all case files

case file 01north korean it scamJuly 2025Litchfield Park, Arizona

the laptop farm in a suburban house

For three years, a woman in Litchfield Park, Arizona kept dozens of company laptops running in her home so North Korean IT workers could appear to be logging in from America. 309 U.S. companies paid them.

309

U.S. companies affected

68

stolen American identities

$17m

revenue generated

102 mo.

prison sentence

what happened

Christina Marie Chapman ran what the Justice Department calls a laptop farm. From about October 2020 to October 2023, U.S. companies shipped work laptops to her house in Arizona, believing they were shipping them to newly hired American remote employees. They were not. Each machine sat in her home with a sticky note on it naming the company and the stolen identity it belonged to, and North Korean IT workers overseas logged into it remotely.

To the employer, everything looked normal. The new hire's laptop was in Arizona. The login came from a residential American internet connection. Payroll went to an American bank account. The work got done. The person doing it was in Asia, using the name and Social Security number of a real American who had no idea.

The workers Chapman helped were placed at a top-five television network, a Silicon Valley technology company, an aerospace manufacturer, an American car maker, a luxury retailer and a media and entertainment company. They also applied to two U.S. government agencies, mostly without success. Chapman shipped 49 laptops and devices overseas, including to a Chinese city on the North Korean border.

The call is coming from inside the house. If this happened to these big banks, to these Fortune 500, brand name, quintessential American companies, it can or is happening at your company.

U.S. Attorney Jeanine Ferris Pirro, on the Chapman sentencing

how it was caught

Not by any of the 309 companies. The FBI searched Chapman's home in October 2023 and found more than 90 laptops. She was arrested in May 2024, pleaded guilty in February 2025, and was sentenced in July 2025 to 102 months, eight and a half years.

The companies had done what they thought was due diligence. They ran video interviews. They ran background checks. The identities checked out, because the identities were real. They belonged to real Americans. Nothing in a standard background check asks whether the person on the video call is the person the documents describe.

what it cost

More than $17 million in wages flowed through the scheme to workers acting for the North Korean regime, which takes up to 90 percent of what these workers earn. Chapman was ordered to forfeit $284,555.92 and pay a judgment of $176,850.

For the 68 Americans whose identities were used, the cost was tax records showing income they never earned and employment histories they did not have. For the companies, it was every hour of recruiter time, every onboarding, every piece of internal access granted to somebody who did not exist.

the tells

signals that were visible, in hindsight, before anyone was hired.

  • A request to ship the laptop to an address that did not match the identity documents on file.
  • A new hire who would not appear on camera consistently, or had persistent video problems.
  • Work hours that did not match the time zone the employee claimed to live in.
  • Remote-access software appearing on the company laptop shortly after delivery.
  • Several supposedly unrelated hires sharing a bank account or payment detail.

what would have stopped it

the checks aperture runs on every session, mapped to this case. nothing here is hindsight-only. each one runs before a hiring team spends an hour on the candidate.

NeuralPrint, on the session

The interview itself was routed through the same proxy chain that made the laptop look American. aperture resolves the real network origin during the session and flags a datacenter, VPN or proxy connection before anyone is hired.

NeuralPrint, on the person

The identity was real, but the person using it was not its owner. Matching the live face on the session against the identity presented is the check a background check cannot perform.

pool-level pattern detection

Multiple applicants operating from the same handful of machines produce repeating device signatures. Independent applicants do not share a fingerprint.

NeuralPrint, across the session

The person who interviewed and the person who worked were often not the same. A voice that matches across a session, and across sessions, closes that gap.

sources

  1. [1]
    Arizona woman sentenced for $17M information technology worker fraud scheme that generated revenue for North Korea

    U.S. Department of Justice · dept. of justice · July 24, 2025

    The primary record for the Christina Chapman laptop farm: 309 U.S. businesses, 68 stolen identities, more than $17 million, 102 months in prison. Fortune reports 311 companies; DOJ's own figure of 309 U.S. plus 2 international is used throughout this site.

  2. [2]
    Charges and seizures brought in fraud scheme aimed at denying revenue for workers associated with North Korea

    U.S. Department of Justice (via GlobalSecurity mirror) · dept. of justice · May 16, 2024

    Mirror of the DOJ release; justice.gov's archived copy is behind a bot check. DOJ called it the largest case of its type ever charged.

  3. [3]
    Treasury sanctions companies and individuals generating revenue for North Korea

    U.S. Department of the Treasury · u.s. treasury · 2024

    Source for the finding that the regime takes up to 90 percent of a worker's wages.

  4. [4]
    How North Korean IT workers fund Kim Jong Un's weapons program from inside American companies

    Fortune · press · October 4, 2025

    FBI estimate of hundreds of millions to $1 billion over five years; UN Panel estimate of $250 to $600 million a year; an estimated 1,000 to 10,000 active fake employees.

human intelligence,on your side.

switch it on today. tomorrow you read a shortlist, not a pile.

free to start, no credit card, set up in minutes