case file 01north korean it scamJuly 2025Litchfield Park, Arizona
the laptop farm in a suburban house
For three years, a woman in Litchfield Park, Arizona kept dozens of company laptops running in her home so North Korean IT workers could appear to be logging in from America. 309 U.S. companies paid them.
309
U.S. companies affected
68
stolen American identities
$17m
revenue generated
102 mo.
prison sentence
what happened
Christina Marie Chapman ran what the Justice Department calls a laptop farm. From about October 2020 to October 2023, U.S. companies shipped work laptops to her house in Arizona, believing they were shipping them to newly hired American remote employees. They were not. Each machine sat in her home with a sticky note on it naming the company and the stolen identity it belonged to, and North Korean IT workers overseas logged into it remotely.
To the employer, everything looked normal. The new hire's laptop was in Arizona. The login came from a residential American internet connection. Payroll went to an American bank account. The work got done. The person doing it was in Asia, using the name and Social Security number of a real American who had no idea.
The workers Chapman helped were placed at a top-five television network, a Silicon Valley technology company, an aerospace manufacturer, an American car maker, a luxury retailer and a media and entertainment company. They also applied to two U.S. government agencies, mostly without success. Chapman shipped 49 laptops and devices overseas, including to a Chinese city on the North Korean border.
“The call is coming from inside the house. If this happened to these big banks, to these Fortune 500, brand name, quintessential American companies, it can or is happening at your company.”
U.S. Attorney Jeanine Ferris Pirro, on the Chapman sentencing
how it was caught
Not by any of the 309 companies. The FBI searched Chapman's home in October 2023 and found more than 90 laptops. She was arrested in May 2024, pleaded guilty in February 2025, and was sentenced in July 2025 to 102 months, eight and a half years.
The companies had done what they thought was due diligence. They ran video interviews. They ran background checks. The identities checked out, because the identities were real. They belonged to real Americans. Nothing in a standard background check asks whether the person on the video call is the person the documents describe.
what it cost
More than $17 million in wages flowed through the scheme to workers acting for the North Korean regime, which takes up to 90 percent of what these workers earn. Chapman was ordered to forfeit $284,555.92 and pay a judgment of $176,850.
For the 68 Americans whose identities were used, the cost was tax records showing income they never earned and employment histories they did not have. For the companies, it was every hour of recruiter time, every onboarding, every piece of internal access granted to somebody who did not exist.
the tells
signals that were visible, in hindsight, before anyone was hired.
- A request to ship the laptop to an address that did not match the identity documents on file.
- A new hire who would not appear on camera consistently, or had persistent video problems.
- Work hours that did not match the time zone the employee claimed to live in.
- Remote-access software appearing on the company laptop shortly after delivery.
- Several supposedly unrelated hires sharing a bank account or payment detail.
what would have stopped it
the checks aperture runs on every session, mapped to this case. nothing here is hindsight-only. each one runs before a hiring team spends an hour on the candidate.
The interview itself was routed through the same proxy chain that made the laptop look American. aperture resolves the real network origin during the session and flags a datacenter, VPN or proxy connection before anyone is hired.
The identity was real, but the person using it was not its owner. Matching the live face on the session against the identity presented is the check a background check cannot perform.
Multiple applicants operating from the same handful of machines produce repeating device signatures. Independent applicants do not share a fingerprint.
The person who interviewed and the person who worked were often not the same. A voice that matches across a session, and across sessions, closes that gap.
sources
- [1]Arizona woman sentenced for $17M information technology worker fraud scheme that generated revenue for North Korea
U.S. Department of Justice · dept. of justice · July 24, 2025
The primary record for the Christina Chapman laptop farm: 309 U.S. businesses, 68 stolen identities, more than $17 million, 102 months in prison. Fortune reports 311 companies; DOJ's own figure of 309 U.S. plus 2 international is used throughout this site.
- [2]Charges and seizures brought in fraud scheme aimed at denying revenue for workers associated with North Korea
U.S. Department of Justice (via GlobalSecurity mirror) · dept. of justice · May 16, 2024
Mirror of the DOJ release; justice.gov's archived copy is behind a bot check. DOJ called it the largest case of its type ever charged.
- [3]Treasury sanctions companies and individuals generating revenue for North Korea
U.S. Department of the Treasury · u.s. treasury · 2024
Source for the finding that the regime takes up to 90 percent of a worker's wages.
- [4]How North Korean IT workers fund Kim Jong Un's weapons program from inside American companies
Fortune · press · October 4, 2025
FBI estimate of hundreds of millions to $1 billion over five years; UN Panel estimate of $250 to $600 million a year; an estimated 1,000 to 10,000 active fake employees.
more case files
north korean it scam · July 2024
the security company that hired one
KnowBe4 trains other companies to spot social engineering. It interviewed a principal software engineer four times on video, ran a background check, checked references, hired him, and shipped him a Mac. Malware started loading 25 minutes after it arrived.
north korean it scam · June 2025
29 laptop farms, 16 states, one week
In June 2025 the Justice Department searched 29 known or suspected laptop farms across 16 states, seized 29 financial accounts and 21 fraudulent websites, and charged the American facilitators making the whole thing possible.
north korean it scam · July 2026
inside a federal agency
In July 2026 an FBI deputy assistant director told a government technology panel that the Bureau had identified, that week, a North Korean remote IT worker employed as a contractor at a U.S. federal agency.