An expanded 11-nation advisory says operatives now use live AI deepfake interviews and laptop farms to win remote jobs, steal data and route wages and crypto through overseas networks.
Western allies have expanded warnings that North Korean IT workers are raising money for Pyongyang’s nuclear weapons and ballistic missile programs by securing remote jobs under false identities, with a new July 31, 2026 advisory highlighting the use of real-time AI deepfake video during live interviews. The coordinated alert, issued by 11 countries including the United States, Japan, South Korea, France, Germany, Italy and the Netherlands, says operatives work from North Korea, China, Russia, Southeast Asia and Africa while posing as job candidates based in the United States and elsewhere. The advisory says the workers use AI-generated resumes, portfolio sites and other fabricated hiring materials, then maintain access after onboarding through “laptop farms” and remote administration tools that make company-issued devices appear to be used domestically. Governments and security firms say the operatives can steal source code, harvest credentials and extort employers by threatening to publish proprietary data if discovered. The campaign generated about $800 million for Pyongyang in 2024 alone, according to the report, while related North Korean actors stole about $2.02 billion in cryptocurrency in 2025, including the $1.5 billion Bybit hack. The warning also underscores legal and compliance risks for employers, noting that companies may face sanctions exposure even if they unknowingly hire North Korean workers. The alert comes as the Justice Department has already secured multiple 2026 prison sentences against U.S.-based facilitators and as new U.S. legislation seeks to formalize allied and private-sector coordination against the scheme.