North Korean IT worker spent months at US federal agency
Has a North Korean IT worker managed to fool the FBI?

Image by Cybernews.
- The FBI said a North Korean remote IT worker was working at a US federal agency for several months.
- The case suggests gaps in government hiring or contractor vetting, despite warnings about North Korean IT worker schemes.
- North Korea uses fake remote IT jobs to earn money and seek access to Western companies and government systems.
- Security experts say the threat begins during hiring, making it both a cybersecurity and personnel-security problem.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
A North Korean was hired as a remote IT worker by a US government agency, the FBI has disclosed. In fact, the individual reportedly worked for the agency for several months before being sniffed out.
The FBI, of course, knows a lot about the long-running campaign involving North Korean remote IT workers fraudulently obtaining jobs at US companies and other organizations.
Yet somehow, the Bureau managed to miss a North Korean worker who successfully infiltrated a federal agency. The case highlights a new kind of insider threat and exposes potential gaps in the government vetting processes.
There’s no official announcement about the aforementioned North Korean worker. The fact that they were hired by and work for a US federal agency was disclosed during a conference panel discussion by Todd Hemmen, deputy assistant director of the FBI’s Cyber Capabilities Branch.
Has your password leaked?
“Without getting into ongoing investigations, we identified just this past week a [Democratic People’s Republic of Korea] remote IT worker that was working for the federal government,” said Hemmen, according to Federal News Network.
“Still kind of unpacking that recent case. It’s actually a little bit baffling to me, not understanding this particular agency’s process. But the short answer is yes, we are seeing remote IT workers not just in the private sector – although a vastly higher proportion in the private sector – but we’re also seeing this impact the government to a degree.”
It’s probable that the remote employee was doing contract work on behalf of the agency. Getting a federal job is too complex a process since every potential employee’s background is extensively investigated.
In 2025, a Maryland man was sent to prison for allowing a North Korean IT worker, based in China, to work on software development contracts for the Federal Aviation Administration. According to the Department of Justice, co-conspirators gained access to “sensitive US government systems.”
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
North Koreans, pretending to be legitimate remote IT workers, have long been infiltrating Western companies to generate revenue for the isolated regime.
On July 31st, US agencies and foreign partner agencies released a global alert regarding the risk North Korean remote IT workers pose to “private companies, governments, and individual citizens.”
But is Pyongyang now expanding the scope of these schemes?
Michael Centrella, Head of Public Policy at SecurityScorecard who previously oversaw major cybercrime and fraud cases at the US Secret Service, tells Cybernews that the government angle “raises the stakes.”
The challenge is that the attack begins before a traditional technical compromise ever occurs – potentially during the hiring process itself,said Michael Centrella, Head of Public Policy at SecurityScorecard.
“That makes this not just an identity or cybersecurity issue, but an insider-risk and personnel-security challenge as well.”
A former FBI official, speaking to Federal News Network, agreed it was only natural for the North Koreans to try and “get placement into government locations” since their actions demonstrate capability and intent to gain access into the federal government.