Tech

FBI probes rare case of sanctioned North Korean national employed by US federal agency

A confirmed instance of a North Korean IT worker infiltrating a US government body underscores ongoing risks from Pyongyang’s state-directed fraud campaigns.

Editorial persona
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: TechCrunch · View original source
North Korean remote IT staffer worked for US government agency, says FBI
Investigation highlights vulnerabilities in remote hiring processes and state-sponsored cybercrime networks

The Federal Bureau of Investigation is examining how a North Korean national secured employment with an unnamed US federal government agency, marking a rare confirmed breach of security clearance protocols. The investigation was first disclosed by Federal News Network, which cited a senior FBI official speaking at a conference in Washington, D.C., on July 28. The official confirmed to the outlet that the bureau is actively investigating the individual’s role within the agency.

This case represents a significant deviation from historical trends, where strict vetting and security clearance practices have largely prevented sanctioned North Korean operatives from accessing government systems. While thousands of North Korean IT workers are believed to have infiltrated private sector organisations in the US and Europe by exploiting weaknesses in remote hiring processes, government agencies have remained comparatively insulated from such infiltration.

The method by which the individual was hired remains unclear, as does the specific federal agency involved. The FBI did not respond to requests for comment from TechCrunch regarding the status of the probe. It is also unknown whether any data was exfiltrated or funds were diverted during the individual’s tenure, although the regime’s modus operandi typically involves stealing intellectual property and using it for extortion once the fraud is discovered.

Pyongyang’s reliance on cybercrime to fund its nuclear weapons programme has intensified in recent years. Blockchain forensic firms have estimated that the Kim Jong Un regime is responsible for 76 per cent of cryptocurrency thefts globally, netting at least US$2 billion in 2025. Authorities have long characterised the North Korean cyber apparatus as operating more like a transnational criminal gang than a traditional state actor, utilising fraudulent identities to secure remote contracts and funnel wages back to the regime.

US authorities have previously taken enforcement actions against networks operating from Pyongyang, Russia, and China, as well as domestic facilitators who provide the infrastructure for these remote work schemes. A notable precedent occurred in 2024, when the Justice Department charged a Maryland man for assisting a North Korean hacker in posing as an American to secure a remote contractor role with the Federal Aviation Administration. This latest investigation suggests that despite heightened awareness and sanctions, the threat of identity fraud in the remote workforce persists.

Continue reading

More from Tech

Read next: Self-hosted Ollama tests expose limits of large AI prompts
Read next: Report alleges OpenAI agents attacked RubyGems, exposing faster software-supply-chain risks
Read next: How to fix Outlook’s “Your message can’t be displayed right now” error