The U.S., FBI, and allied nations including Japan, Canada, Germany, Australia, the UK, and South Korea have issued a joint alert warning companies worldwide about North Korean hackers infiltrating private firms using stolen identities, forged documents, and proxy networks. The July 31, 2026 advisory indicates these operatives remotely secure freelance and full-time contracts to receive salaries in Pyongyang and assist in financing the regime's unlawful nuclear weapons and ballistic missile programs. Officials warn that these schemes create significant insider threats, enabling data exfiltration, cryptocurrency theft, and the theft of sensitive corporate information.

Payment preferences are a red flag: many applicants avoid direct deposits and instead request money transfers or cryptocurrency, or direct funds to a third party's account that then routes the money overseas after taking a cut. Many operate from North Korea, China, Russia, Southeast Asia, or Africa while masking their locations with virtual private networks (VPNs), remote desktop software, and so-called “laptop farms.” In these setups, U.S.-based or other overseas facilitators receive company-issued laptops and keep them powered on to enable North Korean workers to log in remotely.

Contracting with North Korean nationals and paying them can violate United Nations Security Council Resolution 2397 and domestic sanctions laws in the United States, Japan, South Korea, and other jurisdictions, exposing firms to legal penalties and financial sanctions.