The $17 Million Fake Remote Worker Scam Run By North Korea, Uncovered By A London Startup Founder
On paper, Thomas checked every box a hiring manager could want. A self-identified native of rural Tennessee with a computer science degree from the University of Missouri, he claimed eight years of professional programming experience and aced his preliminary coding screening without breaking a sweat. For his would-be boss Simon Wijckmans, founder of London-based web security startup C.Side, it looked like a dream find: Wijckmans, a 27-year-old Belgian, was actively hunting for driven, fully remote software engineers to join his team.
Thomas carried an Anglo-Saxon last name, so Wijckmans was caught off guard when he joined the Google Meet call and was greeted by a young man of Asian descent with a thick, non-native accent. Thomas used a generic stock office background, his internet connection was frustratingly laggy—an odd red flag for a seasoned professional coder—and the line was constantly humming with background noise. To Wijckmans, it sounded like Thomas was calling from a large, crowded space: a dorm room, or worse, a busy call center.
Wijckmans walked through his standard interview questions, and Thomas’ responses were solid enough. But one odd detail stuck out: Thomas only seemed focused on one topic—his starting salary. He asked nothing about the actual work, how the company operated, or even common benefits like startup equity or health insurance. That struck Wijckmans as strange. When the call ended, he moved on to the next candidate in his queue, none the wiser that he’d just stumbled onto something far bigger than a single bad applicant.
The second applicant followed the exact same script. He claimed to be based in the U.S., had an Anglo last name, and turned out to be a young Asian man with a thick, non-American accent. He used a basic virtual background, had a spotty internet connection, and fixated on salary from the start of the call. This candidate, though, wore glasses. Glancing at the reflection on the lenses, Wijckmans spotted multiple screens behind him, and could just make out a white chatbox with messages scrolling up the screen. “He was clearly either talking to someone else the whole time or using an AI tool to answer for him,” Wijckmans recalls.
On high alert, Wijckmans took screenshots and jotted down notes. After the call, he dug into his company’s applicant pool and made a troubling discovery: his job postings were being flooded with hundreds of identical suspicious candidates. One full-stack developer opening got more than 500 applications in a single day, far above the normal volume. When he looked deeper, he found that dozens of applicants had used a virtual private network (VPN) to mask their true location when taking the coding test.
Wijckmans had no idea at the time, but he’d just brushed up against a brazen, global cybercrime operation run by the North Korean government: a sprawling network of fake IT workers that use stolen identities to land fully remote jobs at Western companies, funneling millions of dollars in illicit revenue back to Pyongyang. All they needed was a local helper on the ground to cover their tracks. That’s where Christina Chapman came in.
In 2020, Chapman was living in a trailer in Brook Park, Minnesota, a small town north of Minneapolis, when a recruiter’s message changed everything. A bubbly 44-year-old with curly red hair and glasses, Chapman loved her dogs, her mom, posting social justice content on TikTok, K-pop, Renaissance fairs, and cosplay. Her sparse online resume noted she was learning to code remotely, making her an easy target for the outreach.
It was March 2020 when she opened the message on her LinkedIn account: a foreign firm was looking for someone to act as the “U.S. face” for their business, helping overseas workers secure remote jobs with Western companies. Chapman signed on. It’s unclear how quickly her workload grew, but by October 2022, she earned enough to leave cold Minnesota behind and buy a modest four-bedroom single-story house in Litchfield Park, Arizona. It wasn’t luxurious: a suburban corner lot with a handful of thin young trees, but it was a massive step up from her old trailer.
Chapman started sharing more of her daily life on TikTok and YouTube, mostly talking about diet, fitness, and mental health. In one chatty 2023 video, she described grabbing a quick breakfast of an açaí bowl and smoothie on her way out, explaining she was swamped with work. “My clients are going crazy!” she complained. In the background of the shot, the camera caught a glimpse of metal racks holding at least a dozen open laptops, each covered in sticky notes. A few months later, federal agents raided her home, seized the laptops, and filed charges alleging she’d spent three years helping the North Korean government generate illicit revenue.
