Startups

North Korean remote IT worker case reaches a US federal agency, FBI says

The FBI is examining a North Korean remote IT worker who was working for the federal government, while key details remain undisclosed.

Theo Nakamura

By Theo Nakamura · Staff Writer

· 3 min read

North Korean remote IT worker case reaches a US federal agency, FBI says
Photo: TechCrunch

The North Korean remote IT worker FBI investigation has reached an unnamed U.S. federal agency, according to an FBI official. For employers and investors tracking cyber risk, the key point is narrow but significant: the bureau says it identified a worker working for the federal government, though it has not disclosed the agency, the person’s route into the job or whether any information was taken.

Todd Hemmen, deputy assistant director of the FBI’s Cyber Capabilities Branch, disclosed the case during a July 28 conference in Washington, according to Federal News Network. Hemmen said the FBI had identified the worker in the preceding week and was still examining the case. He said such cases occur far more often in the private sector, but also affect government to some extent.

The FBI declined to provide further details to Federal News Network. It remains unknown how long the worker was engaged, which agency was involved, and whether sensitive data was stolen. TechCrunch subsequently reported the investigation, also noting that those facts had not been disclosed.

What is known about the North Korean remote IT worker case?

The public disclosure establishes that the FBI is investigating a North Korean remote IT worker who was working for the federal government. It does not establish that the person was a direct federal employee. Experts interviewed by Federal News Network assessed that contract work for an agency was highly likely, given federal identity-proofing and background-investigation requirements, but that is not a confirmed detail of this case.

The episode follows an earlier, separate case involving the Federal Aviation Administration. Federal News Network reported that a Maryland man received a 15-month prison sentence for allowing a North Korean national in China to work on FAA software-development contracts. The outlet said the Justice Department had also stated that companies contracted the man’s services to other federal agencies, allowing co-conspirators to access sensitive government systems from China.

How do these remote-worker schemes operate?

The Justice Department said in June 2025 that court documents alleged North Korean workers used stolen or false identities to obtain remote IT jobs at more than 100 U.S. companies. The alleged schemes involved assistance from people in the U.S. and other countries, along with front companies and fraudulent websites.

In some cases, according to the Justice Department, U.S.-based facilitators hosted “laptop farms,” locations holding employer-provided computers that workers could access remotely. The FBI has separately said facilitators may receive company devices at U.S. addresses, enable remote-desktop connections, reship laptops overseas, open financial accounts, create job-search accounts or attend virtual interviews.

Those allegations and prior enforcement actions provide context, not evidence that any of those methods were used in the newly reported federal-agency case.

What does the FBI recommend for remote-worker hiring?

In a 2025 public alert, the FBI recommended that employers scrutinize identity documents and directly verify employment and education histories. It also advised in-person identity checks where possible, close review of changes to equipment-shipping addresses, and withholding system access until background checks are complete.

The bureau said third-party IT contracting can add risk because the ultimate employer is further removed from the hiring process. That guidance does not identify a failure in the federal case, but it outlines the checks the FBI recommends for remote-worker hiring.

This story draws on original reporting from TechCrunch.

More from Startups

All Startups