Eleven Nations Issue Joint Alert on North Korean IT Worker Revenue Schemes Funding Weapons Programs
The Financial Action Task Force reiterated that the Democratic People’s Republic of Korea has increased connectivity with the international financial system.
WASHINGTON — The United States Department of State and Federal Bureau of Investigation, together with counterparts from Japan, the Republic of Korea, Australia, Canada, France, Germany, Italy, the Netherlands, New Zealand, and the United Kingdom, issued a joint alert on July 31 detailing how North Korean IT workers obtain false identities to secure remote contracts and remit earnings to parent agencies supporting unlawful nuclear weapons and ballistic missile programs.
The alert describes workers who impersonate foreign nationals on private online platforms for employment, procurement, and service contracts, while also posing insider risks through data exfiltration, cryptocurrency theft, and sensitive-information theft. Methods now include AI integration to obscure identities.
Participating states note that contracting with such workers can violate domestic laws in Japan, the United States, and the Republic of Korea and may trigger legal or financial penalties.
United Nations Security Council Resolution 2397 requires Member States to repatriate North Korean nationals earning income in their jurisdictions, subject to limited exceptions.
The Financial Action Task Force continues to list North Korea as a high-risk jurisdiction subject to a call for action and has identified IT worker schemes in its proliferation-financing and sanctions-evasion typologies as a revenue channel for weapons of mass destruction programs.
In its June 19 public statement on high-risk jurisdictions, the Financial Action Task Force reiterated that the Democratic People’s Republic of Korea has increased connectivity with the international financial system, which raises proliferation financing risks, and called for continued countermeasures including limits on business relationships and financial transactions with DPRK persons.
Key Finding 1 (high confidence, based on the July 31 joint alert text and consistent prior advisories from the same states): North Korean IT workers systematically falsify nationality and identity documents, often supplied by third-party proxies, to register on commercial platforms and secure contracts whose proceeds are remitted to North Korean agencies.
Key Finding 2 (high confidence, based on Department of Justice charging documents and sentencing records from 2025–2026): U.S.-based facilitators operate “laptop farms” that receive employer-provided computers and enable remote access by overseas workers, generating documented multimillion-dollar revenue streams for North Korean entities.
Key Finding 3 (moderate-to-high confidence, based on the October 2025 Multilateral Sanctions Monitoring Team report summary released by participating states): Fraudulent IT work forms part of a broader pattern of cyber-enabled sanctions evasion that the MSMT links to UN-designated entities, including the Reconnaissance General Bureau, and to revenue supporting weapons programs.
Key Finding 4 (moderate confidence, trajectory assessment drawn from the sequence of joint statements in 2025 and the expanded 2026 indicator list): The schemes are expanding in technical sophistication and geographic reach, with workers operating from North Korea, China, Russia, Southeast Asia, and Africa while using proxies, VPNs, and remote-desktop tools to conceal locations.
Key Finding 5 (high confidence, based on the December 2024 Department of Justice indictment, the 2026 National Proliferation Financing Risk Assessment, and the March 12 Office of Foreign Assets Control designations): Documented schemes have generated revenues ranging from tens of millions of dollars in individual conspiracies to nearly $800 million in 2024, with facilitators operating from China, Russia, Vietnam, Laos, Spain, and the Democratic People’s Republic of Korea itself.






