all case files

case file 05north korean it scamJune 202516 U.S. states

29 laptop farms, 16 states, one week

In June 2025 the Justice Department searched 29 known or suspected laptop farms across 16 states, seized 29 financial accounts and 21 fraudulent websites, and charged the American facilitators making the whole thing possible.

29

laptop farms searched

16

states

100+

U.S. companies affected

80+

stolen identities

what happened

The Justice Department created a dedicated program for this, the DPRK RevGen: Domestic Enabler Initiative, aimed specifically at the Americans who make the scheme work. Overseas workers cannot receive a company laptop at an American address, open an American bank account, or pass an American identity check without help on the ground.

In a coordinated sweep it searched 29 known or suspected laptop farms across 16 states, seized 29 financial accounts and 21 fraudulent websites, and brought two indictments plus a plea agreement. Six Chinese and two Taiwanese nationals were indicted in Massachusetts. Four North Koreans were indicted in Georgia for stealing more than $900,000 in cryptocurrency from their own employers.

The two central American facilitators, Kejia Wang and Zhenxing Wang of New Jersey, were later sentenced to 108 and 92 months. Between 2021 and October 2024 they had used more than 80 stolen identities to place North Korean workers at over 100 U.S. companies, many of them Fortune 500 firms, using shell companies with ordinary-sounding names to make the workers look like American contractors.

These schemes target and steal from U.S. companies and are designed to evade sanctions and fund the North Korean regime's illicit programs.

Assistant Attorney General John A. Eisenberg

how it was caught

Through the facilitators, not the applicants. Each laptop farm is a physical address that receives hardware, and hardware leaves a paper trail. Federal investigators worked backwards from shipping records, financial accounts and the shell companies that issued the invoices.

That is why enforcement always arrives after the hire. The scheme is caught downstream, at the logistics layer, months or years after a hiring team already onboarded somebody.

what it cost

More than $5 million in revenue for North Korea from the Massachusetts case alone, with over $3 million in damages to the victim companies for audits and remediation.

Over 100 companies had to work out, after the fact, which systems a fraudulent employee had touched and for how long. That work is expensive, and it happens long after the recruiter who approved the hire has moved on.

the tells

signals that were visible, in hindsight, before anyone was hired.

  • Several employees sharing a bank account, a payment detail or a shipping address.
  • A contracting firm that supplies remote IT workers with unusually little verifiable history.
  • Requests to change the laptop shipping address after the offer is signed.
  • Employees whose sign-in locations do not match their stated residence.

what would have stopped it

the checks aperture runs on every session, mapped to this case. nothing here is hindsight-only. each one runs before a hiring team spends an hour on the candidate.

pool-level pattern detection

A laptop farm is, by definition, a small number of machines serving many identities. That repetition is obvious to a system reading the whole pool and invisible to a recruiter reading one application.

the session, examined

Silent Push documented how this infrastructure is built specifically to defeat simple location checks. Evaluating the interview session itself is a different question from asking which country an address is in.

NeuralPrint, on the person

The identities belonged to real Americans, so everything a background check inspects was true. Only the person was false, and that is the one thing a document check never looks at.

sources

  1. [1]
    Justice Department announces coordinated, nationwide actions to combat North Korean remote information technology workers' illicit revenue generation schemes

    U.S. Department of Justice · dept. of justice · June 30, 2025

    The DPRK RevGen: Domestic Enabler Initiative. Searches of 29 known or suspected laptop farms across 16 states, 29 financial accounts and 21 fraudulent websites seized.

  2. [2]
    Two U.S. nationals sentenced for facilitating fraudulent remote information technology worker scheme

    U.S. Department of Justice · dept. of justice · April 15, 2026

    Kejia Wang, 108 months; Zhenxing Wang, 92 months. 80+ stolen identities placed at 100+ U.S. companies including many Fortune 500 firms.

  3. [3]
    Unmasking the DPRK remote worker problem

    Silent Push · security research · January 2026

    How laptop-farm proxy chains defeat geofencing, so an interview that looks like it comes from a U.S. home is routed from overseas.

  4. [4]
    Two U.S. nationals sentenced for facilitating fraudulent remote information technology worker scheme

    U.S. Department of Justice · dept. of justice · May 6, 2026

    Matthew Knoot and Erick Ntekereze Prince, 18 months each. DOJ noted these were the seventh and eighth U.S. laptop-farmer convictions in five months.

human intelligence,on your side.

switch it on today. tomorrow you read a shortlist, not a pile.

free to start, no credit card, set up in minutes