READ. SCROLL. LISTEN.

Unbiased headlines. Facts, not spin.

Every story is an unbiased news briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

FBI Finds North Korean IT Worker Embedded Inside a US Federal Agency

FBI Finds North Korean IT Worker Embedded Inside a US Federal Agency
The FBI's Todd Hemmen disclosed in late July that agents identified a North Korean remote IT worker employed by a US federal agency, the latest sign Pyongyang's fake-worker scheme has reached inside the government itself. No agency was named, no charges have been announced, and the FBI won't say if sensitive data was touched.

The FBI has identified a North Korean IT worker who landed a remote job inside a US federal agency, according to Federal News Network. Todd Hemmen, deputy assistant director of the FBI's Cyber Capabilities Branch, disclosed the case at a Washington conference on July 28, saying the bureau had found the worker just the week before.

Hemmen did not name the agency. He gave no details on what the worker's job involved or how long the person had been employed. The FBI has declined to comment further, and it's still unclear whether any sensitive government data or systems were accessed.

This isn't a confirmed breach. It's a confirmed infiltration of the federal payroll by someone using a fake identity to work for Pyongyang's benefit. Those are different things, and nobody should conflate them until more facts come out.

A scheme years in the making

North Korea has run this playbook for years: skilled IT workers use stolen or fabricated identities to land remote jobs at Western companies, then funnel their paychecks back to the regime, according to Korea Herald. It's a sanctions-evasion cash machine that's been documented by US prosecutors repeatedly.

This isn't the first time it's reached federal contractors. Korea Herald points to a Maryland man sentenced last year to 15 months in prison for helping a North Korean national based in China secure software development contracts, including work tied to the Federal Aviation Administration. The Justice Department said that scheme touched at least 13 companies, some of which had contracts with federal agencies and gave the operation access to sensitive government systems.

The difference now is directness. Instead of a US-based facilitator running interference for an overseas operator, the FBI is describing a North Korean worker apparently employed straight into a federal role.

Governments are finally comparing notes

On July 31, the US, South Korea, Japan and other partner nations issued a joint alert warning that North Korean IT workers pose risks to governments, businesses and individuals, according to Korea Herald. Multiple governments are now treating this as a shared national security problem, not just an isolated fraud case each country handles on its own.

US officials have also flagged that North Korean operatives are increasingly using artificial intelligence to build convincing fake resumes, generate identity documents, and even get through job interviews and day-to-day remote work, according to Korea Herald's reporting. AI is lowering the cost of pulling off the deception at scale.

It's bigger than one federal job

A separate case detailed by Allens, the Australian law firm, in a Cyber Brief podcast episode with Ryan LaSalle, CEO of the threat intelligence firm Nisos, shows how far this has spread in the private sector. LaSalle described how Nisos uncovered a North Korean fraud cell after a suspected operative applied for a job at Nisos itself. Investigating that single application exposed a network of more than 20 workers employed across multiple US organizations.

If a security firm can stumble into a 20-person fraud ring just from vetting one applicant, the number of North Korean operatives currently drawing paychecks from American companies and possibly federal contractors is very likely higher than what's been publicly confirmed. Nisos and Allens frame this as an insider threat problem tied directly to the rise of remote work, which strips away in-person verification and makes stolen identities easier to use.

What's proven, what's not

Proven: a North Korean worker got hired into a federal role using deception, per an FBI official speaking on the record. Proven: this pattern has happened before with federal-adjacent contractors, resulting in a real conviction. Alleged but unconfirmed: whether any classified or sensitive data was compromised in this latest case. Unknown: which agency, what role, how long the person worked there, and how they passed federal hiring screening in the first place.

That last question is the one that should worry Congress most. Federal hiring is supposed to include identity verification well beyond what a private company runs during onboarding. If a North Korean operative got past that bar, either the screening process failed, or the impersonation tools being used, including AI-generated documents and coached interviews, are now good enough to beat it.

No agency has said publicly whether this worker has been removed, whether charges are being pursued, or whether other federal roles are being audited for similar infiltration. The FBI's Hemmen made the disclosure at a conference, not in a press release, and the bureau has not answered follow-up questions from reporters. Until there's more transparency on which agency was affected, taxpayers are left trusting an unnamed department's word that nothing sensitive leaked.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

unknown
koreaheraldDisguised North Korean IT worker caught working for US federal agency, FBI probes
unknown
allens.com.auThe Cyber Brief | The operative we hired: inside a North Korean fraud cell