On July 31, 2026, authorities from the United States, Japan, the Republic of Korea, Australia, Canada, France, Germany, Italy, the Netherlands, New Zealand, and the United Kingdom issued a joint alert warning countries, companies, and other entities about the threat posed by information technology (“IT”) workers of the Democratic People’s Republic of Korea (“DPRK” or “North Korea”). According to the alert, North Korea relies on a network of skilled IT workers, deployed both within and outside North Korea, who obtain remote work under false identities and remit their earnings to fund North Korea’s unlawful nuclear weapons and ballistic missile programs.
The alert continues a series of allied actions on this issue that date back several years. Most recently, on March 12, 2026, the US Department of the Treasury’s Office of Foreign Assets Control (“OFAC”) sanctioned two entities and six individuals for their roles in DPRK IT worker schemes that Treasury stated generated nearly USD 800 million in 2024. The alert also follows the August 2025 “Joint Statement on North Korean IT Workers” issued by Japan, the United States, and the Republic of Korea, and the October 2025 second report of the Multilateral Sanctions Monitoring Team on North Korea’s evasion of UN sanctions through cyber and IT worker activities. The Federal Bureau of Investigation (“FBI”) has likewise published successive advisories on North Korean IT workers since 2022, most recently a July 23, 2025 public service announcement updating previously shared guidance and referencing advisories issued in 2022 and 2023 and further FBI guidance in 2024 and 2025.
The alert restates common ways described in previous advisories, under which North Korean IT workers impersonate nationals of other countries to obtain work and income through online platforms for employment, procurement, and contracting of services, increasingly across areas such as web page, mobile application, software, and blockchain development. It also notes that these workers increasingly use artificial intelligence to obscure their identities and may pose an insider threat through data exfiltration, cryptocurrency theft, and theft of sensitive information.
The alert identifies red flag indicators for companies operating online platforms, including frequent changes to registered account information; mismatches between an account holder’s name and its payment account; multiple accounts tied to the same identification document or IP address; and forged or altered identification documents. For those hiring or procuring services, indicators include profiles suggesting inaccurate machine translation; refusal to appear on video or manipulated video feeds; offers to work at below-market rates; and requests for payment in cryptocurrency. To counter these schemes, the alert recommends that companies operating online platforms strengthen their countermeasures, such as enhancing identity verification procedures. The FBI’s July 2025 announcement goes further, recommending that companies verify prior employment and education directly with the institutions concerned, require in-person meetings where possible to confirm identity and claimed location, compare payment accounts across employees for matching banking information, and ship company equipment only to the address on an employee’s identification documents.
Companies that engage remote IT workers or operate freelance, procurement, or contracting platforms should consider reviewing their onboarding and identity-verification procedures in light of the indicators in the alert and the FBI’s guidance, and assessing whether their existing sanctions compliance controls adequately address the risks identified. Companies that employ North Korean workers (even unwittingly) may face liability under applicable sanctions and/or export controls, which further underscores the need for trade compliance programs to address this risk.