North Korea is hiring foreign workers to get past US company job interviews, then swapping them for North Korean operatives once the contracts are signed, according to a new report. The tactic is part of a broader push by the DPRK to fund its weapons programs through hacking and data theft.
The report, published Friday by NBC, describes a scheme where workers from Iran and Lebanon apply for IT jobs in the United States. These workers pass the interviews, take the positions, and then hand their salaries back to North Korean agencies. Once the contracts are in place, North Korean operatives move in to steal data, cryptocurrency, and sensitive information.
The Alert That Described the Scheme
The US government and several foreign agencies issued an alert in July warning about North Korean IT workers. The alert said these workers “seek out contracts with the intent of remitting their salaries to their parent North Korean agencies. They also pose an insider threat to companies and are involved in data exfiltration, cryptocurrency theft, and theft of sensitive information.”
The alert detailed the threat. The workers steal from within while they work, and they send their paychecks back to the DPRK. The report said the DPRK has turned to these third-country workers as US and other governments have moved to counter its earlier efforts.
How the Workers Were Recruited
NBC reported that foreign IT workers had been scouted on LinkedIn. Some were offered $500 monthly in cryptocurrency to work part-time as “interview associates.” The job title suggests a role designed to help the worker pass the interview process.
The report does not specify which companies were targeted or which industries were affected. It focuses on the recruitment method and the pattern of behavior rather than individual cases.
A Growing Problem
The DPRK’s tactics appear to be meeting with some success. In May, Cointelegraph reported that North Korean state-affiliated hackers and threat actors were responsible for more than $2 billion in crypto losses in 2025, a 51% year-on-year increase. That figure comes from cybersecurity company CrowdStrike.
The scale of the problem is notable. More than $2 billion in losses in a single year represents a significant expansion of the DPRK’s hacking operations.
The Economic Payoff
The Bank of Korea estimates that North Korea’s GDP increased 3.5% in 2025 despite global sanctions. The growth figure shows that the DPRK’s illicit financial activities are helping sustain its economy even under pressure.
The combination of data theft, cryptocurrency heists, and stolen salary payments feeds directly into that economic picture. Money taken from US companies becomes revenue for the DPRK’s weapons programs.
What Companies Should Watch For
The report highlights a specific warning sign: workers who apply for jobs but then send their salaries back to their home country. That behavior fits the profile of the third-country workers described in the alert.
Companies should also watch for employees who suddenly start handling sensitive data or cryptocurrency in ways that seem unusual. The alert describes these workers as posing an “insider threat,” meaning they can access information from the inside once they are hired.
The Pattern in Practice
The report describes a two-step process:
- A foreign worker applies for a job and passes the interview.
- Once hired, the worker sends their salary back to a North Korean agency.
- Later, a North Korean operative takes over the position.
The report does not specify how long the transition takes or whether the foreign worker stays on site during the changeover. Those details are not provided in the available information.
Comparing the Tactics
| Tactic | Known Detail |
|---|---|
| Third-country workers | Salaries remitted to North Korean agencies |
| State-affiliated hackers | $2 billion in losses in 2025 |
| Insider threat | Data exfiltration, theft of sensitive information |
The table shows that the DPRK is attacking from multiple angles. One group steals money directly from crypto exchanges, while another steals data from inside corporate networks.
What This Means for US Security
The report paints a picture of a sophisticated adversary adapting to pressure. As US and other governments have tightened their defenses against direct DPRK operations, the DPRK has shifted to using foreign workers as cover.
The use of LinkedIn for recruitment suggests the DPRK is also adapting its methods to modern hiring practices. Job boards are now part of its toolkit.
The $500 monthly payment in cryptocurrency adds another layer. It gives the worker an incentive to cooperate, and it supports the overall scheme.
The report’s core message is that the threat has evolved. The DPRK is no longer just attacking banks or exchanges. It is now targeting the quiet corners of corporate IT departments, where a compromised account can yield sensitive information or access to systems.
The alert issued in July warned companies about the insider threat. Now the report confirms that the threat is real and ongoing.
The DPRK’s approach is unsettling because it relies on deception at every step. The foreign worker gets past the interview by pretending to be a regular applicant. Then they pretend to be a regular employee while sending their pay home. Only later does the real operator arrive.
The report raises questions about how companies screen applicants and monitor employee behavior. A worker who suddenly starts handling sensitive data could be a warning sign, especially if their salary is going somewhere unexpected.
The DPRK’s tactics are sophisticated, and they are paying off. The $2 billion in crypto losses and the 3.5% GDP growth show the scale of the DPRK’s operations.
The report’s warning is clear. Companies need to look closely at their hiring processes and their employees’ behavior. A worker who passes an interview may not be the person who actually holds the job.

