FBI probes North Korean hired by US agency

A North Korean remote worker was hired by a U.S. federal agency, prompting an FBI probe into a rare breach of government hiring controls.
The FBI is investigating how a North Korean was hired to work for a U.S. federal government agency, in a case first reported by Federal News Network. The episode stands out because it appears to be a rare confirmed example of a sanctioned North Korean working inside a government institution, not just a private company.
The agency has not been named, and it remains unclear how the person got through the hiring process. The FBI also declined to comment when contacted by TechCrunch. No public information has been released on whether any data or money were taken.
A federal hiring failure draws scrutiny
North Korean IT workers have for years been tied to schemes that use false identities to get remote jobs at companies in the U.S. and Europe. The aim, according to the source text, is to earn wages that are funneled back to the regime while also stealing intellectual property and other data that can later be used for extortion.
Government agencies have usually been tougher targets because of stricter vetting and security clearance checks. Even so, there have been earlier incidents. In 2024, the Justice Department charged a Maryland man who helped a North Korean hacker pose as an American to land a remote contractor job with the Federal Aviation Administration.
This case is more sensitive because it involves a federal agency directly rather than a private employer. That raises fresh concerns for public-sector hiring and security teams that rely heavily on remote work systems and identity checks.
How North Korean IT worker schemes function
The source describes these operations as long-running, coordinated efforts to fraudulently obtain employment. Workers are believed to use fake identities to pass hiring checks and secure remote positions, often with help from facilitators.
US authorities have warned that these networks do not operate alone. Enforcement actions and sanctions have targeted groups operating from Pyongyang, as well as from Russia and China, and Americans who helped set up fleets of laptops so North Koreans could work remotely while appearing to be based in the United States.
The concern goes beyond payroll fraud. According to IT-PUB News, the source says these workers may also steal corporate information and later try to extort companies once they are discovered. That mix of deception, data theft, and financial gain has made the issue a recurring cybersecurity and law-enforcement problem.
Why the investigation reaches beyond one agency
The case matters because it shows that even government hiring systems are not fully immune to remote-work deception. While the source says strict vetting has generally kept North Korean hackers out of government roles, this investigation suggests those safeguards can still fail.
For public agencies, the risk is especially serious. The stakes can include sensitive data, internal systems, and taxpayer-funded contracts. For businesses, the case is another reminder that remote hiring can be exploited when identity checks are weak or when employers rely too heavily on paperwork and online screening.
The source does not say whether any information was stolen, and it does not identify the agency involved. Still, the FBI investigation places the case within a broader pattern of North Korean efforts to use remote work as a tool for sanctions evasion and funding.
Sanctions, cybercrime and the money trail
The source also ties the IT-worker scheme to North Korea’s broader financing model. It says the country relies on hacks, including cryptocurrency theft, to support its sanctioned nuclear weapons program. According to blockchain forensic firms cited in the text, the Kim Jong Un regime was responsible for 76% of cryptocurrency thefts and netted at least $2 billion during 2025, despite being cut off from the global financial system.
That helps explain why this case has drawn attention. It is not simply a hiring failure. It sits at the intersection of cybersecurity, sanctions enforcement, remote-work fraud, and state-backed criminal activity.
For organizations that hire remotely, the warning is hard to ignore: a job interview and a background check may not be enough on their own. For government agencies, the case underscores how even established security procedures can be tested by sophisticated identity fraud.