
Newsletter
Six stories and one chart, in your inbox by 6:30 a.m. Eastern. Written by the desk editors, not a machine.
Kim Jong Un’s spy network is exploiting the remote work economy to get its operatives inside American tech companies

Thousands of North Korean operatives are posing as remote IT workers to land jobs at U.S. companies—and a shocking number of them are slipping through the front door.
By leveraging stolen American identities, domestic "laptop farms," and AI-assisted interview tools, Kim Jong Un’s regime is exploiting the work-from-home revolution to infiltrate U.S. businesses. In 2024 alone, this state-directed program funneled nearly $800 million back to Pyongyang, providing a vital financial lifeline for the heavily sanctioned regime’s weapons programs.
Treasury Secretary Scott Bessent warned that these operatives weaponize sensitive corporate data and extort businesses for massive payouts.
The Threat Inside the Firewall
The real danger goes far beyond a fraudulent paycheck. Once hired, these workers gain legitimate logins, internal access, and corporate equipment—opening the door to corporate espionage, data theft, extortion, and destructive cyberattacks.
The Meridian interviewed Michael "Barni" Barnhart, a former Army intelligence specialist and top cybersecurity threat hunter at DTEX who tracks North Korean operatives. Barnhart revealed just how pervasive the threat has become: when he audited 20 Fortune 500 companies, 18 of them had been targeted, applied to, or actively compromised by North Korean IT workers.
Before joining DTEX to focus on nation-state insider threats, Barnhart spent years investigating foreign adversaries in Iraq and later helped build Mandiant’s North Korea threat-hunting unit before its acquisition by Google. His obsession with stopping Pyongyang is permanent—he literally has the names of North Korean hacking groups like APT43 and APT45 tattooed on his feet.
From Elementary School to Elite Hacking
According to Barnhart, North Korea begins scouting its cyber workforce remarkably early:
Early Selection: The regime identifies children as young as seven who show a talent for math and tech, funneling them into specialized state pipelines.
Military Focus: By college, recruits work on defense technology, including drone warfare.
Specialization: The top elite enter nation-state cyber warfare units, while thousands of others are deployed into the lucrative overseas IT workforce.
How the Scam Operates: AI, Intermediaries, and "Laptop Farms"
As U.S. companies get better at spotting suspicious applicants, the regime's tactics are rapidly evolving:
Real-Time AI Fraud: Operatives use generative AI, deepfakes, and live interview-assistance tools to answer technical questions and speak fluent, unaccented English during video calls.
Global Proxy Networks: They route applications through intermediaries in countries like India, Pakistan, and Nigeria, or enter networks via third-party contractors to hide their tracks.
U.S. "Laptop Farms": Because shipping a corporate laptop to North Korea, Russia, or China triggers instant red flags, operatives recruit U.S. residents to receive, host, and connect company laptops to the internet.
These American facilitators—often recruited on Reddit, Discord, Telegram, or Craigslist—are usually cash-strapped individuals lured by promises of easy money. While some are unaware of the full scope, others knowingly participate.



In 2025, Arizona resident Christina Chapman was sentenced to over eight years in prison after running a massive laptop farm out of her home. Chapman helped North Korean workers infiltrate over 300 U.S. companies, including top media networks, aerospace manufacturers, tech giants, and defense contractors.
A Gateway for Nation-State Hackers
What started as a scheme to generate illicit revenue has transformed into a major national security threat.
Barnhart warns that these workers are actively embedded in sensitive sectors, including critical infrastructure and defense. Rather than trying to hack past a company's outer defenses, North Korea is simply tricking American employers into handing over the keys. Once inside, these basic IT workers can open the back door for Pyongyang's most dangerous state-sponsored hackers.
"The pandemic was absolute gasoline on a fire for this scheme," Barnhart told The Meridian. "We can't just rely on law enforcement anymore. Companies must overhaul their internal policies and identity verifications to stop them."