The FBI is looking into how a North Korean IT professional secured a remote position within a U.S. government agency.
Todd Hemmen, the deputy assistant director of the FBI’s Cyber Capabilities Branch, revealed the case on July 28 during a Digital Government Institute conference in Washington, in reply to an inquiry regarding whether North Korea’s remote IT worker initiative had extended to government sectors.
He stated that the bureau had recognized the worker the previous week but did not reveal the agency or outline the worker’s responsibilities, according toFederal News Network, which documented his comments on August 11.
Hemmen mentioned he was still reviewing the case and described it as “somewhat confusing,” informing the committee that he failed to grasp the recruitment procedure at the relevant agency.
The details of how the employee successfully passed the screening process and whether they accessed confidential systems or information remain undisclosed.
Federal authorities claim that North Korea has deployed thousands of trained IT professionals globally to secure positions through deception, generating income for its military initiatives, and embedding them within hundreds of companies.
The United Nations estimates that the operation generates approximately $250 million to $600 million annually for Pyongyang.
Employees employ fake identities to secure remote jobs and redirect their salaries to the government, while also stealing intellectual property and other information, which they then use to blackmail employers once uncovered.TechCrunch reported.
![]() |
|
The FBI emblem at the entrance of the agency’s headquarters in Washington, D.C., in May 2025. Photo by Reuters |
Experts told Federal News NetworkThe public sector’s involvement was expected, and he noted that the case highlights weaknesses in government and industry screening processes, especially concerning IT support positions.
Three days following Hemmen’s remarks, the U.S. along with 10 Asian and European allies cautioned businesses against employing North Korean IT professionals, stating in a joint declaration on July 31 that such labor supports Pyongyang’s nuclear weapons and missile development initiatives,AFP reported.
The signatories included Japan, South Korea, Australia, Canada, France, Germany, Italy, the Netherlands, New Zealand, and the U.K., with six of them having previously issued their own warnings regarding the threat.
The warning indicated that the workers pretend to be citizens of different nations to secure contracts via business hiring and purchasing websites, and afterward send their wages back to their overseeing bodies in North Korea.
Their techniques are becoming more advanced, the statement noted, such as employing AI to hide their identities, and they pose a risk from within, associated with stealing data and cryptocurrency.







Leave a comment