You have been warned: eleven governments just put the North Korean IT worker threat on the record

August 13, 2026

by imper.ai

On July 31, 2026, eleven governments issued the same warning on the same day.

The United States, through the State Department and the FBI. Japan, through five ministries and agencies. The Republic of Korea. Australia. Canada. France. Germany. Italy. The Netherlands. New Zealand. The United Kingdom. One alert, one subject: North Korean IT workers who impersonate other nationals to get hired, draw a salary, and route the money back to the regime.

The alert states that these governments have warned the world about this before. It points to a joint statement in August 2025 and to a United Nations sanctions monitoring report in October 2025. This is not a first notice. It is a coordinated escalation of a warning that has been repeated for years, now carrying more names than at any point before it.

A warning from one agency is easy to set aside. A warning signed by this many governments, on the same day, is not.

What they are warning about

The alert is specific about how the operation works.

North Korean IT workers falsify their nationality and forge identity documents, in many cases using images of real people’s documents supplied by proxies in third countries. Increasingly, they do not act alone. The alert warns that third parties now sit in interviews on their behalf, and in some cases appear in person, to build enough trust to close a contract. A single hired persona may be run by a team, with the individual on the call changing depending on the time of day.

The infrastructure will be familiar to anyone who reads threat research. VPNs and remote desktop software to disguise location. Laptop farms inside the destination country that receive company-issued machines, so the worker looks domestic while operating from abroad. Payment steered away from direct deposit toward money transfer services and cryptocurrency. And, increasingly, artificial intelligence: generated personas, machine-translated profiles polished enough to pass, and interview video feeds that appear manipulated or artificially generated.

The governments also list the warning signs. Frequent changes to account and payment details. One identity document reused across several accounts. A single account reached from many IP addresses in a short window. A refusal to appear on video, or a video that does not hold up. Offers to work well below market rate. Payment requested in cryptocurrency. No single item is proof. Several together are a pattern.

Why this alert is different from the ones before it

What sets this alert apart is who signed it. Every member of the Group of Seven is on it, the widest coalition yet on this threat. Six of the eleven governments had issued advisories before. France, Germany, Italy, and the Netherlands are on it for the first time, and four of Europe’s largest economies stepping in now says the targeting is no longer concentrated on the United States and South Korea. A year ago, three governments made this case together. Now it is eleven.

Then the pace. CrowdStrike’s 2026 Global Threat Report found that the 2025 activity of FAMOUS CHOLLIMA, its tracking name for the North Korea-linked group behind much of this fraudulent employment, doubled compared to 2024. The same report documents the group folding commercial AI tools into its operations, using image manipulation to build personas, AI-enabled messaging to run multiple accounts at once, and coding assistants to perform the jobs it fraudulently obtains.

Then the fact that should end any debate about whether this is someone else’s problem. In July 2025, a United States federal court sentenced Christina Chapman to more than eight years in prison for running a laptop farm out of her home. The Department of Justice assessed that the operation she supported generated more than $17 million for North Korea between 2020 and 2023. The companies that unknowingly paid those workers included Fortune 500 corporations, a national television network, an aerospace manufacturer, and an American automaker. The acting United States Attorney for the District of Columbia summarized it in one line: “the call is coming from inside the house.”

A pattern, not a handful of cases

Chapman was not an outlier, and the enforcement record makes that clear. The Justice Department has described the sentencings of Matthew Knoot and Erick Prince as its seventh and eighth against US-based laptop farmers in a five-month span. Those two cases alone touched nearly 70 US companies and generated more than $1.2 million for the regime. In a separate case, the Ukrainian national Oleksandr Didenko admitted to selling stolen US identities into roughly 40 companies and to managing as many as 871 proxy identities before his sentencing. The Justice Department describes thousands of these workers deployed worldwide. The Wall Street Journal, reporting this week, described the effort as an operation aimed at the American job market itself.

Why standard hiring controls did not catch it

The alert’s recommended defenses are strict review of identity documents and in-person interviews. Those help. They also describe the gap as much as they close it. Resume screening, background checks, and skills assessments were built to judge whether a candidate can do the job. They were not built to observe the device the candidate is using, the network the session is routed through, or whether the person on the video is operating from where they claim to be.

That gap is measurable. In the first quarter of 2026, imper.ai reviewed 600 candidates for remote technical roles at a single enterprise and flagged four carrying high-confidence indicators of the exact tradecraft these governments describe: Astrill VPN, a provider documented repeatedly across independent North Korean IT worker investigations, AnyDesk installed on interview machines, network latency that could not be reconciled with a claimed US location, VoIP phone numbers, and freshly created email accounts with no history. Four in a single hiring cohort. The tooling matched what threat researchers documented as far back as 2022. It has not needed to change, because the controls most companies rely on still do not look for it.

