FBI Investigates North Korean IT Worker Hired by U.S. Federal Agency
The FBI is reportedly investigating how a North Korean remote IT worker obtained employment with an unnamed U.S. federal government agency.
The FBI is investigating how a North Korean remote IT worker obtained employment with a U.S. federal government agency, according to Federal News Network, marking an unusual breach of government hiring safeguards.
A senior FBI official disclosed the investigation during a July 28 conference in Washington, D.C., and confirmed to Federal News Network that a North Korean had worked for an unnamed federal agency. The FBI has not publicly identified the agency involved.
FBI investigates North Korean IT worker at federal agency
It remains unclear how the worker secured the position or what role the individual performed. It is also not known whether government data or money was stolen during the incident.
North Korea has operated coordinated campaigns in which IT workers use fraudulent identities to obtain remote jobs at U.S. and European organisations. U.S. authorities have warned that thousands of workers may be involved in such schemes.
The workers can use their employment to generate income that is ultimately sent back to North Korea. Authorities have also accused participants in these operations of stealing intellectual property and sensitive corporate data and, in some cases, using stolen information to extort employers after their identities are discovered.
North Korean remote work schemes have targeted U.S. companies
Government security clearance and vetting requirements have generally presented greater barriers to these schemes than private-sector hiring processes. Previous cases, however, have demonstrated attempts to gain access to government-related work.
The Justice Department brought charges in 2024 against a Maryland man accused of helping a North Korean worker pose as an American to obtain remote employment connected to work for the Federal Aviation Administration.
U.S. authorities have repeatedly taken enforcement actions against networks supporting North Korean IT workers. Investigations have also targeted American facilitators accused of operating groups of laptops that allow overseas workers to appear as though they are connecting to corporate systems from inside the United States.
U.S. authorities have warned about North Korean cyber operations
The remote-worker campaigns form part of broader concerns about North Korea’s cyber operations and North Korea’s efforts to generate revenue despite international sanctions. U.S. officials have linked the regime to cryptocurrency theft and other cybercrime used to generate funds.
Blockchain forensic firms cited in the source reporting estimated that North Korean actors were responsible for 76% of cryptocurrency thefts and obtained at least $2 billion through such activity during 2025.
The latest investigation is notable because it involves employment directly within a federal agency rather than a private company or government contractor. How the worker passed the agency’s hiring process, how the agency’s access was obtained, and whether the incident caused any damage remain unknown.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
Wow
0