Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

If you suspect a North Korean IT worker has obtained a job at your company, treat the discovery as both an identity-fraud investigation and a potential cybersecurity incident. Escalate to security or incident response, legal, HR, and executive owners; validate what happened before making public accusations; and report suspected activity through the FBI’s channels. A suspected identity does not, by itself, establish what the worker accessed or whether the company violated sanctions law.

This guide focuses on U.S. businesses, reflecting the scope of the cited FBI, Treasury, State Department, and OFAC guidance. The FBI warns that suspected North Korean IT workers may misuse access to company networks and, in some cases, extort victims by holding stolen proprietary data or code hostage. Follow your organization’s incident-response procedures and counsel’s advice: the official materials identify risks and reporting routes, but do not prescribe one universal response or decide liability in an individual case.

What should the company do first?

Coordinate the response before confronting the worker or making external claims about their identity. Assign owners for the security investigation, employment review, legal analysis, and communications, and keep decisions aligned through the organization’s incident-response process.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Escalate internally. Notify the incident-response or security lead, legal counsel, HR, and the relevant executive owners. Limit sensitive case details to people who need them while the facts are being checked.
  2. Control access and preserve records. Use established company procedures and counsel’s guidance to manage the worker’s access and preserve relevant records. Avoid ad hoc actions that could destroy evidence or disrupt the investigation; the appropriate steps depend on the systems and circumstances involved.
  3. Assess activity, not just identity. Review the suspected worker’s network activity and assigned devices for possible unauthorized remote access, unusual data access or transfer, and signs that proprietary information or code may have been taken or used as leverage.
  4. Report suspected activity promptly. The FBI’s January 23, 2025 public service announcement recommends reporting suspected activity to the Internet Crime Complaint Center (IC3) as quickly as possible. The FBI’s July 23, 2025 announcement also lists a local FBI field office, IC3, and the FBI tip line, 1-800-CALL-FBI (225-5324), as reporting options.
  5. Review financial activity with specialists. Have counsel and sanctions or compliance specialists assess relevant payments and counterparties against current requirements. Do not infer a legal conclusion from discovery alone.

The FBI’s January 2025 announcement specifically recommends evaluating activity from the suspected employee and assigned devices, including using internal intrusion-detection software to capture activity on the suspected device. It does not require a particular commercial tool. Follow your organization’s technical and evidence-handling procedures when carrying out that assessment.

How should you handle a report to the FBI?

Choose a reporting route that fits the situation and coordinate with counsel or your incident-response lead. The FBI’s July 23, 2025 announcement identifies three routes for suspected activity: a local FBI field office, IC3, or the FBI tip line at 1-800-CALL-FBI (225-5324). For suspected data extortion, the FBI’s January 23, 2025 announcement emphasizes reporting to IC3 as quickly as possible.

If the FBI has already notified your company that it may be a victim, the FBI’s July 1, 2025 notice, “Seeking Victim Information in North Korean Remote IT Worker Investigation,” points to a specific IC3 form for requesting identified information related to potentially fraudulent employees. Use that route when it applies rather than treating it as a general public reporting channel.

What should the investigation establish?

Separate verified facts from suspicion. An identity concern is not proof of a network intrusion, and a suspicious login or data transfer does not by itself establish who was responsible. Build the review around the questions relevant to your company’s systems, employment relationship, and potential exposure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Identity and hiring: What information appears inconsistent, and what can be independently verified about identity, location, work history, and the hiring or staffing channel?
  • Access and devices: Which accounts, systems, and assigned devices were available to the worker, and what activity is relevant to the period under review?
  • Data and extortion: Is there evidence of unusual access, transfer, or retention of company data or code? Has anyone threatened to disclose, damage, or withhold information?
  • Third parties and payments: Did a staffing firm, contractor, payment intermediary, or other counterparty play a role? What payments or transactions need review by counsel and compliance specialists?

The FBI’s January 2025 announcement describes cases involving data theft and extortion after discovery. Treat those as risks to investigate, not as facts established in every case.

What does this mean for sanctions or legal exposure?

U.S. authorities warn that people and entities engaged in or supporting DPRK IT worker-related activity, including related financial transactions, may face reputational risks and potential legal consequences, including sanctions designation. The May 16, 2022 joint guidance from the State Department, Treasury, and FBI sets out that warning, and later Treasury sanctions actions show continued enforcement.

That warning is not a finding that every company deceived by a fraudulent worker violated sanctions. Exposure depends on the specific facts, including knowledge, conduct, transactions, jurisdiction, and current law. Ask counsel and sanctions specialists to assess the company’s circumstances and check OFAC’s current North Korea Sanctions program page for applicable materials.

In a 2025 sanctions announcement, the U.S. Treasury Department reported that DPRK IT worker schemes generated nearly $800 million in 2024. This is Treasury’s reported figure in that announcement, not an independently audited total presented here.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How can the company reduce the chance of another fraudulent hire?

The FBI’s recommendations span initial screening, onboarding, remote employment, and third-party staffing. Use multiple checks together; no single inconsistency is proof of a person’s identity or affiliation.

  • Verify identity throughout employment. The FBI’s January 2025 announcement recommends identity verification during interviewing and onboarding, and throughout remote employment.
  • Complete background checks before access. The FBI’s July 23, 2025 announcement states: “Additionally, do not grant access to any systems until the background check is completed.” Apply this pre-access rule to the relevant hiring process.
  • Check for inconsistencies. The FBI recommends checking whether communication accounts are reused across resumes, asking questions about location or education, and reviewing resumes for typos or unusual nomenclature. Treat these as prompts for verification, not conclusive indicators.
  • Verify staffing channels. The FBI identifies contracted IT work as a common employment route and recommends verifying and auditing staffing firms. Educate third-party firms about the FBI’s guidance and set clear verification expectations.
  • Confirm unusual delivery requests. If an employee asks for a device to be delivered somewhere other than the address on their identification documents, the FBI recommends verifying the alternate address with additional documentation.
  • Use in-person steps where practical. The FBI’s January 2025 announcement recommends doing as much of the hiring and onboarding process in person as possible.

When should you bring in outside incident-response support?

The official guidance identifies investigative needs but does not rank vendors or require a particular service. Consider outside support if the suspected activity involves systems your team cannot assess, potential theft of sensitive data or code, extortion, multiple jurisdictions, or a need for specialized evidence analysis. Choose support based on the scope of the investigation, relevant incident-response experience, ability to preserve and analyze evidence, geographic and regulatory coverage, and availability. Have counsel help determine how external work should be coordinated with the company’s legal response.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.