What to do about it

The gap is fixable, but not by adding another check at the end. It comes down to where verification happens, which signals it looks at, and who owns it.

Make hiring a shared problem between security and HR. Talent acquisition owns the funnel and knows what a normal candidate looks like. Security understands attacker infrastructure and knows what a masked session looks like. Neither sees the whole picture alone. The organizations that catch this treat the hiring pipeline as a security surface, with identity signals feeding the hiring decision rather than surfacing after the offer.

Put a signal layer in front of every interview, not just the last one. The tells the governments describe, remote-access tooling, VPNs and proxies, mismatched geography, virtual audio, a persona that does not behave like one person, sit at the session level and are observable in real time. They do not appear on a resume or a background check. Running that check on every interview, from the first screen onward, is what turns a static gate into a live one.

Correlate across interviews, not only within them. A single hire is often operated by a team, with the person on the call changing by time of day. Assessed one interview at a time, that is invisible. Compared across rounds, it is obvious. Consistency of device, network, voice, and behavior across a candidate’s interviews is a stronger signal than anything a single session provides.

Treat onboarding as the point of no return. Onboarding is where a candidate stops being an outside applicant and becomes an identity with credentials, access, and a company device. Everything before it is reversible at the cost of a declined offer. Everything after it is an insider with legitimate access, and the cost of being wrong becomes an incident rather than a rejected candidate. The verification that matters most is the one that happens before access is granted.

This is what imper.ai focuses on: detecting the device, network, and behavioral signals that reveal who is actually on the other end, across the interview and onboarding window, before access is granted. If you want to see how that maps to your hiring pipeline, get in touch.

What the warning now obligates

This alert is not only a security notice. It is a legal one.

United Nations Security Council Resolution 2397 requires member states to repatriate North Korean nationals earning income in their jurisdictions. The governments warn that contracting with these workers and paying them may itself violate domestic law and result in penalties. The Financial Action Task Force lists North Korea as a high-risk jurisdiction and ties these IT worker schemes directly to the financing of the regime’s weapons program. This is not ordinary payroll fraud. In the governments’ assessment, every salary paid to one of these workers is money moving toward a nuclear and ballistic missile program under active international sanction.

So the warning now sits on the record. It was issued at the highest level, by eleven governments, on a single day, about a threat they say they have flagged repeatedly and that is measurably spreading and accelerating. What any one company does with that warning is now a decision. It can no longer be filed under oversight.

You have been warned.


imper.ai’s Q1 2026 threat research documents the indicators referenced above, with detection guidance for teams responsible for the hiring pipeline.

Further listening

For a longer account of how this network operates, the investigative podcast To Catch a Thief: North Korea On Our Payroll, hosted by former New York Times cybersecurity reporter Nicole Perlroth, follows the scheme from the inside, from a look at a North Korean IT worker on the job to interviews with defectors and visits to the Americans hosting laptop farms. Listen on Apple Podcasts or Spotify. imper.ai has no affiliation with the podcast or its producers; the recommendation stands on the strength of the reporting.

Sources

imper.ai Q1 2026 threat research: https://imper.ai/dprk-it-worker-detection-hiring-pipeline/2 2026. Each case is presented as a hypothesis about attacker behavior with confidence stated per case. imper.ai does not claim definitive attribution absent additional corroborating intelligence.

U.S. Department of State, alert on North Korean IT workers, July 31, 2026: https://www.state.gov/releases/office-of-the-spokesperson/2026/07/alert-to-countries-companies-and-other-entities-regarding-north-korean-it-workers/

The Wall Street Journal, “Inside North Korea’s Operation to Conquer the American Job Market,” August 2026: https://www.wsj.com/business/media/inside-north-koreas-operation-to-conquer-the-american-job-market-93729962

CrowdStrike 2026 Global Threat Report: https://www.crowdstrike.com/en-us/press-releases/2026-crowdstrike-global-threat-report/

U.S. Department of Justice, Arizona woman sentenced in $17M IT worker fraud scheme (Christina Chapman), July 24, 2025: https://www.justice.gov/usao-dc/pr/arizona-woman-sentenced-17m-it-worker-fraud-scheme-illegally-generated-revenue-north

U.S. Department of Justice, two U.S. nationals sentenced for facilitating DPRK IT worker schemes (Knoot and Prince), May 6, 2026: https://www.justice.gov/opa/pr/two-us-nationals-sentenced-facilitating-fraudulent-remote-information-technology-worker-0

U.S. Department of Justice, Ukrainian pleads guilty in D.C. laptop farm scheme (Oleksandr Didenko): https://www.justice.gov/usao-dc/pr/ukrainian-pleads-guilty-dc-laptop-farm-scheme-generated-income-north-korean-it-workers