Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes. Google Threat Intelligence Group (GTIG) reported increased suspected North Korean IT worker activity in Europe in an April 2025 assessment. Its examples show how the schemes can cross borders and persist after hiring, but Google did not publish a Europe-wide count of workers, employers, or victims. That distinction matters: the report establishes observed cases and an intelligence assessment of expansion, not the prevalence of the activity across the continent.

What Google reported about Europe

In its April 1, 2025 report, “DPRK IT Workers Expanding in Scope and Scale,” GTIG said that, working with partners, it had identified increased active operations in Europe, confirming an expansion beyond the United States. Google linked the shift to difficulties seeking and maintaining U.S. employment, including greater awareness of the schemes, U.S. Department of Justice indictments, and right-to-work verification challenges. Those are Google’s assessment and proposed drivers, not a quantified measurement of European hiring.

Google described one late-2024 case in which a suspected worker operated at least 12 personas across Europe and the United States. The worker pursued European roles, particularly in defense-industrial-base and government sectors, used fabricated references, and built rapport with recruiters. Other personas controlled by the same operator vouched for the applicant. The figure is a case detail, not a count of workers or victims.

Other examples included personas seeking jobs in Germany and Portugal, credentials for European job and human-capital-management sites, and UK projects involving web development, bot development, content management, blockchain, and AI applications. Google said the personas claimed a range of nationalities, including Italian, Japanese, Malaysian, Singaporean, Ukrainian, U.S., and Vietnamese identities; it described a mixture of real and fabricated personas. These are details of cases Google reported, not characteristics that identify applicants from any of those countries.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Google named Upwork, Telegram, and Freelancer among platforms used in European recruitment and reported payments through cryptocurrency, Wise (called TransferWise in the report), and Payoneer. In a facilitator-related case, a company laptop intended for New York was found operating in London. A platform, payment method, claimed nationality, or location mismatch alone does not establish DPRK involvement.

Google also described European facilitators helping workers obtain jobs, defeat identity verification, and receive funds. Investigative materials included fabricated resumes and instructions for navigating European job sites; one document advised seeking work in Serbia and using a Serbian time zone during communications. These details describe specific materials and activity Google encountered, not a general profile of applicants from Serbia or elsewhere.

What the findings do—and do not—establish

Google’s report supports the conclusion that its investigators observed suspected operations expanding into Europe and described concrete cross-border cases. The reviewed report does not provide a comparable Europe-wide total for affected companies, workers, or hires. The scale of activity across Europe therefore remains unquantified in these findings; the 12-persona example should not be read as a prevalence statistic.

At a broader government level, a multilateral statement published by Global Affairs Canada on July 31, 2026, says North Korean IT workers use false identities and online employment, procurement, and service-contracting platforms. Issued by participating governments and agencies including Australia, France, Germany, Canada, Italy, Japan, the Netherlands, New Zealand, the Republic of Korea, the United Kingdom, and the United States, it warns of insider threats such as data exfiltration, cryptocurrency theft, and theft of sensitive information. It says income is intended to be remitted to North Korean agencies and used to fund unlawful nuclear-weapons and ballistic-missile programs. The statement adds: “North Korean IT workers employ increasingly sophisticated methods, including the integration of AI, to obfuscate their identities and expand their activities globally.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The same statement says UN Security Council Resolution 2397 requires member states to repatriate North Korean nationals earning income in their jurisdiction, subject to limited exceptions. It warns that contracting and paying North Korean IT workers may violate domestic law in some countries, including Japan, the United States, and the Republic of Korea, and may bring legal consequences or financial penalties. That is not a universal legal conclusion: laws and facts differ by jurisdiction, so organizations should consult current official guidance and qualified counsel. Global Affairs Canada’s July 2026 statement provides the participating governments’ warning.

Why the risk can continue after hiring

Hiring is not the only point of exposure. GTIG assessed that extortion attempts had increased since late October 2024 and were targeting larger organizations. It described recently fired workers threatening to release sensitive company data or give it to competitors, including proprietary information and source code. Google suggested that increased law-enforcement pressure might be related to the more aggressive tactics, but presented that connection as a possibility rather than a proven cause.

The FBI’s January 23, 2025 alert says it had observed workers using unlawful network access to exfiltrate proprietary and sensitive data, facilitate cybercrime, and generate revenue. It describes stolen source code being held for ransom or released publicly, as well as company code repositories copied to personal profiles or cloud accounts. The FBI alert recommends least privilege and monitoring network logs, remote access, and browser sessions for unusual activity or exfiltration through shared drives, cloud accounts, and private repositories.

How BYOD and virtual desktops affect visibility

Bring-your-own-device (BYOD) policies and virtual desktop access can leave employers with less evidence about a worker’s device and location. GTIG said personal devices may lack the monitoring and logging tools found on corporate laptops. In these arrangements, employers may also lack evidence such as laptop shipping addresses and endpoint software inventories. Google said it believed workers had identified BYOD environments as promising and had observed operations against employers using such setups in January 2025.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The FBI’s January 2025 guidance recommends limiting privileges to install remote desktop applications, monitoring remote connections and unusual simultaneous logins, and reviewing endpoint and browser activity. These measures are relevant when work runs through virtual environments, but they do not replace identity checks or establish who is behind an account.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How companies can reduce hiring and access risks

The FBI’s July 23, 2025 business alert treats verification as an ongoing process rather than a single interview check. Its recommendations are controls for reducing risk, not proof that any one signal reveals a person’s nationality or intent.

Verify identity and work history directly

  • Scrutinize identity documents and compare photos and contact details with social profiles, portfolio sites, and payment-platform details.
  • Verify claimed employment and education directly with the institutions concerned; check for duplicate resumes or contact details.
  • Use in-person meetings when practical. For video interviews, request an unobscured background and compare location details with the candidate’s claims.
  • Capture interview images for comparison in later meetings, since the person interviewed may differ from the person who performs the work.
  • Continue identity verification during onboarding and employment, not only during recruitment.

Check equipment, payments, and staffing arrangements

  • Compare payment-account details with the applicant’s identity and investigate frequent account changes.
  • Verify that equipment is being sent to the address on the identity document.
  • Complete background checks before granting system access.
  • Educate and audit third-party staffing firms. The FBI warns that outsourcing can add vulnerability when the hiring company is less directly involved in recruitment and onboarding.

Limit access and watch for data movement

  • Apply least privilege so workers can access only the systems and data their roles require.
  • Investigate unusual network traffic, remote access software, remote connections, and simultaneous logins that do not fit expected work patterns.
  • Review network logs, endpoint activity, and browser sessions for transfers to shared drives, personal cloud accounts, or private repositories.
  • Restrict who can install remote desktop applications, especially in BYOD or virtual desktop arrangements where endpoint visibility may be limited.

Respond to suspected activity

The FBI’s January 2025 alert advises organizations that suspect a scheme to evaluate network activity from the worker and assigned devices and report it to the FBI’s Internet Crime Complaint Center. Preserve relevant hiring and access records and follow applicable incident-response and legal procedures.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.