Journal logo

The North Korean Infiltrator in the Federal Workforce: FBI Investigates a Breach of Unprecedented Scale

A routine IT contract spiraled into a national security nightmare when the FBI discovered a North Korean operative had been working remotely for an unidentified U.S. federal agency. The case reveals a sprawling, state-sponsored campaign to infiltrate the American government from the inside out.

By Mark Lim Published 2 months ago • 6 min read

The Federal Bureau of Investigation (FBI) is currently investigating a chilling national security breach: a North Korean information technology (IT) worker successfully obtained employment with an unidentified U.S. federal government agency. The revelation, which came to light during a July 28, 2026, conference in Washington, D.C., has sent shockwaves through the intelligence and cybersecurity communities, exposing a vulnerability in federal hiring and vetting processes that many experts feared existed but had never seen confirmed.

The case marks a rare and alarming instance of a sanctioned North Korean national penetrating the federal government's digital defenses, not through a firewall, but through the front door with a badge and a paycheck.


The FBI's Discovery

The investigation was first reported by Federal News Network, citing Todd Hemmen, the deputy assistant director of the FBI's Cyber Capabilities Branch. Speaking at a forum hosted by the Digital Government Institute, Hemmen revealed that the FBI had identified a North Korean remote IT worker employed by the federal government .

"Without getting into ongoing investigations, we identified just this past week a DPRK remote IT worker that was working for the federal government," Hemmen said during the panel. He described the case as "baffling" due to the apparent gaps in the agency's hiring process, noting, "Still kind of unpacking that recent case. It's actually a little bit baffling to me, not understanding this particular agency's process".

Hemmen confirmed that while the vast majority of North Korean IT infiltrations occur in the private sector, the government is not immune. "The short answer is yes, we are seeing remote IT workers not just in the private sector, although a vastly higher proportion are in the private sector, but we're also seeing this impact the government to a degree," he added .

The FBI has declined to provide further details, leaving critical questions unanswered: Which federal agency was compromised? How long was the operative employed? And most importantly, was any sensitive data or intellectual property stolen ?


The North Korean IT Worker Scheme: A State-Sponsored Enterprise

North Korea has for years used skilled IT workers to obtain jobs overseas through false identities and other deceptive methods. The regime's goal is twofold: to generate hard currency to fund its nuclear and weapons of mass destruction programs, and to gain access to sensitive systems and information for espionage purposes .

The U.S. Department of Justice has described North Korea's IT worker scheme as a "years-long plot" designed to "trick U.S. companies into funding the North Korean regime's priorities, including its weapons programs" . The DPRK has dispatched thousands of skilled IT workers to live abroad, primarily in China and Russia, with the aim of deceiving U.S. and other businesses worldwide into hiring them as freelance IT workers .

This is not a small-scale operation. Research published in March 2026 revealed that North Korea stole more than 100,000 identities to infiltrate global companies . In one operation alone, prosecuted by the DOJ, operatives infiltrated more than 300 U.S. organizations, including government agencies, using the stolen identities of 68 Americans. Prosecutors called it the largest identity theft case of its kind.


The FBI Official's Bafflement

Hemmen's public remarks suggest that the FBI is struggling to understand how such a breach could occur. "It's actually a little bit baffling to me, not understanding this particular agency's process," he told the forum .

Experts who reviewed Hemmen's comments noted that the case likely involves a remote IT contractor rather than a direct federal employee, given the extensive background checks required for full federal positions. Donald Blersch, a former senior government official who now advises risk assessment firm Clearspeed, said such incidents point to gaps in support roles that don't undergo the same vetting as other federal employees and contractors .

"If you're a contractor supporting a company, even if you're nowhere near the government contract itself, you may still have access to corporate networks, systems, and information that can ultimately provide a pathway into government environments," Blersch explained .


A Precedent for Infiltration

While the current case is alarming, it is not without precedent. In 2024, the Justice Department brought charges against a Maryland man who assisted a North Korean hacker to pose as an American to get a remote job as a contractor for the Federal Aviation Administration . The man was sentenced to 15 months in prison for allowing a North Korean national in China to work on software development contracts for the FAA.

In that case, the Justice Department said the scheme involved at least 13 U.S. companies, several of which contracted the man's services to U.S. government agencies, leading to access to "sensitive U.S. government systems" from China .


