The FBI is investigating how a North Korean remote IT worker came to work for an unidentified US federal agency, after the bureau discovered the individual in July 2026. The case has raised fresh questions about how North Korean operatives are getting through hiring and identity checks designed to prevent them from accessing US organisations.
The discovery was disclosed by Todd Hemmen, deputy assistant director of the FBI's Cyber Capabilities Branch, during a Digital Government Institute conference in Washington, DC, on 28 July.
Hemmen said investigators had identified a Democratic People's Republic of Korea remote IT worker who had been working for the federal government, although he gave no details about the agency or the person involved.
The FBI has been warning for years that North Korea sends skilled IT workers overseas to obtain legitimate employment under false identities. The workers can then earn money for the regime, while potentially gaining access to corporate networks and sensitive information.
The scheme has become increasingly sophisticated. US authorities say North Korean workers have used stolen identities, false documents, virtual private networks and remote-access tools to disguise where they are actually working from. In some cases, US-based facilitators have helped receive company laptops or create the appearance that an overseas worker is physically located in America.
The FBI has also warned that the threat is no longer limited to collecting salaries. Investigators have found cases in which workers used their access to steal proprietary information, credentials and other sensitive data, sometimes followed by extortion attempts.
Artificial intelligence is adding another layer to the problem. Hemmen said during the July conference that AI was being used across the recruitment process, including for creating CVs and identity documents, taking part in video interviews and generating convincing deepfakes.
'We're seeing AI use across that entire spectrum of the DPRK remote worker, from application to employment,' Hemmen said.
That matters because a remote IT position can appear relatively ordinary on paper. The person may not hold a security clearance or occupy a high-profile government role, yet still have access to systems that connect to major government infrastructure.
Hemmen described the particular case as 'a little bit baffling', saying he did not understand how the agency's process had allowed the worker to get through.