On August 13, 2026, the world learned of an unprecedented revelation: thousands of North Korean programmers have been secretly working for American companies for years, using neural networks to create deepfakes and fake identities. An investigation by The Wall Street Journal, backed by leaks from internal North Korean documents, reveals that Pyongyang has created a global shadow network that brings the Kim Jong Un regime up to $800 million annually. Up to 90% of these funds directly finance North Korea's military and nuclear programs.

Technological Upgrade: AI Instead of Fake Passports

The scheme, which previously relied on the crude use of stolen profiles, reached a level of cybernetic perfection in 2026. North Korean operatives now use generative AI to create perfect resumes, indistinguishable from texts written by native speakers, and to write test assignments. During video interviews on Zoom or Teams, live face-masking software is used — software for overlaying digital faces in real time. This allows the speaker's appearance to fully match the stolen ID card of a real US citizen, whose Social Security Number (SSN) was purchased on darknet markets.

"Laptop Farms": How Physical Presence is Simulated from China and Russia

A key element of the scheme is physical infrastructure. American companies send work laptops to addresses in the US, where they are met by hired intermediaries. These devices are connected to the network and form so-called "laptop farms." North Korean coders, located in China, Laos, or Russia, connect to American laptops via remote access software (TeamViewer, AnyDesk). To corporate security systems, they look like ordinary programmers from a neighboring state. Some of these "employees" manage to work 3–4 jobs simultaneously, earning up to $300,000 a year on a single position.

From Payroll Theft to Open Extortion

The situation has gone beyond the scope of ordinary fraud and turned into a national security threat. On August 11, 2026, the FBI officially confirmed an investigation into an incident in which a North Korean agent obtained a contract at one of the US federal government agencies. This caused panic in Washington. Moreover, the nature of the Koreans' presence in US infrastructure has become more aggressive. Cybersecurity experts from ANY.RUN and Nisos note that while North Korean agents previously tried to stay quiet to simply accumulate money, a new wave has now been recorded: gaining access to company databases (especially in the crypto sphere), they download confidential information and openly blackmail management, demanding million-dollar ransoms before their "termination".

Contradictory Data

While The Wall Street Journal claims that the scheme is fully automated and brings in up to $800 million annually, some experts point to possible exaggerations of the figures. According to independent analysis, actual revenues may be lower due to losses on intermediaries and failed operations. Furthermore, there is disagreement regarding the exact number of specialists involved: WSJ cites "thousands," while other sources suggest that active operators may number only a few hundred, supported by a network of intermediaries.

HR Industry Crisis and a Paradigm Shift in Threats

The US remote hiring market is facing a systemic crisis: traditional background checks are no longer coping with synthetic identities created by artificial intelligence. According to Gartner 2026 surveys, more than 62% of recruiters admit that candidates have learned to forge identities using AI faster than security services can update verification methods. Previously, companies defended themselves against hackers from the outside (firewalls, antivirus software); now the threat comes from within. North Korean operatives obtain legal access, corporate accounts, and SSH keys, making them practically indistinguishable from real employees.