North Korean Operatives Infiltrate U.S. Companies

May 13, 2026 Advisory

What is Happening

Over the past several years, reports have shown that North Korean operatives have infiltrated U.S. companies by posing as remote workers using deepfakes, social engineering, and AI tools. These operatives often work through “laptop farms” that host company-issued devices and allow remote access to corporate systems. Their activities can expose companies to sanctions violations, regulatory penalties, frozen assets, trade secret theft, data breaches, and extortion attempts involving stolen information.

How to Prevent This

Companies can reduce risk through coordinated cybersecurity, HR, and sanctions compliance controls, including stronger identity verification, tighter system access restrictions, continuous monitoring, and enhanced vendor and payment screening procedures.

  • Require live, on-camera interviews and government-issued identification verification, where permitted by law.
  • Independently verify prior employment, education, and professional credentials rather than relying solely on candidate-provided contacts.
  • Use E-Verify and ensure third-party staffing agencies follow robust identity verification procedures.
  • Apply continuous authentication and least-privilege access controls rather than relying solely on pre-employment screening.
  • Restrict access from high-risk jurisdictions and limit the use of personal devices and external storage media.
  • Implement and maintain endpoint detection and response tools to continuously monitor suspicious activity.
  • Establish clear policies governing access to sensitive information, suspicious activity reporting, and remote work security.
  • Send company equipment only to verified addresses or conduct additional verification for alternative delivery requests.
  • Screen vendors, contractors, and workers against applicable sanctions lists and monitor for red flags such as VPN use, payment requests to third parties, refusal to appear on camera, or frequent bank account changes.
  • Avoid cryptocurrency payments and do not pay ransoms or extortion demands.
  • Maintain relationships with law enforcement and be prepared to report suspicious activity promptly.

What to Do if This Happens

If it is discovered that an operative has infiltrated a company, immediately revoke system access, secure affected systems, and begin a cybersecurity investigation to determine the scope of access and potential data exposure. Take appropriate employment actions consistent with applicable law, preserve relevant evidence, and, if appropriate, notify law enforcement to mitigate potential sanctions and regulatory risks.

Contact Us
  • Worldwide
  • Chicago, IL
  • Denver, CO
  • Edwardsville, IL
  • Jefferson City, MO
  • Kansas City, MO
  • Miami, FL
  • New York, NY
  • Philadelphia, PA
  • St. Louis, MO
  • Washington, D.C.
  • Wilmington, DE
Worldwide
abstract image of world map
Chicago, IL
100 North Riverside Plaza
Suite 1500
Chicago, IL 60606-1520
Google Maps
Chicago, Illinois
Denver, CO
4600 South Syracuse Street
Suite 1400
Denver, CO 80237
Google Maps
Denver, Colorado
Edwardsville, IL
115 N. Second St.
Edwardsville, IL 62025
Google Maps
Edwardsville, Illinois
Jefferson City, MO
101 E. High St.
First Floor
Jefferson City, MO 65101
Google Maps
Jefferson City, Missouri
Kansas City, MO
2345 Grand Blvd.
Suite 1500
Kansas City, MO 64108
Google Maps
Kansas City, Missouri
Miami, FL
355 Alhambra Circle
Suite 1200
Coral Gables, FL 33134
Google Maps
Photo of Miami, Florida
New York, NY
400 Park Ave.
12th Floor
New York, NY 10022
Google Maps
New York City skyline
Philadelphia, PA
2005 Market Street
29th Floor, One Commerce Square
Philadelphia, PA 19103
Google Maps
Philadelphia, Pennsylvania
St. Louis, MO
7700 Forsyth Blvd.
Suite 1800
St. Louis, MO 63105
Google Maps
St. Louis, Missouri
Washington, D.C.
1717 Pennsylvania Avenue NW
Suite 400
Washington, DC 20006
Google Maps
Photo of Washington, D.C. with the Capitol in the foreground and Washington Monument in the background.
Wilmington, DE
1007 North Market Street
Wilmington, DE 19801
Google Maps
Wilmington, Delaware