North Korea using foreign talent to help infiltrate US companies: Report
North Korea is reportedly using remote IT workers based in third countries, including Iran and Lebanon, to pass job interviews at U.S. companies and then transfer those roles to North Korean operatives. U.S. and allied agencies warned in July that such hires can be used to funnel pay to North Korean agencies and to carry out data theft and cryptocurrency theft.

Why It Matters
The tactic creates an insider access pathway that can facilitate large-scale financial theft and data exfiltration while helping North Korea circumvent sanctions to fund state programs. Independent cybersecurity reporting and government alerts link these methods to substantial cryptocurrency losses and continued North Korean economic resilience.
Key Facts
- Publication date: September 12, 2026
- Reporting outlet: NBC (reported), summarized by Cointelegraph
- Third countries named: Iran and Lebanon
- July alert: Issued by the US government and several foreign agencies warning about DPRK IT worker activity
- Recruiting method: Scouting on LinkedIn; hiring third-country IT workers as 'interview associates'
U.S. and allied officials say North Korea has shifted to using remote workers in third countries to gain footholds inside foreign firms and help move money back to state entities. NBC reported that the Democratic People’s Republic of Korea has recruited IT contractors based in places such as Iran and Lebanon to pass job interviews at companies abroad; after positions are secured, they are often turned over to North Korean operatives.
According to the reporting, recruiters have scouted candidates on LinkedIn and offered part-time roles described as "interview associates," with some recruits reportedly paid around $500 per month in cryptocurrency. The arrangement is presented as a way to obtain legitimate contracts or employment relationships that can later be exploited by DPRK personnel.
A government alert issued in July by the U.S. and several foreign agencies warned that North Korean IT workers pursue contracts while sending salaries back to their home agencies. The advisory said these individuals can present insider risks and have been linked to activities including data exfiltration, cryptocurrency theft, and the theft of sensitive information.
Cybersecurity firms and reporting suggest the tactics may be effective. CrowdStrike told Cointelegraph that North Korea–linked hackers were tied to more than $2 billion in cryptocurrency losses in 2025, a 51% year-on-year increase, and the Bank of Korea estimates the country’s GDP rose about 3.5% in 2025 despite international sanctions. Analysts say those losses and the government alert underscore the evolving and increasingly sophisticated methods used to generate revenue and access target networks.
Keep Reading

Revolut confirms customer data breach through fake government requests

Anthropic CEO outlines plan to ‘pace the frontier’

Nvidia considers $10B investment in potential record Anthropic IPO: Reuters
