FBI probes rare case of sanctioned North Korean national employed by US federal agency
A confirmed instance of a North Korean IT worker infiltrating a US government body underscores ongoing risks from Pyongyang’s state-directed fraud campaigns.

The Federal Bureau of Investigation is examining how a North Korean national secured employment with an unnamed US federal government agency, marking a rare confirmed breach of security clearance protocols. The investigation was first disclosed by Federal News Network, which cited a senior FBI official speaking at a conference in Washington, D.C., on July 28. The official confirmed to the outlet that the bureau is actively investigating the individual’s role within the agency.
This case represents a significant deviation from historical trends, where strict vetting and security clearance practices have largely prevented sanctioned North Korean operatives from accessing government systems. While thousands of North Korean IT workers are believed to have infiltrated private sector organisations in the US and Europe by exploiting weaknesses in remote hiring processes, government agencies have remained comparatively insulated from such infiltration.
The method by which the individual was hired remains unclear, as does the specific federal agency involved. The FBI did not respond to requests for comment from TechCrunch regarding the status of the probe. It is also unknown whether any data was exfiltrated or funds were diverted during the individual’s tenure, although the regime’s modus operandi typically involves stealing intellectual property and using it for extortion once the fraud is discovered.
Pyongyang’s reliance on cybercrime to fund its nuclear weapons programme has intensified in recent years. Blockchain forensic firms have estimated that the Kim Jong Un regime is responsible for 76 per cent of cryptocurrency thefts globally, netting at least US$2 billion in 2025. Authorities have long characterised the North Korean cyber apparatus as operating more like a transnational criminal gang than a traditional state actor, utilising fraudulent identities to secure remote contracts and funnel wages back to the regime.
US authorities have previously taken enforcement actions against networks operating from Pyongyang, Russia, and China, as well as domestic facilitators who provide the infrastructure for these remote work schemes. A notable precedent occurred in 2024, when the Justice Department charged a Maryland man for assisting a North Korean hacker in posing as an American to secure a remote contractor role with the Federal Aviation Administration. This latest investigation suggests that despite heightened awareness and sanctions, the threat of identity fraud in the remote workforce persists.
