The Federal Bureau of Investigation (FBI) is conducting an investigation into a North Korean who worked at an unnamed US federal agency. This was reported by Federal News Network, citing a high-ranking FBI official who spoke at a conference on July 28 in Washington, DC.
The official confirmed to Federal News Network that the FBI is investigating the circumstances of the North Korean’s employment. This case is a rare confirmed example of a sanctioned North Korean citizen working in a government institution. It is currently unknown how exactly he was hired.
Employment schemes and financing of the regime
The North Korean regime is known for its coordinated and long-term campaigns aimed at fraudulent employment in private organizations and transnational companies. It is believed that in recent years, thousands of North Korean IT workers have obtained jobs in American and European organizations by exploiting vulnerabilities in hiring processes.
The purpose of these schemes is to use fake identification data to obtain remote work and earnings, which are then transferred to the regime. Meanwhile, the workers steal intellectual property and other data that can later be used to blackmail companies after the scheme is exposed. Strict checks and procedures for obtaining access to classified information have mostly prevented the regime’s hackers from infiltrating government institutions, although there have been exceptions.
In 2024, the US Department of Justice charged a man from Maryland who helped a North Korean hacker pose as an American to obtain remote contract work at the Federal Aviation Administration (Federal Aviation Administration). The FBI declined to comment when contacted by TechCrunch representatives on Tuesday. It is currently unknown which specific federal agency was involved in the current incident, or whether data or funds were stolen during it.
US warnings and sources of funding for the DPRK
The US has long warned about the risks associated with North Korean IT worker schemes. American authorities have taken a number of measures to counter and imposed sanctions to obstruct networks operating from Pyongyang, as well as from neighboring Russia and China, and American intermediaries who set up laptop parks that allow North Koreans to work remotely as if they were in the United States.
North Korea relies heavily on hacking attacks, including cryptocurrency theft, to finance its nuclear program, which is under international sanctions. According to blockchain forensics companies, the regime of Kim Jong Un is reportedly responsible for 76% of cryptocurrency thefts. In 2025, this brought the regime at least 2 billion dollars, despite its disconnection from the global financial system.
Source: TechCrunch



