The U.S. Department of Justice has sentenced eight individuals for helping North Korean IT workers infiltrate American companies through fraudulent remote employment arrangements. The defendants, described as “laptop farmers,” enabled North Korean operatives to pose as U.S.-based workers and gain access to corporate systems.
Remote access setup used to impersonate U.S. employees
According to the case details, the facilitators installed remote desktop software on employer-issued laptops, allowing overseas operators to control the devices and appear as legitimate U.S. employees. The scheme reportedly targeted nearly 70 American companies and generated $1.2 million for North Korea.
Two defendants, Matthew Issac Knoot and Erick Ntekereze Prince, each received 18-month prison sentences in May. The case highlights how remote work infrastructure and device access can be abused to bypass hiring controls and internal security checks.
Crypto firms were a primary focus
The report says the operation mainly targeted technical roles at cryptocurrency companies, with the apparent objective of stealing digital assets or gaining deeper access to internal infrastructure. This approach is particularly concerning for crypto businesses, where engineering, security, and operations roles may have access to wallets, code repositories, and sensitive systems.
In a related case last month, Kejia Wang and Zhenxing Wang were sentenced to 9 years and 7 years and 8 months, respectively, for running a larger operation that brought in more than $5 million for North Korea.
Corporate exposure has risen sharply
The source also notes that the number of companies found to have employed North Korean workers has surged by 220% over the past year, with more than 320 enterprises affected. The figures suggest growing risks around remote hiring, identity verification, and endpoint management, especially for crypto firms that rely on distributed teams and global recruiting.
The sentencing signals continued U.S. enforcement pressure on North Korea-linked cyber revenue operations, while also underscoring the need for stronger hiring and security controls across vulnerable sectors.

