case file 06north korean it scamJuly 2026United States, agency unnamed
inside a federal agency
In July 2026 an FBI deputy assistant director told a government technology panel that the Bureau had identified, that week, a North Korean remote IT worker employed as a contractor at a U.S. federal agency.
1
federal agency, confirmed
ongoing
investigation
what happened
Speaking at a Digital Government Institute panel on 28 July 2026, FBI Deputy Assistant Director Todd Hemmen said the Bureau had identified, that same week, a North Korean remote IT worker who was working for the federal government as a contractor.
The agency was not named. Neither the duration of the employment nor the extent of any data exposure was disclosed, and the investigation was described as ongoing.
Chapman's operation had already tried to place workers at two U.S. government agencies, mostly without success. This is the case that shows the ceiling was reached.
“We identified just this past week a [DPRK] remote IT worker that was working for the federal government.”
Todd Hemmen, FBI Deputy Assistant Director
how it was caught
By the FBI, through investigation, not by the contracting process that hired the worker.
Federal contractors are subject to more identity scrutiny than almost any private employer applies. The scrutiny is documentary. It confirms that papers are valid. It does not confirm that the person on the video call is the person in the papers.
what it cost
Not disclosed. The relevant number is the one nobody can produce: how long the worker was there, and what they could reach.
For every private company weighing whether this is a real risk, the useful comparison is that an organization with federal-grade identity requirements still hired one.
the tells
signals that were visible, in hindsight, before anyone was hired.
- Contractor placements sourced through staffing intermediaries with thin verification of their own.
- Remote-only roles with privileged system access and no in-person step at any point.
- Sign-in patterns and working hours inconsistent with the stated residence.
what would have stopped it
the checks aperture runs on every session, mapped to this case. nothing here is hindsight-only. each one runs before a hiring team spends an hour on the candidate.
Documentary checks confirm information. Confirming the live person is a different question, and it has to be asked of every candidate rather than only the ones somebody already suspects.
A remote-only pipeline has exactly one point where the real person has to be present: the interview. That is the moment worth instrumenting, and it is the moment almost nobody instruments.
sources
- [1]FBI investigating North Korean remote IT staffer working for a U.S. agency
Federal News Network · press · August 10, 2026
FBI Deputy Assistant Director Todd Hemmen disclosed the finding at a Digital Government Institute panel on July 28, 2026.
- [2]Arizona woman sentenced for $17M information technology worker fraud scheme that generated revenue for North Korea
U.S. Department of Justice · dept. of justice · July 24, 2025
The primary record for the Christina Chapman laptop farm: 309 U.S. businesses, 68 stolen identities, more than $17 million, 102 months in prison. Fortune reports 311 companies; DOJ's own figure of 309 U.S. plus 2 international is used throughout this site.
- [3]Alert to countries, companies and other entities regarding North Korean IT workers
U.S. Department of State and ten allied governments · government · July 31, 2026
Eleven governments warn that workers increasingly use third-party proxies to sit interviews and even in-person meetings, and urge in-person verification.
more case files
north korean it scam · July 2025
the laptop farm in a suburban house
For three years, a woman in Litchfield Park, Arizona kept dozens of company laptops running in her home so North Korean IT workers could appear to be logging in from America. 309 U.S. companies paid them.
north korean it scam · July 2024
the security company that hired one
KnowBe4 trains other companies to spot social engineering. It interviewed a principal software engineer four times on video, ran a background check, checked references, hired him, and shipped him a Mac. Malware started loading 25 minutes after it arrived.
north korean it scam · June 2025
29 laptop farms, 16 states, one week
In June 2025 the Justice Department searched 29 known or suspected laptop farms across 16 states, seized 29 financial accounts and 21 fraudulent websites, and charged the American facilitators making the whole thing possible.