FBI investigating North Korean remote IT staffer working for US agency

jaredwiener1 pts0 comments

FBI investigating North Korean remote IT staffer working for US agency | Federal News Network

.async-hide { opacity: 0 !important}

Listen Live

Listen

Schedule

Search

Search

Trending:

DoD considers AI for faster hiring<br>Push for review of counter-WMD work<br>GAO: DOGE's savings claims unverifiable

-->

Cybersecurity

FBI investigating North Korean remote IT staffer working for US agency

Experts say the incident highlights potential gaps in government and industry vetting processes, especially for jobs like IT support work.

Justin Doubleday@jdoubledayWFED

August 10, 2026 7:07 pm

8 min read

The FBI is investigating how an unidentified federal agency was recently swept up in a yearslong campaign involving North Korean remote IT workers fraudulently obtaining jobs at major companies and other organizations.

The North Korean campaign has been notorious for using remote IT contract jobs to infiltrate both Fortune 500 companies and smaller private sector firms.

But experts contacted for this story said it’s not surprising the public sector has been implicated as well. They said the incident highlights a new kind of insider threat, as well as potential gaps in the government and industry vetting processes, especially for jobs like IT support work.

During a panel discussion at a July 28 conference hosted by the Digital Government Institute in Washington, D.C., Todd Hemmen, deputy assistant director of the FBI’s Cyber Capabilities Branch, was asked whether the North Korean remote IT worker issue had impacted government.

Which issues are dominating federal CFO priorities right now? Join us Aug. 25-26 for the Federal Leader’s Guide to the CFO event to find out!

“Without getting into ongoing investigations, we identified just this past week a [Democratic People’s Republic of Korea] remote IT worker that was working for the federal government,” Hemmen said. “Still kind of unpacking that recent case. It’s actually a little bit baffling to me, not understanding this particular agency’s process. But the short answer is yes, we are seeing remote IT workers not just in the private sector – although a vastly higher proportion in the private sector – but we’re also seeing this impact the government to a degree.”

The FBI declined to comment further on the story. It’s unclear what agency was impacted, how long the intrusion lasted, and whether any sensitive data was stolen.

It’s highly likely Hemmen was referring to a remote IT employee doing contract work on behalf of an agency, experts confirmed, given extensive background investigation and identity proofing requirements needed to get a federal job.

Such a case wouldn’t be unprecedented. Last year, a Maryland man was sentenced to 15 months in prison for allowing a North Korean national in China to work on software development contracts for the Federal Aviation Administration.

In a press release announcing the sentencing, the Justice Department said the man fraudulently gained work with at least 13 U.S. companies. Several of those companies contracted the man’s services to "U.S. government agencies in addition to the FAA," the DoJ said, leading to several co-conspirators gaining access to "sensitive U.S. government systems" from China.

A former FBI official, asked about Hemmen’s comments, pointed to the widening scope of the North Korean campaign. The official requested anonymity to speak candidly.

“It’s a natural progression that they would try to get placement into government locations,” the former official said. “It is hard to say whether the alleged DPRK IT worker discovered working inside the federal government was the result of direct targeting or a target of opportunity. Either way, if true, it demonstrates capability and intent to gain access into the federal government.”

Sign up for our daily newsletter so you never miss a beat on all things federal

Donald Blersch, a former senior government official who now advises risk assessment firm Clearspeed, said such incidents point to gaps in support roles that don’t undergo the same vetting as other federal employees and contractors.

“If you’re a contractor supporting a company, even if you’re nowhere near the government contract itself, you may still have access to corporate networks, systems, and information that can ultimately provide a pathway into government environments,” Blersch said. “When those individuals aren’t vetted in a way comparable to the access they’re given, you’re potentially hiring a Trojan horse."

On July 31, U.S. agencies and more than a dozen foreign partner agencies released a “global alert” regarding the risk North Korean remote IT workers pose to “private companies, governments, and individual citizens.”

Forged identities and laptop farms

Official warnings about the DPRK’s remote IT worker scheme go back to 2022. Federal investigators say the North Korean government has dispatched thousands of highly skilled IT workers across the world to gain fraudulent employment and...

government federal remote north korean said

Related Articles