all case files

case file 06north korean it scamJuly 2026United States, agency unnamed

inside a federal agency

In July 2026 an FBI deputy assistant director told a government technology panel that the Bureau had identified, that week, a North Korean remote IT worker employed as a contractor at a U.S. federal agency.

1

federal agency, confirmed

ongoing

investigation

what happened

Speaking at a Digital Government Institute panel on 28 July 2026, FBI Deputy Assistant Director Todd Hemmen said the Bureau had identified, that same week, a North Korean remote IT worker who was working for the federal government as a contractor.

The agency was not named. Neither the duration of the employment nor the extent of any data exposure was disclosed, and the investigation was described as ongoing.

Chapman's operation had already tried to place workers at two U.S. government agencies, mostly without success. This is the case that shows the ceiling was reached.

We identified just this past week a [DPRK] remote IT worker that was working for the federal government.

Todd Hemmen, FBI Deputy Assistant Director

how it was caught

By the FBI, through investigation, not by the contracting process that hired the worker.

Federal contractors are subject to more identity scrutiny than almost any private employer applies. The scrutiny is documentary. It confirms that papers are valid. It does not confirm that the person on the video call is the person in the papers.

what it cost

Not disclosed. The relevant number is the one nobody can produce: how long the worker was there, and what they could reach.

For every private company weighing whether this is a real risk, the useful comparison is that an organization with federal-grade identity requirements still hired one.

the tells

signals that were visible, in hindsight, before anyone was hired.

  • Contractor placements sourced through staffing intermediaries with thin verification of their own.
  • Remote-only roles with privileged system access and no in-person step at any point.
  • Sign-in patterns and working hours inconsistent with the stated residence.

what would have stopped it

the checks aperture runs on every session, mapped to this case. nothing here is hindsight-only. each one runs before a hiring team spends an hour on the candidate.

verification at the interview, for everyone

Documentary checks confirm information. Confirming the live person is a different question, and it has to be asked of every candidate rather than only the ones somebody already suspects.

the one observable moment

A remote-only pipeline has exactly one point where the real person has to be present: the interview. That is the moment worth instrumenting, and it is the moment almost nobody instruments.

sources

  1. [1]
    FBI investigating North Korean remote IT staffer working for a U.S. agency

    Federal News Network · press · August 10, 2026

    FBI Deputy Assistant Director Todd Hemmen disclosed the finding at a Digital Government Institute panel on July 28, 2026.

  2. [2]
    Arizona woman sentenced for $17M information technology worker fraud scheme that generated revenue for North Korea

    U.S. Department of Justice · dept. of justice · July 24, 2025

    The primary record for the Christina Chapman laptop farm: 309 U.S. businesses, 68 stolen identities, more than $17 million, 102 months in prison. Fortune reports 311 companies; DOJ's own figure of 309 U.S. plus 2 international is used throughout this site.

  3. [3]
    Alert to countries, companies and other entities regarding North Korean IT workers

    U.S. Department of State and ten allied governments · government · July 31, 2026

    Eleven governments warn that workers increasingly use third-party proxies to sit interviews and even in-person meetings, and urge in-person verification.

human intelligence,on your side.

switch it on today. tomorrow you read a shortlist, not a pile.

free to start, no credit card, set up in minutes