North Korean IT workers are still getting hired by US companies in 2026, and the screening that stops them is boring: check the person, the address and the bank account at three different moments, and don't let any one of them change quietly. Two government alerts this year, on July 31 and September 18, describe the scheme in more detail than ever, and almost every red flag in them is something a hiring manager can see before the laptop ships.
Key Takeaways
- An 11-country alert dated July 31, 2026 says many North Korean IT workers live in North Korea, China, Russia, Southeast Asia and Africa, and hide it with proxies, VPNs and US "laptop farms."
- A September 18, 2026 alert adds interview tells: glances at another monitor, background voices, and repeated video or audio freezes.
- Payment is the strongest tell: the July alert says these workers avoid direct deposit and route pay through a third party's account.
- Paying them can expose the employer to sanctions risk, so screen before the first invoice.
What the 2026 alerts actually say
The July 31 alert is hosted on the FBI's IC3 site; NK News reported that 11 governments issued it.
It says many "reside in North Korea, China, and Russia, as well as Southeast Asian and African countries," and they "may conceal the fact that they are working from abroad using third-party proxies, VPNs, remote desktop software, and similar tools." The facilitators who run laptop farms are named as being in places "such as in the United States."
The red flags it lists for hiring teams:
- photo ID that doesn't match the person, or "video feeds that appear to be manipulated or artificially generated"
- refusing video meetings
- rates below market
- signs that "multiple people" run the account, where the person you talk to "may change depending on the time of day"
- requests for crypto payment, and avoiding direct deposit by giving you "a third party's bank account"
The September 18 alert, from Japan's National Police Agency and National Cybersecurity Office, the FBI, the US DoD Cyber Crime Center, Australia's ASD and Germany's BND and BfV, adds what an interviewer sees: "Frequent glances at another monitor, as if reading from the screen," "Occasional background voices," and "Repeated video or audio freezes." Its suggested checks are cheap: confirm the IP matches the claimed residence, call the phone number, probe the resume in depth, and ask about "hometown, weather, or hobbies."
Is Latin America part of the North Korean IT worker problem?
Not in the government documents. The July alert does not mention Latin America. The only reference I found is from DTEX, a private security firm, as paraphrased by NBC News in September 2026: "Nigeria, Pakistan, India and parts of Latin America are also being targeted to assist in the scheme for facilitator recruitment." That's about recruiting facilitators who lend identities or host laptops, not where the workers sit.
I place LATAM engineers with US startups, so weigh my take accordingly. The scheme borrows real identities, so a candidate in Bogota gets the same checks as one in Ohio. A location confirmed at three points is what counts.
A screening process built from the alerts
| Stage | What to check | Which alert flag it catches |
|---|---|---|
| Application | Same phone or email reused across resumes; rate far below market | Jan 2025 FBI PSA; Jul 2026 alert |
| Live interview | Camera on, unscripted follow-ups, eyes reading another screen, background voices, freezes | Sep 2026 alert |
| Identity | Name on ID matches the person on video and the payment account | Jul 2026 alert |
| Before the laptop ships | Shipping address matches the ID; no late address change | 2022 State/Treasury/FBI guidance; May 2024 PSA |
| First invoice | Paid to an account in the worker's own name; no crypto, no third party | Jul 2026 alert |
| First 60 days | Remote desktop tools on company devices; same person on every call | May 2024 PSA |
The 2022 guidance says to be "particularly suspicious if a developer claims they cannot receive items at the address on their identification documentation." Most schemes surface at the laptop.
Why this belongs before the contract
First, the damage after hire. The FBI's January 2025 PSA says some workers, once discovered, held "stolen proprietary data and code hostage until the companies meet ransom demands," and copied GitHub repos to personal accounts.
Second, sanctions. The 2022 guidance warns of possible "sanctions designation" for anyone "processing related financial transactions," and says violations of the North Korea Sanctions Regulations can bring civil penalties "up to the greater of the applicable statutory maximum penalty or twice the value of the underlying transaction." The July alert adds that paying these workers "may also violate the domestic laws of many countries, including Japan, the United States, and the Republic of Korea." Enforcement is real, too: in May 2026 the DOJ announced its 7th and 8th laptop-farmer sentences in five months. This is general information, not legal advice; if you think you've paid one, call a sanctions lawyer and report it to the FBI at ic3.gov.
A Concrete Version
Say you're a 30-person Series A hiring a senior backend engineer, fully remote. A contractor applies at $45 an hour when every other senior applicant from the same city and market asks $70 to $90. Strong resume, polished answers. Here's the run, alert flags in brackets:
1. Day 1, interview. Camera on. You ask about a bug they fixed in their last job, then three follow-ups on why. Their eyes drift left every time [Sep 2026: glances at another monitor]. You note it.
2. Day 3, second interviewer. Ask about their city and the weather lately [Sep 2026].
3. Day 5, identity. The ID matches the resume and the person on today's call.
4. Day 8, offer. They ask to be paid through a friend's account "for tax reasons" and to ship the laptop to another city [Jul 2026 + 2022 guidance]. Two independent flags.
You stop. Total time lost: about four hours of interviews, against a contractor with commit access and a payment you may not be allowed to make.
The Honest Counterpoint
These checks create false positives. Honest engineers have bad internet, shared apartments and second monitors with their notes on them. Treat any single flag as proof and you'll reject good people, disproportionately from countries with worse infrastructure. Count flags, don't react to one.
The checks also don't prove much on their own. A facilitator with a real US identity, a real US bank account and a laptop farm passes the address and payment checks by design. That's why the FBI tells companies to verify identity "during hiring, onboarding, and throughout the employment of any remote worker," not once.
And on what Ruzora does: every engineer we place passes an AI-led technical interview and a graded coding assessment; how we vet lists the further steps. Sol, our hiring agent, shows you blind profiles first; names come after the MSA, which is the right moment to run the identity, address and payment checks above. We do not run ID-document or liveness checks today. Proof-of-human interviews are on our roadmap. You should still run your own identity checks on anyone, including people we send. Our post on candidate identity verification covers how, and how to identify fake candidates covers candidate fraud more broadly.
Frequently Asked Questions
How do I know if I hired a North Korean IT worker?
Check payment and access: pay routed through someone else's account, a shipping address changed after the offer, remote desktop software, or a different person on calls at different times. If several appear, involve counsel and the FBI before confronting the worker.
Are North Korean IT workers only a problem for big companies?
No. The DOJ's June 2025 action described jobs at more than 100 US companies, many Fortune 500. Small teams with no security staff are easier to fool.
Does hiring through a staffing provider remove the risk?
It moves some of the work, not the risk. The FBI's May 2024 PSA tells employers to make sure third-party staffing firms run sound hiring practices, routinely audit them, and flag changes in address or payment platforms. Ask any provider which identity checks it runs, and when, in writing.
The Bottom Line
North Korean IT workers depend on nobody checking the person, the address and the bank account against each other. Put a check at each seam the 2026 alerts describe, and keep checking after the start date. To start from engineers who already passed a coding assessment and an AI-led technical interview, browse the vetted bench and run your own checks on top.
Roberto Espinoza is CEO of Ruzora, which helps US startups hire pre-vetted senior LATAM engineers, with a vetted shortlist in 72 hours. See available engineers.