For roughly a decade, North Korean intelligence has trained young IT workers and deployed them in teams abroad, most often to China or Russia. From these bases, they scan job boards for open software engineering roles at American and European companies, prioritizing fully remote positions with solid pay, broad access to company systems, and minimal oversight. Over time, they’ve refined their scheme: they apply using stolen or fabricated identities, get criminal teammates to write fake references, and now even use AI to pass coding tests, video interviews, and background checks.
But if a fake worker lands a job offer, the ring needs a local person in the country the applicant claims to live in. A fake employee can’t use a U.S. address or bank account tied to their stolen identity, and logging into company networks from overseas would immediately trigger fraud alerts. That’s the role Chapman filled.
As a facilitator for hundreds of North Korea-linked jobs, Chapman signed fraudulent employment documents and handled the fake workers’ paychecks. She would deposit full salary checks into her own bank accounts, take a cut for herself, then wire the remaining money overseas. Federal prosecutors say Chapman was promised up to 30% of all funds that passed through her accounts.
Her most critical job, though, was running what investigators call a “laptop farm.” After a fake worker is hired, they typically ask the company to ship their work computer to a different address than the one listed on their application, spinning a story about a last-minute move or needing to stay with a sick relative. That new address belongs to the facilitator— in this case, Chapman. Sometimes facilitators ship the laptops on to the North Korean operatives overseas, but more often they keep the devices, install remote access software that lets the North Korean workers control the laptop from anywhere in the world, while making it appear the device is active in the U.S. (“You know how to install Anydesk?” one North Korean operative asked Chapman in 2022. “I do it practically EVERYDAY!” she replied.)
In text messages with her handlers, Chapman discussed everything from faking signatures on U.S. employment forms like the I-9, which verifies a worker’s eligibility to work in the U.S. A 2023 exchange, cited in court documents, shows how she even stepped in for last-minute work tasks:
Worker: We are going to have laptop setup meeting in 20 mins. Can you join Teams meeting and follow what IT guy say? Because it will require to restart laptop multiple times and I can not handle that. You can mute and just follow what they say ...
Chapman: Who do I say I am?
Worker: You don’t have to say, I will be joining there too.
Chapman: I just typed in the name Daniel. If they ask WHY you are using two devices, just say the microphone on your laptop doesn’t work right ... Most IT people are fine with that explanation.
Chapman grew nervous as the scheme grew. “I hope you guys can find other people to do your physical I9s,” she wrote to her handlers in 2023, per court documents. “I will SEND them for you, but have someone else do the paperwork. I can go to FEDERAL PRISON for falsifying federal documents.”
Michael Barnhart, an investigator at cybersecurity firm DTEX and a leading expert on North Korean IT worker fraud, says Chapman’s involvement fits the standard playbook: it starts with innocent outreach on LinkedIn, then requests slowly escalate. “Little by little, the asks get bigger and bigger,” he says. “Then by the end of the day, you’re asking the facilitator to go to a government facility to pick up an actual government ID.”
By the time agents raided Chapman’s home, she was holding dozens of laptops, each marked with a sticky note listing the fake worker’s identity and their employer. Some North Korean operatives held multiple jobs at once, and some had been working quietly under their fake identities for years. Prosecutors say at least 300 U.S. employers were caught up in Chapman’s single scheme, including “a top-five national television network and media company, a premier Silicon Valley technology company, an aerospace and defense manufacturer, an iconic American car manufacturer, a high-end retail store, and one of the most recognizable media and entertainment companies in the world.” Chapman helped funnel at least $17 million back to North Korea, prosecutors allege. She pleaded guilty in February 2025 to charges of wire fraud, identity theft, and money laundering, and is awaiting sentencing.
Chapman’s case is far from unique. A string of similar North Korean fake-worker prosecutions are moving through U.S. courts right now:
A Ukrainian man named Oleksandr Didenko is accused of building a freelancing platform to match fake IT workers with stolen identities to open jobs. Prosecutors say at least one of his workers was tied to Chapman’s laptop farm, and Didenko has links to other operations in San Diego and Virginia. He was arrested in Poland last year and extradited to the U.S.
