North Korea's Fake IT Worker Scheme: 100,000 Workers Funnel $500M Annually to Regime
By
speckx
Crackling crust, pillowy middle. The kind of bagel that earns a second cup of coffee.
Summary
Researchers from IBM X-Force and Flare Research have uncovered North Korea's extensive fake IT worker scheme, where approximately 100,000 North Korean nationals operate as remote IT contractors to infiltrate companies worldwide. These workers funnel an estimated $500 million annually back to the Kim Jong Un regime while also stealing sensitive information. The report details the organizational structure of the operation, from dodgy recruiters to Western collaborators, and provides mitigation strategies for businesses to protect themselves.
Key quotes
· 3 pulledResearchers at IBM X‑Force and Flare Research have uncovered data that sheds light on how North Korea's fake IT worker schemes operate and infiltrate companies in order to funnel money back to the regime and steal sensitive information.
The threat of North Korean nationals operating as remote IT contractors or full-time technol
Researchers map full org chart of the scam from dodgy recruiters to helpful Western collaborators
You might also wanna read
Cloudflare Threatens Italian Exit Over €14 Million Regulatory Fine
Cloudflare, an American network and cybersecurity company, has threatened to exit the Italian market in response to a €14 million fine impos
Edmunds Data Breach: 178,000 Records Exposed by ShinyHunters Hacking Group
In January 2026, the automotive research and car-shopping platform Edmunds was breached by the ShinyHunters hacking group. The compromised d
Iran threatens to charge undersea cable operators in Strait of Hormuz, highlighting vulnerability of global internet infrastructure
Iranian state-linked media has proposed charging operators of undersea internet cables in the Strait of Hormuz for access to what Iran claim
Chinese EV shipment arrives in Melbourne as geopolitical tensions drive global electric car demand surge
A massive shipment of Chinese-made electric vehicles (EVs) has arrived in Melbourne, signaling a potential permanent shift in Australian mot
Google Ads to require passkeys for sensitive account actions starting July 15, 2026
Google Ads will mandate passkeys for sensitive account actions starting July 15, 2026, replacing traditional passwords with biometric or dev
DORA regulation creates compliance challenges for London law firms beyond GDPR requirements
The article discusses how the Digital Operational Resilience Act (DORA), which took full effect in January 2025, is impacting London law fir
