United States and a dozen allied countries have issued a joint warning this Friday directed at public administrations, private companies, and digital platforms about the activity of computer workers linked to North Korea who, allegedly, access —using fictitious identities— remote job positions whose income would end up funding the weapons programs of Pyongyang.
The statement has been supported by authorities from the United States, Japan, South Korea, Australia, Canada, France, Germany, Italy, the Netherlands, New Zealand, and the United Kingdom. These governments denounce that the North Korean regime maintains a network of specialists in information technology (IT), deployed both within its borders and abroad, in order to obtain funds for its illegal nuclear and ballistic missile programs.
According to the signatories, these professionals systematically resort to identity theft of citizens from third countries to secure contracts through private selection and service provision platforms. The ultimate purpose is to channel the salaries obtained towards North Korean state agencies.
The authorities have emphasized that these individuals also pose a direct risk to the organizations that incorporate them, as they can exploit their access to internal systems to extract sensitive information, leak data, or perpetrate cryptocurrency thefts.
At the same time, they have pointed out that their methods have become progressively more advanced thanks to the use of artificial intelligence tools, which facilitate hiding their true identity and expanding the scope of their operations in the digital environment.
The involved governments have recalled that in recent years they had already disseminated several alerts about this threat, including the Joint Declaration on North Korean IT Workers, signed by Japan, the United States, and South Korea in August 2025, as well as the second report of the Multilateral Sanctions Monitoring Team (EMMS), published in October of the same year, which details the violations of international sanctions by Pyongyang through cyber activities and the employment of IT personnel.
In this context, they have assured that they will continue to intensify monitoring and measures to curb these activities.
The signatory countries have also emphasized that Resolution 2397 of the United Nations Security Council requires, with few exceptions, the repatriation of North Korean citizens who generate income in the territory of member states. They have also warned that the hiring of these actors may conflict with the national legislation of some states —such as Japan, the United States, or South Korea— and lead to economic sanctions or legal liabilities for the companies involved.
The alert also highlights the delicate financial situation of North Korea, reminding that the Financial Action Task Force (FATF) keeps the country on its list of high-risk jurisdictions, and insists on the need to apply financial sanctions to prevent money laundering, the financing of terrorism, and the proliferation of weapons of mass destruction.
Despite this sanctioning framework, the document notes that Pyongyang has managed to increase its access to the international financial system through various income-generating mechanisms, including networks of IT workers used to bolster its military programs.
In light of this scenario, the signatory governments have urged "all countries, companies, and other entities to deepen their understanding of the schemes for recruiting IT workers in North Korea and implement measures to counteract the tactics detailed below."
Among the recommendations made, they demand that hiring platforms strengthen identity verification processes with more rigorous checks of documentation, in-person interviews when feasible, and systems capable of detecting anomalous behavior patterns or suspicious accounts.
"MODUS OPERANDI"
The alert also details the modus operandi of these workers, who often use falsified documents or identities provided by third parties to register on digital platforms. In numerous cases, they rely on intermediaries to pass job interviews or project a trustworthy image to potential employers.
Furthermore, they have explained, they tend to reject payment via direct deposit and prefer to receive payments by bank transfer to third-party accounts or through cryptocurrencies, subsequently using complex networks to withdraw the money from the country.
The authorities have also indicated that these professionals have a high technical qualification and seek opportunities in fields such as web development, mobile applications, enterprise software, or projects based on blockchain technology, both through specialized platforms and through direct hiring.
Although a considerable part resides in North Korea, China, Russia, and several countries in Southeast Asia and Africa, they usually hide their real location through virtual private networks (VPNs), proxy servers, remote access tools, or even "laptop farms" managed by collaborators in third countries, from where they connect to equipment provided by the contracting companies to simulate that they work from the declared location.