How Fake Remote Jobs Helped North Korea Make Millions
Two U.S. operatives sentenced for enabling North Korean scheme that infiltrated companies, exposing cyber & sanctions-evasion threat.
Jason Kwon ·

Two men from New Jersey have been sentenced to prison for their roles in a scheme that allowed North Korean operatives to secure jobs at major U.S. companies and generate millions in revenue. Zhenxing “Danny” Wang received more than seven years, while Kejia “Tony” Wang was sentenced to nine years by a federal court in Boston.
Prosecutors said the operation brought in roughly $5 million for Pyongyang, providing a steady funding stream tied to its broader sanctions evasion efforts.
How the Scheme Worked
At the center of the operation were so-called “laptop farms” run from the defendants’ homes. The men allegedly hosted company-issued computers that enabled overseas workers—many linked to North Korea—to appear as if they were based in the United States.
Those workers secured jobs at Fortune 500 firms using stolen American identities. In at least one instance, prosecutors said, the access allowed the theft of export-controlled information from a defense contractor in California.
Background: A Growing Playbook
The case reflects a wider shift in how North Korea generates hard currency. Alongside cryptocurrency theft, the regime has increasingly deployed skilled IT workers abroad to infiltrate Western firms and collect salaries.
U.S. officials say these operations have stolen billions in recent years. A separate case in 2024 charged an Arizona woman in a similar scheme that compromised dozens of identities and affected hundreds of companies, including a major Silicon Valley group.
Direct Impact: Companies and Workers Exposed
The scheme touched multiple sectors, including defense, semiconductors, and software. Companies in Massachusetts and California unknowingly paid wages to workers who were not who they claimed to be.
At least 80 Americans had their identities misused, according to prosecutors. The use of front companies and falsified employment records helped the operatives pass hiring checks and maintain access once inside.
Industry Implications: Weak Spots in Hiring Systems
The case exposes vulnerabilities in remote hiring and contractor verification processes. Experts say the use of U.S.-based shell companies, combined with legitimate-looking credentials, makes detection difficult.
Staffing and recruiting firms have also played an unintended role. Some agencies vouched for candidates after conducting background checks that failed to identify the deception, allowing the workers to blend into normal workflows.
Global Context: Sanctions Pressure and Cyber Strategy
For North Korea, these operations serve a strategic purpose. With traditional revenue channels restricted by sanctions, the regime has leaned on cyber-enabled methods to fund state priorities, including its weapons programs.
Embedding workers within subcontractors has expanded the reach of these networks. That approach allows access not only to private companies but also to government-linked projects across multiple countries.
What Comes Next
U.S. authorities are continuing to pursue those involved. The State Department has offered up to $5 million for information on additional participants tied to similar revenue-generating schemes.
Risks remain elevated. As remote work persists and companies rely on global talent pools, distinguishing legitimate workers from state-backed operatives will remain a challenge. The scale of past breaches suggests enforcement actions alone may not be enough to deter future attempts.