The Infiltration Playbook

North Korean operatives have developed an increasingly sophisticated playbook for infiltrating Western companies and government agencies. According to security researchers, the DPRK is running an industrial-scale insider threat operation known as "Jasper Sleet" (tracked by Microsoft) . Operatives are using AI-generated identities, voice spoofing, and laptop farms to infiltrate Western companies as remote developers .

The scale of the operation is staggering. In one uncovered network, 22 North Korean agents submitted over 166,000 job applications, landing more than 21,000 interviews and 76 job offers using stolen identities and AI tools . Another operation involved North Korean agents submitting an average of 7,586 applications each to secure employment .

Major U.S. tech companies like Amazon and Google have been struggling with disguised employment attempts by North Korean IT personnel aiming to infiltrate their AI technologies . Amazon has prevented more than 1,800 suspected North Korean operatives from securing employment since April 2024.


The Threat to Government

A former FBI official, speaking on condition of anonymity, told Federal News Network that the infiltration of government agencies is a natural progression of North Korea's campaign. "It's a natural progression that they would try to get placement into government locations," the official said . "It is hard to say whether the alleged DPRK IT worker discovered working inside the federal government was the result of direct targeting or a target of opportunity. Either way, if true, it demonstrates capability and intent to gain access into the federal government" .

The consequences of such infiltration could be catastrophic. Beyond the immediate risk of data theft, North Korean operatives could use their access to compromise supply chains, implant backdoors in critical systems, or launch ransomware attacks against government infrastructure.


The Scale of the Problem

The scope of North Korea's IT worker campaign is staggering. According to the Justice Department, the DPRK has dispatched thousands of skilled IT workers to live abroad, earning up to $300,000 annually each, generating hundreds of millions of dollars collectively each year.

In one case, a New Jersey man pleaded guilty to participating in a scheme that generated revenue for North Korean weapons programs . The scheme involved the dispatch of skilled IT workers who, using stolen identities of U.S. persons, posed as domestic workers to obtain remote IT jobs with U.S. companies, including several Fortune 500 companies and a defense contractor . The IT workers gained access to sensitive employer data and source code, including International Traffic in Arms Regulations (ITAR) data from a California-based defense contractor that develops AI-powered equipment and technologies.


A Criminal Enterprise, Not a Nation

North Korea operates more like a transnational criminal gang than a government, relying on cybercrime to fund its globally sanctioned nuclear weapons program . The Kim Jong Un regime is reportedly responsible for 76% of cryptocurrency thefts, netting the regime at least $2 billion during 2025 alone .

The IT worker scheme is just one component of a broader cyber-enabled sanctions evasion strategy that includes crypto theft, ransomware, and the development of "laptop farms"—networks of computers in the United States that allow North Korean operatives to work remotely as if they were physically present in the country .


The U.S. Response

The U.S. government has taken several enforcement actions and sanctions to combat North Korean IT worker schemes. In June 2025, the Justice Department announced coordinated actions against DPRK schemes to fund its regime through remote IT work . In January 2025, two North Korean nationals and three facilitators were indicted for a multi-year fraudulent scheme .

Late last month, South Korea, the U.S., Japan, and eight other countries issued a joint alert about North Korean IT workers, warning that they pose an insider threat to companies and are involved in data exfiltration, cryptocurrency theft, and the theft of sensitive information . The discovery of a North Korean IT worker inside a federal agency is a wake-up call. It reveals that North Korea's infiltration campaign is not limited to the private sector and that the U.S. government's vetting processes are not as secure as previously believed.

As the FBI continues its investigation, the incident raises uncomfortable questions: How many other North Korean operatives are currently working for the U.S. government? What data have they accessed? And what can be done to prevent future breaches?

For now, the FBI is "still kind of unpacking that recent case." But one thing is clear: the North Korean IT worker scheme has crossed a critical threshold, and the U.S. government is now a target.


politics

About the Creator

Mark Lim

Hi I am mark an automotive student and a car, tech and food enthusiast ! Im gonna try and post daily & hope you enjoy what I write and do share my page with people you know. I would gladly appreciate it! Cheers

Enjoyed the story? Support the Creator.

Subscribe for free to receive all their stories in your feed.

Subscribe For Free

Reader insights

Comments

There are no comments for this story

Be the first to respond and start the conversation.

Sign in to comment
    Written by Mark Lim