ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

North Korean IT Workers Extort Employers in Escalating Cyber Scheme

North Korean operatives posing as IT workers in the US, UK, and other countries are now resorting to extortion after infiltrating companies, according to cybersecurity firm Secureworks. This marks a significant evolution in their tactics, using fake identities to gain access to sensitive information and demanding ransom payments.

 

Secureworks’ investigation revealed that these individuals are stealing proprietary data from their employers and then leveraging it for financial gain. In a recent case, a fraudulent contractor accessed sensitive information soon after joining a company and later demanded a six-figure ransom in cryptocurrency to prevent the data’s public release.

 

The extortion tactic highlights a shift in North Korea’s strategy, moving beyond traditional espionage to include intellectual property theft for monetary gain. This evolution raises the risk for organisations that unknowingly hire North Korean workers, according to Secureworks.

 

US authorities have long warned about North Korea’s scheme to place state-backed workers in Western companies, using the salaries to support its military and gain access to crucial technology. The operation initially targeted cryptocurrency firms but has since expanded to include major global corporations.

 

In a related development, Amazon’s Chief Security Officer Stephen Schmidt suggested that Chinese entities might be collaborating with North Korea in these operations. While direct evidence of such cooperation is lacking, Schmidt noted indications of shared intelligence between the two nations.

 

To evade detection, North Korean operatives employ sophisticated tactics, including using remote access tools like Chrome Remote Desktop and software like SplitCam to disguise their identities during video calls.

 

Secureworks also found evidence that these fake workers use interconnected personas and frequently update their banking details to circumvent traditional financial systems, indicating a well-coordinated effort to exploit Western employers for both strategic and financial gain.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543