the tech buzz

SUBSCRIBE
AIEnterpriseDealsSecurityCrypto
Newsletter

the tech buzz

Your premier source for technology news, insights, and analysis. Covering the latest in AI, startups, cybersecurity, and innovation.

FOLLOW US

THE DAILY

Get the latest technology updates delivered straight to your inbox.

Company

  • About Us
  • Editorial Team
  • Write For Usnew
  • Contact Us
  • Advertisenew

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Disclaimer
  • EULA
  • AI Code of Conduct

Resources

  • Newsletters
  • RSS Feeds
  • Subscribe
  • Pricing & Packages
  • Sitemap
  • Archives
  • TechBuzz Pressnew

PUBLISH WITH US

Reach 1.1M+ subscribers via TechBuzz Press.

TechBuzz Press

HAVE A TIP?

Send us a tip using our anonymous form.

Send a tip

HAVE QUESTIONS?

Reach out to us on any subject.

Ask Now

Browse by Category

AIBlockchainCloudSecurityDataDealsInvestmentsEnterpriseVenturesIoTMobileRoboticsSoftwareStartupsAppleMetaMicrosoftOpenAiGoogleTesla

© 2026 The Tech Buzz. All rights reserved.

the tech buzz

DOJ Busts North Korean Remote Worker Scheme - 5 Guilty Pleas

ArticlesNewsletters
ArticlesNewsletters
cybersecurity

DOJ Busts North Korean Remote Worker Scheme - 5 Guilty Pleas

Five people plead guilty to helping North Korean IT workers infiltrate 136 US companies

by The Tech Buzz

PUBLISHED: Fri, Nov 14, 2025, 5:43 PM UTC | UPDATED: Fri, Sep 4, 2026, 4:59 PM UTC

Add as a preferred source on Google
DOJ Busts North Korean Remote Worker Scheme - 5 Guilty Pleas

Five people have pleaded guilty to orchestrating an elaborate scheme that helped North Korean IT workers infiltrate 136 US companies as remote employees, netting Kim Jong Un's regime $2.2 million in wages. The Department of Justice announced the guilty pleas Friday as part of its ongoing crackdown on North Korea's cybercrime operations that fund the country's nuclear weapons program.

The Department of Justice just pulled back the curtain on one of North Korea's most sophisticated infiltration operations yet. Five people - including four US nationals - have pleaded guilty to running a sprawling scheme that helped North Korean IT workers pose as legitimate remote employees at 136 American companies.

The operation wasn't just sophisticated - it was profitable. Kim Jong Un's regime pocketed $2.2 million from the scheme, while US companies unknowingly paid out $1.28 million in salaries to workers they thought were based domestically.

Here's how the scam worked: The facilitators provided real or stolen identities from US nationals, hosted company-issued laptops in homes across America to create the illusion of local workers, and even helped the North Korean operatives pass drug tests and background screenings. "These prosecutions make one point clear: the United States will not permit [North Korea] to bankroll its weapons programs by preying on American companies and workers," US Attorney Jason A. Reding Quiñones said in the DOJ press release.

The guilty pleas reveal the extent of the operation. Three US nationals - Audricus Phagnasay, Jason Salazar, and Alexander Paul Travis - each pleaded guilty to wire fraud conspiracy. Travis, who was an active US Army servicemember during the scheme, earned over $50,000 for his role. Phagnasay and Salazar received at least $3,500 and $4,500 respectively.

Advertisement

But the most elaborate setup belonged to Erick Ntekereze Prince, a fourth US national who ran a company called Taggcar. Prince's operation supplied allegedly "certified" IT workers to US companies while knowing they worked outside the country using stolen identities. He hosted laptops with remote access software across multiple Florida residences and earned more than $89,000 for his services.

The international element came through Ukrainian national Oleksandr Didenko, who specialized in stealing US citizens' identities and selling them to North Korean operatives. Didenko's identity theft operation helped North Koreans secure jobs at over 40 US companies, earning him hundreds of thousands of dollars. As part of his guilty plea, he agreed to forfeit $1.4 million.

This case represents the latest escalation in a years-long battle between US authorities and North Korea's cyber operations. The regime has successfully infiltrated hundreds of Western companies as remote workers, investors, and recruiters to fund its internationally sanctioned nuclear weapons program. The US government has responded with indictments and sanctions on international fraud networks.

Advertisement

The DOJ also announced it froze and seized over $15 million in cryptocurrency stolen in 2023 by North Korean hackers from crypto platforms. This seizure highlights another revenue stream for the regime - North Korean hackers stole over $650 million in crypto in 2024 and more than $2 billion so far this year.