In Tennessee, 38-year-old Matthew Knoot is set to stand trial for allegedly running his own laptop farm in Nashville that sent hundreds of thousands of dollars to North Korean-linked accounts (he has pleaded not guilty).
In January 2025, Florida prosecutors charged two U.S. citizens, Erick Ntekereze Prince and Emanuel Ashtor, a Mexican accomplice, and two North Korean men with running a similar scheme. Court documents allege Prince and Ashtor ran a network of fake staffing companies for six years that placed North Korean workers at at least 64 U.S. businesses.
None of the defense attorneys for the defendants in these cases responded to requests for comment.
Before North Korea built its global network of laptop farms and fake workers, it had just one confirmed connection to the global internet, as far as outside observers could tell. As recently as 2010, that single connection was reserved exclusively for top government officials. Then in 2011, 27-year-old Kim Jong Un took power after his father’s death. Secretly educated in Switzerland and reportedly an avid video gamer, Kim made IT development a national priority. In 2012, he urged North Korean schools to “pay special attention to intensifying their computer education” to open new opportunities for the government and military. Today, computer science is part of many high school curricula, and college students can take advanced courses in information security, robotics, and engineering.
The most talented students are taught hacking techniques and foreign languages to turn them into effective operatives. Recruiters from North Korea’s top intelligence agency, the Reconnaissance General Bureau, target the highest-performing graduates from elite schools like Kim Chaek University of Technology (often called “North Korea’s MIT”) and Pyongsong’s prestigious University of Sciences. Recruits are promised good pay and unlimited access to the real global internet— not the restricted domestic intranet available to most wealthy North Koreans, which only hosts a small number of heavily censored local websites.
North Korea’s early cyber operations were relatively simple: defacing enemy websites with political messages, or launching denial-of-service attacks to take down U.S. government and corporate sites. They quickly grew bolder. In 2014, North Korean hackers stole and leaked confidential internal data from Sony Pictures in a high-profile attack. Next they targeted financial institutions: fraudulent trades stole more than $81 million from the Bank of Bangladesh’s accounts at the New York Federal Reserve. After that, they moved into ransomware: the 2017 WannaCry attack locked hundreds of thousands of Windows computers across 150 countries and demanded ransom payments in bitcoin. While the total ransom revenue from WannaCry is disputed— one estimate says the attackers only collected around $140,000 in payouts— the attack caused billions in indirect damage as companies scrambled to upgrade their systems, with total costs reaching an estimated $4 billion.
After Western governments responded with harsh new sanctions and upgraded cyber defenses, the North Korean regime shifted strategies, pulling back on high-profile ransomware attacks in favor of quieter, more consistent illicit revenue streams. Today, North Korea’s most profitable cyber criminal activity is cryptocurrency theft: in 2022, hackers stole more than $600 million worth of ether from blockchain game Axie Infinity, and in early 2025 they stole $1.5 billion worth of digital currency from Dubai-based crypto exchange Bybit. But the fake remote worker scam, which grew slowly for years, exploded after the COVID-19 pandemic made fully remote work the norm for millions of Western companies, giving Pyongyang a perfect low-risk opportunity to scale the scheme.
South Korea’s National Intelligence Service reported in 2024 that North Korea now has 8,400 people working in its cyber divisions, which include fake remote workers, crypto thieves, and military hackers— up from 6,800 just two years earlier. Some operatives are based inside North Korea, but many are stationed abroad in China, Russia, Pakistan, and other countries. While they earn more than the average North Korean citizen, their living and working conditions are harsh.
