A North Korean remote IT worker managed to obtain work for a US federal agency and remained there for several months before being discovered, according to an FBI official. The case brings a fraud scheme already responsible for infiltrating numerous American businesses directly into the federal government.
Todd Hemmen, deputy assistant director of the FBI’s Cyber Capabilities Branch, disclosed the case during a conference panel discussion. He said the FBI had identified the worker during the previous week but provided few details because the investigation remains active. The federal agency involved has not been publicly identified, and the FBI has not disclosed what systems or information the individual could access.
Hemmen described the case as surprising and questioned how the unidentified agency’s procedures had allowed it to happen. He also confirmed that North Korean IT worker schemes are affecting government organizations, although private companies continue to represent a much larger proportion of known cases.
The discovery is particularly notable because US authorities have spent years investigating how North Korean nationals disguise their identities to obtain legitimate technology jobs. The FBI says these operations use methods including stolen identities, false online profiles, proxy computers and people located inside the United States to conceal the workers’ actual locations.
In some schemes, an employer sends its company laptop to what appears to be the worker’s US address. The device is instead kept at a location controlled by an intermediary and remotely accessed from overseas. These arrangements, commonly described as “laptop farms,” can make network activity appear to originate from within the United States while the person performing the work is located elsewhere.
The FBI has warned that the objective can extend beyond collecting salaries. North Korean IT workers have been observed obtaining access to sensitive corporate information, stealing proprietary data and, in some cases, using stolen information for extortion after their activity is discovered. US authorities say revenue generated through fraudulent employment is also used to benefit the North Korean government.
The latest federal case is not the first time a suspected North Korean worker has obtained access to US government systems. A previous Justice Department prosecution involved Maryland resident Minh Phuong Ngoc Vong, who fraudulently secured software development positions and allowed overseas workers to perform the work using his credentials.
One position involved a Virginia technology company that assigned Vong to a Federal Aviation Administration contract. The project involved software used by government agencies to manage sensitive information related to national defense. A foreign worker living in China, whom court documents indicated was likely a North Korean national, remotely performed the work between March and July 2023.
The scheme went beyond the FAA. According to the Justice Department, Vong used fraudulent representations to obtain positions with at least 13 US companies between 2021 and 2024. Several provided his services to government agencies, resulting in overseas conspirators receiving access to sensitive US government systems. Vong was sentenced to 15 months in prison in December 2025.
The scale of the broader operation has also become clearer through other prosecutions. In April 2026, the Justice Department announced sentences for two US nationals who helped North Korean remote workers obtain positions at more than 100 American companies. That operation used at least 80 stolen identities and generated more than $5 million in illicit revenue for North Korea.
The identity of the federal agency involved in the newly disclosed incident, the worker’s exact position and the level of access obtained have not been made public. The FBI has said it is still examining the case, leaving those details unresolved.