For companies, this case exposes critical vulnerabilities in remote work verification processes. The fact that 136 companies fell victim suggests that standard background checks and identity verification methods aren't equipped to detect state-sponsored deception operations. The scheme's success at helping workers pass drug tests and vetting procedures indicates these operations have become increasingly sophisticated.

The financial impact extends beyond the direct wage theft. Companies likely face additional costs from compromised systems, potential data breaches, and the need to implement more robust verification procedures. The involvement of a US Army servicemember in Travis also raises national security concerns about insider threats within military ranks.

This DOJ crackdown represents a significant victory in the ongoing battle against North Korea's cyber-enabled revenue generation, but it also reveals how vulnerable remote work practices have become to state-sponsored deception. With $2.2 million flowing to fund nuclear weapons programs through what appeared to be routine IT work, companies now face the reality that their remote hiring processes may be inadvertently supporting international sanctions violations. The involvement of US nationals and military personnel in facilitating these operations suggests the threat extends far beyond foreign actors - it's now embedded within domestic networks willing to profit from helping hostile nations exploit American businesses.

Advertisement

Advertisement

Trending Now

1

GoPro CEO Vows Cameras Stay Core After Starman Deal

2

Judge Splits Ruling in X vs. Twitter Rival Fight

3

Tim Cook Steps Down, Ternus Takes Apple's Helm

4

Google's Lyria 3.5 Brings AI Music to Gemini

5

Google Translate Gets Listening Mode, Live Background Mode

People Also Ask

The DOJ busted a scheme where five facilitators helped North Korean IT workers infiltrate 136 US companies as remote employees using stolen identities, laptop hosting services, and fake background checks. The operation netted North Korea's regime $2.2 million to fund nuclear weapons programs.

North Korea's regime received $2.2 million from the fake remote worker scheme, while US companies paid out $1.28 million in total salaries to workers they believed were legitimate domestic employees. The DOJ also seized $15 million in stolen cryptocurrency from separate North Korean hacking operations.

Five people pleaded guilty: four US nationals (Audricus Phagnasay, Jason Salazar, Alexander Paul Travis, and Erick Ntekereze Prince) and one Ukrainian national (Oleksandr Didenko). Travis was an active US Army servicemember who earned over $50,000, while Prince ran a fake IT company called Taggcar.

North Korean workers used stolen US identities provided by facilitators, laptop hosting services in American homes to appear local, and received help passing drug tests and background screenings. The scheme involved sophisticated identity theft operations and remote access software across multiple residences.

136 US companies were infiltrated by North Korean remote workers through this specific scheme. The operation reveals critical vulnerabilities in remote work verification processes, as standard background checks failed to detect the state-sponsored deception operations across all these companies.

North Korea uses fake remote workers to generate revenue for funding its nuclear weapons program, which faces international sanctions. The regime has successfully infiltrated hundreds of Western companies as remote workers, investors, and recruiters to circumvent financial restrictions and fund weapons development.

More in cybersecurity

How To Prevent Account Takeover?

How To Prevent Account Takeover?

Coupang CEO Resigns After 34M Customer Data Breach

Coupang CEO Resigns After 34M Customer Data Breach

Petco Data Breach Exposes SSNs, Driver's Licenses in Major Leak

Petco Data Breach Exposes SSNs, Driver's Licenses in Major Leak

Petco Data Breach Exposes Customer Info in App Config Error

Petco Data Breach Exposes Customer Info in App Config Error

Marquis Ransomware Attack Hits 400K+ Bank Customers

Marquis Ransomware Attack Hits 400K+ Bank Customers

Okta beats Q3 earnings as AI agent push drives growth

Okta beats Q3 earnings as AI agent push drives growth

More Articles

Mixpanel Data Breach Exposes Millions, OpenAI Cuts Ties

Mixpanel Data Breach Exposes Millions, OpenAI Cuts Ties

Dec 2

Coupang Data Breach Hits 34M Users in Months-Long Attack

Coupang Data Breach Hits 34M Users in Months-Long Attack

Dec 1

London Councils Hit by Major Cyberattack, Emergency Plans Activated

London Councils Hit by Major Cyberattack, Emergency Plans Activated

Nov 26

Tyler Technologies jury system bug exposed juror data across US

Tyler Technologies jury system bug exposed juror data across US

Nov 26

Major Banks Assess Data Theft After SitusAMC Breach

Major Banks Assess Data Theft After SitusAMC Breach

Nov 24

Corporate America ditches passwords as 92% of CISOs go passwordless

Corporate America ditches passwords as 92% of CISOs go passwordless

Nov 23