Teams of 10 to 20 young men live and work in a single apartment, with four or five sharing a bedroom, and work up to 14 hours a day on shifted schedules to align with their U.S. or European employer’s time zone. They have strict quotas for illicit revenue they have to meet each quarter. Their movements are tightly controlled, and their relatives back in North Korea are effectively held hostage to prevent them from defecting. “You don’t have any freedom,” says Hyun-Seung Lee, a North Korean defector based in Washington, D.C., who says several of his former friends took part in these operations. “You’re not allowed to leave the apartment unless you need to purchase something, like grocery shopping, and that is arranged by the team leader. Two or three people must go together so there’s no opportunity for them to escape.”
The U.S. government estimates that a single team of fake remote workers can earn up to $3 million a year for Pyongyang. Experts say the revenue goes to everything from Kim Jong Un’s personal slush fund to the country’s nuclear weapons program. While $3 million a year sounds small compared to nine-figure crypto heists, the scam works because it’s mundane: hundreds of small, hidden teams flying under the radar of company security teams.
In summer 2022, a large multinational company hired a remote engineer to work on website development. “He would dial in to meetings, he would participate in discussions,” a company executive told me on condition of anonymity. “His manager said he was considered the most productive member of the team.”
One day, the engineer’s coworkers organized a surprise birthday celebration over video call. When they all wished him a happy birthday, he was confused: “But it’s not my birthday,” he replied. After working at the company for nearly a year, the fake worker had forgotten the fake birth date listed on his application. The exchange sparked an internal investigation, and the security team quickly found he was running remote access software on his work laptop, and fired him. It wasn’t until later, when federal investigators found one of his pay stubs at Chapman’s Arizona laptop farm, that the company realized they had employed a North Korean agent for almost a year.
For most fake workers, the primary goal is just to collect a steady salary to send back to Pyongyang, not to steal data or launch an immediate attack. “We’ve seen long-tail operations where they were going 10, 12, 18 months working in some of these organizations,” says Adam Meyers, senior vice president for counter adversary operations at security firm CrowdStrike. But sometimes operatives only stay a few days: long enough to download massive troves of company data or plant malware in the company’s systems before quitting abruptly. That malware can alter financial records, compromise security systems, and lay dormant for months or even years before being activated.
“The potential risk from even one minute of unauthorized access to company systems is almost unlimited for an individual business,” says Declan Cummings, head of engineering at software firm Cinder. Experts warn that these scams are growing not just in the U.S., but across Germany, France, the U.K., Japan, and other developed economies. They urge companies to add rigorous vetting steps: speaking directly to candidate references, flagging sudden address changes, using trusted third-party screening tools, and requiring in-person ID verification or a live unscripted interview.
But none of these measures are foolproof, and new AI tools are making it easier than ever for scammers to evade detection. Tools like ChatGPT let almost anyone answer complex technical questions in real time with unearned confidence, and AI’s advanced coding abilities have rendered many standard pre-employment coding tests useless. AI deepfakes and video filters add another layer of deception.
For example, many HR teams now ask new hires to hold their ID up to the camera during onboarding to verify their identity. “But the fraudsters have a neat trick there,” says Donal Greene, a biometrics expert at online background check provider Certn. They use a green card cut to the exact size and shape of a government ID, essentially a mini green screen, and use deepfake technology to project a copy of the stolen ID onto the card. “They can actually move it and show the reflection,” says Greene. “It’s very sophisticated.” North Korean operatives have even been known to send look-alike stand-ins to pick up physical ID cards from government offices or take pre-employment drug tests.
Even cybersecurity experts can be fooled. In July 2024, Florida-based security training firm KnowBe4 discovered that a new hire going by “Kyle” was actually a North Korean agent. “He interviewed great,” says Brian Jack, KnowBe4’s chief information security officer. “He was on camera, his résumé was right, his background check cleared, his ID cleared verification. We didn’t have any reason to suspect this wasn’t a valid candidate.” The company only caught on when his U.S.-based facilitator tried to install malware on Kyle’s work laptop, triggering the company’s security tools.
Back in London, Wijckmans couldn’t shake the thought that scammers had tried to infiltrate his company. After reading about the KnowBe4 breach, his suspicions deepened. He ran
