
Experts emphasize that support roles often lack the rigorous background checks of security clearance holders. Donald Blersch, former senior government official, warned, "When those individuals aren’t vetted in a way comparable to the access they’re given, you’re potentially hiring a Trojan horse."
AI and Deepfakes
AI is increasingly used to create convincing resumes, identity documents, and deepfakes during interviews, making detection harder. Hemmen noted, "We’re seeing AI use across that entire spectrum of the DPRK remote worker, from application to employment."
Call to Action
The Intelligence and National Security Alliance (INSA) recommends strengthening identity verification, establishing joint working groups, and expanding risk assessments. Lorna Macfarlane, co-author of an INSA white paper, urged organizations to "strengthen every component of their hiring process to prevent these schemes."
Recommendations
- Implement multi-factor identity verification (fingerprinting, biometrics)
- Require proof of education and employment history
- Conduct regular risk assessments of existing controls
- Foster transparency and information sharing about red flags
As Megan Mocho, a partner at Holland & Knight, stressed, "The only way that we are going to get better as a community in preventing unauthorized access is to have transparency around what sort of tactics these individuals are using."





Comments
Join Our Community
Sign up to share your thoughts, engage with others, and become part of our growing community.
No comments yet
Be the first to share your thoughts and start the conversation!