DPRK IT Worker Network (Overseas Scheme)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·4DwiK3…Lk6ySummary
The DPRK IT Worker Network is a state-directed, multi-year operation run by the North Korean government that places thousands of fraudulently credentialed software developers inside U.S. and global technology and crypto companies using stolen identities, fake personas, and U.S.-based facilitators. Workers generate hundreds of millions of dollars annually in illicit wages funneled back to Pyongyang to fund weapons of mass destruction and ballistic missile programs, and have escalated to data theft and extortion. The operation has drawn DOJ indictments of dozens of individuals across multiple enforcement waves (2024–2026), OFAC sanctions designating front companies and facilitators in China, Vietnam, Laos, Russia, and Spain, and FBI warnings to private industry.
Connected Entities
1 entities · 10 linked investigations- + 7 more
Timeline(17 events)
April 2017
Yanbian Silverstar and Volasys Silver Star begin operating; DPRK IT workers placed in U.S. companies under false identities (approximate start date per DOJ indictment).
DOJ: Fourteen North Korean Nationals Indicted (December 2024)April 2018
Second cohort of DPRK IT workers (Jin Sung-Il, Pak Jin-Song network) begins placing workers at U.S. companies under stolen U.S. passport identities (approximate start date per DOJ indictment).
DOJ: Two North Korean Nationals and Three Facilitators Indicted (January 2025)16 May 2022
OFAC publishes advisory on North Korea IT Workers; first U.S. government public warning to the private sector.
OFAC: Publication of North Korea Information Technology Workers AdvisoryApril 2023
Sim Hyon Sop indicted for conspiring with DPRK IT workers to generate revenue and with OTC crypto traders to launder funds; $7.74 million restrained by U.S. government.
DOJ: Civil Forfeiture Complaint Against $7.74M (June 2025)March 2024
DOJ launches DPRK RevGen: Domestic Enabler Initiative under National Security Division and FBI Cyber and Counterintelligence Divisions, specifically targeting U.S.-based laptop farm operators.
DOJ: Nationwide Actions to Combat Illicit North Korean Government Revenue GenerationAugust 2024
DOJ arrests Nashville-based facilitator Matthew Isaac Knoot; disrupts North Korean remote IT worker fraud schemes. Seizures of related financial accounts.
DOJ: Justice Department Disrupts DPRK Remote IT Worker Fraud Schemes Through Charges and Arrest of Nashville FacilitatorOctober 2024
Google/Mandiant documents sharp increase in extortion attempts by DPRK IT workers, coinciding with increased law enforcement pressure. Workers begin targeting larger organizations.
DPRK IT Workers Expanding in Scope and Scale — Google Cloud / Mandiant11 December 2024
DOJ indicts 14 North Korean nationals (including Yanbian Silverstar CEO Jong Song Hwa, Kim Ryu Song, Ri Kyong Sik) for $88 million IT worker fraud scheme over six years. State Department simultaneously offers $5 million Rewards for Justice bounty on the companies.
DOJ: Fourteen North Korean Nationals Indicted (December 2024)21 January 2025
DOJ indicts North Korean nationals Jin Sung-Il and Pak Jin-Song plus three facilitators for placing workers at 64 U.S. companies between 2018 and 2024, generating at least $866,255 in illicit revenue laundered through a Chinese bank account.
DOJ: Two North Korean Nationals and Three Facilitators Indicted (January 2025)23 January 2025
FBI IC3 issues public service announcement warning companies of data extortion by North Korean IT workers leveraging unauthorized corporate network access.
FBI IC3: North Korean IT Workers Conducting Data Extortion (January 2025)10 June 2025
DOJ announces coordinated nationwide enforcement: two new indictments, one information with plea, arrest of Zhenxing Wang in New Jersey. FBI executes searches of 21 premises across 14 states hosting laptop farms (June 10–17). Seizure of 29 financial accounts and 21 fraudulent websites.
DOJ: Coordinated Nationwide Actions to Combat DPRK IT Workers (June 2025)5 June 2025
DOJ files civil forfeiture complaint against $7.74 million in cryptocurrency tied to Sim Hyon Sop's laundering network.
DOJ: Civil Forfeiture Complaint Against $7.74M Laundered on Behalf of DPRK (June 2025)4 August 2025
CrowdStrike reports North Korean IT worker infiltration attempts grew 220% year-over-year; AI is weaponized at every stage of the hiring process including deepfakes and synthetic identity generation.
North Korean IT worker infiltrations exploded 220% — Fortune / CrowdStrike27 August 2025
OFAC designates Russian national Vitaliy Sergeyevich Andreyev, Shenyang Geumpungri Network Technology Co. (China), and Korea Sinjin Trading Corporation (DPRK) for facilitating payments to Chinyong IT worker network.
Sanctions Imposed on DPRK IT Workers Generating Revenue for the Kim Regime — Treasury (August 2025)12 March 2026
OFAC designates six individuals and two entities (Amnokgang Technology Development Company; Quangvietdnbg International Services Company Limited) for roles in generating approximately $800 million in 2024 for DPRK weapons programs. Twenty-one cryptocurrency addresses across Ethereum, Tron, and Bitcoin identified.
Treasury Sanctions Facilitators of DPRK IT Worker Fraud Targeting U.S. Businesses (March 2026)16 April 2026
Kejia Wang sentenced to 108 months in prison and Zhenxing Wang sentenced to 92 months in prison for operating laptop farms for DPRK IT workers, generating more than $5 million for the regime using stolen identities of 80+ U.S. citizens.
DOJ: Two U.S. Nationals Sentenced for $5M DPRK IT Worker Scheme (April 2026)14 May 2026
CrowdStrike reports DPRK-linked cyber groups stole a combined $2.02 billion in 2025 (up 51% year-over-year); financial services identified as an escalating target sector.
North Korean operatives stole $2 billion last year — financial firms are the next target (Fortune / CrowdStrike)Decision Log
- hash: AHzt7CqCzXkNWMtFpHxXsV5LKNPcT8dLqQLA9vBVganx
- hash: G9W8mVxnf2q4MbT7GmhKDWVjekKXonxx6StP3Vdgvu9y
- hash: Aa7L63s9c39CUnZ1NwGHzNvbUgR5mGRKg4ZufafLZRgs
This investigation is cryptographically anchored to the Solana blockchain (3 events). 30 of 30 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 6/3/2026, 12:08:20 AM
last updated: 7/26/2026, 4:25:42 PM
avoid.net — verified advice for a post-truth world