What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

On March 12, 2026, the U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) designated six individuals and two entities for supporting North Korean government-orchestrated IT-worker schemes. Treasury says the schemes use deceptive identities to place workers at legitimate companies, route earnings to North Korea, and, in some cases, steal data or extort employers.

What the March 12 sanctions target

Treasury says the designees supported a network that helps North Korean IT workers obtain jobs while concealing their identities and channeling revenue to the Democratic People’s Republic of Korea (DPRK). The named facilitators were based in the DPRK, Vietnam, Laos, and Spain. Their alleged roles differed:

  • Amnokgang Technology Development Company manages overseas IT-worker delegations, according to Treasury.
  • Nguyen Quang Viet, identified by Treasury as the CEO of a Vietnam-based company, facilitated currency conversion. Treasury says he converted approximately $2.5 million into cryptocurrency for North Koreans between mid-2023 and mid-2025, including illicit earnings associated with Amnokgang.
  • Yun Song Guk led a group of freelance IT workers operating from Boten, Laos. Treasury says he coordinated several dozen financial transactions totaling more than $70,000 related to IT services and worked with a facilitator to develop freelance contracts.
  • Other designees, Treasury says, provided banking, currency, or contract support.

The amounts and conduct above are Treasury’s descriptions in its sanctions announcement; they are not presented here as independently verified findings. Treasury also reported that DPRK IT-worker schemes generated nearly $800 million in 2024 and said the revenue supports weapons programs.

In announcing the action, Treasury Secretary Scott Bessent said: “The North Korean regime targets American companies through deceptive schemes carried out by its overseas IT operatives, who weaponize sensitive data and extort businesses for substantial payments,” Treasury said on March 12, 2026.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the hiring scheme can put employers at risk

Treasury says teams use fraudulent documents, stolen identities, and fabricated personas to secure work with legitimate companies, including U.S. businesses. The DPRK government reportedly takes most of the workers’ wages. Treasury also says some workers have covertly introduced malware into company networks to obtain proprietary or sensitive information.

The FBI’s January 23, 2025 alert describes additional risks after a worker gains access: copying code repositories to personal accounts, potentially harvesting credentials and session cookies, and extorting companies by holding stolen data or code for ransom. A hiring red flag warrants further review; it is not proof that an applicant is a North Korean worker.

What OFAC designation means for U.S. persons

Treasury says the designees’ property and interests in property in the United States, or in the possession or control of U.S. persons, are blocked and must be reported to OFAC. An entity owned 50 percent or more, individually or in the aggregate, by blocked persons is also blocked. Transactions by U.S. persons, or within or transiting the United States, involving blocked property are generally prohibited unless authorized by an OFAC general or specific license or exempt.

Treasury warns that violations may carry civil or criminal penalties. These are general consequences, not a determination about any particular transaction. For a specific situation, consult OFAC’s current North Korea sanctions program information, including applicable regulations, licenses, and sanctions lists; a news article cannot establish whether a particular activity is authorized.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How employers can reduce hiring and security risks

Official guidance combines identity and employment checks with limits on access and monitoring. These measures are indicators and controls, not a method for conclusively identifying a person’s nationality or affiliation.

Verify identity and work history

  • Verify identity during interviews and onboarding, and continue appropriate checks during employment.
  • Confirm employment and education history using contact details obtained independently, rather than relying solely on information supplied by the applicant. The interagency May 16, 2022 advisory from the State Department, Treasury, and FBI also recommends video identity checks and background checks.
  • Review inconsistent names, locations, work histories, or contact details; repeated resume information; reused phone numbers or email addresses; and requests to change payment arrangements. Treat these as prompts for further verification, not proof of wrongdoing.
  • Audit staffing firms and educate HR and technical staff about the risks of identity fraud and deceptive applications.
  • The 2022 advisory recommends avoiding cryptocurrency payments to workers and using caution with remote-collaboration tools on employer-provided computers.

Limit access and watch for suspicious activity

  • Apply least privilege. Restrict local administrator access and the ability to install remote desktop tools unless those privileges are necessary.
  • Monitor unusual network traffic and remote connections. Review network logs and browser sessions for signs of data movement or exfiltration, and check endpoints for suspicious software.
  • Look for indicators such as multiple logins from different countries or unexpected access to repositories and sensitive data. Investigate them in context; no single indicator establishes identity or intent.
  • Report suspected activity to the FBI’s Internet Crime Complaint Center (IC3), as the FBI’s employer guidance recommends.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How this differs from the August 2025 sanctions action

The March 2026 designations are separate from Treasury’s August 27, 2025 action involving Vitaliy Andreyev, Kim Ung Sun, Shenyang Geumpungri Network Technology, and Korea Sinjin Trading Corporation. In that earlier action, Treasury said a network facilitated cryptocurrency-to-cash transfers and that a delegation associated with the Chinese front company had earned over $1 million in profits for related entities since 2021. That figure concerns the earlier action, not the March 2026 designees. See Treasury’s August 27, 2025 announcement.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.