North Korean remote IT staffer worked for US government agency, says FBI
The FBI is reportedly investigating how a North Korean was hired to work for a U.S. federal government agency.
News of the investigation was first reported by Federal News Network, citing a senior FBI official speaking at a conference on July 28 in Washington, D.C. The official confirmed to Federal News Network that the FBI is investigating a North Korean working for an unnamed federal agency.
It’s unclear how the North Korean was hired, but the regime is known for its coordinated and long-running campaigns aimed at fraudulently obtaining employment at private organizations and multinationals. The case marks a rare confirmed instance of a sanctioned North Korean working for a government agency.
There are thought to be thousands of North Korean IT workers who have gained employment with U.S. and European organizations in recent years by exploiting weaknesses in the hiring process. The goal is to use fraudulent identities to gain employment with remote positions and to earn a wage that gets funneled back to the regime, all the while stealing intellectual property and other data, then using that information to extort the companies when they are inevitably caught.
But strict vetting and security clearance practices have largely kept the regime’s hackers out of government — though, not without incident. The Justice Department brought charges in 2024 against a Maryland man who assisted a North Korean hacker to pose as an American to get a remote job as a contractor for the Federal Aviation Administration.
The FBI declined to comment when contacted by TechCrunch on Tuesday. It’s not known which federal agency was affected, and if any data or funds were stolen during the incident.
The U.S. has long warned about the risks posed by North Korean IT workers’ schemes. U.S. authorities have taken several enforcement actions and sanctions to stymie both the networks that operate from Pyongyang, as well as neighboring Russia and China, as well as the American facilitators who set up fleets of laptops that allow the North Koreans to work remotely as if they were in the United States.
North Korea operates more like a transnational criminal gang than a government, and relies on hacks, including thefts of cryptocurrency, to fund its globally sanctioned nuclear weapons program. The Kim Jong Un regime is reportedly responsible for 76% of cryptocurrency thefts, per blockchain forensic firms, netting the regime at least $2 billion during 2025 despite being banned from the global financial system.
Updated with FBI’s decline to comment.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, this week in security.
He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at [email protected].
View Bio