Infiltrators on the payroll: the threat of fake North Korean IT workers and the exposure of Spanish organizations

AUTHOR: Álvaro RodríguezPublished by: International Sustainable Development Observatory (ISDO) Security and Intelligence Department | isdo.ch
Scope: Counterintelligence and Economic SecurityDOI: 10.5281/zenodo.23283922

Executive summary

North Korean IT workers are not independent freelancers. They belong to a state network that places operatives in remote jobs at foreign companies under false or stolen identities and channels their salaries to the agencies that fund the regime’s nuclear weapons and ballistic missile programs. What began as revenue fraud is now a layered threat. Whoever lands a job receives legitimate credentials and access to internal systems and, in some cases, the ability to steal intellectual property, extort the employer or support operations by other actors linked to the North Korean state.

The International Sustainable Development Observatory (ISDO) assesses the threat as of October 2026 through its Security and Intelligence Department and asks what it means for Spanish organizations. Its central thesis is that defense cannot rest on the cybersecurity team alone: it takes Human Resources, Security, Compliance, Legal Counsel and hiring managers working under one identity verification and insider risk model. For Spain, the report rates the risk as plausible and high-impact, although no public case has been verified, and argues that waiting for local evidence means discovering the problem too late.

Key findings at a glance

  • Official alert. On July 31, 2026, the U.S. Department of State and the FBI, with authorities from ten other countries, issued a joint alert on North Korean IT workers addressed to countries, companies and other entities, online platforms included.
  • Scale. CrowdStrike, a security vendor, detected more than 320 companies with operatives of the group it calls FAMOUS CHOLLIMA in the 12 months to June 2025, 220% more than the year before. That is a minimum threshold, and the report finds no reliable figure for active workers or for affected organizations in Europe.
  • Money. The Multilateral Sanctions Monitoring Team (MSMT) estimates that IT workers abroad earned between USD 350 million and USD 800 million in 2024. Its third report, published on September 16, 2026, puts the annual income of the wider North Korean workforce in at least 17 countries, non-IT sectors included, at USD 450 million to USD 800 million. The ranges cover different groups and cannot be added.
  • Facilitators. One convicted facilitator managed up to 871 intermediary identities and affected 40 U.S. companies, according to the U.S. Department of Justice. The sentence was 60 months in prison.
  • Spain. The sources document activity in Germany, Portugal and the United Kingdom and list no incident in Spain. Spain is also outside both the joint alert and the MSMT.

What are fake North Korean IT workers?

They are highly qualified technical professionals who look for remote work in web development, mobile applications, software and blockchain. Official documents often call them DPRK IT workers, after the Democratic People’s Republic of Korea. According to the MSMT, they belong to entities subordinate to UN-sanctioned bodies, among them the Reconnaissance General Bureau, the Ministry of Atomic Energy Industry, the Ministry of Defense and the Munitions Industry Department, and they remit roughly half of their income to the regime. They operate mainly from North Korea, China and Russia, and also from countries in Southeast Asia and Africa.

How do North Korean IT workers get hired and paid?

The report breaks the operating cycle into five phases: identity preparation, recruitment, onboarding, exploitation of access, and payment and laundering. The operative buys or builds an identity, applies in bulk on freelance platforms and increasingly relies on intermediaries to pass interviews, while generative AI produces résumés and translations. The laptop then arrives at an intermediary address, a so-called laptop farm, or the worker uses a personal device under a bring-your-own-device (BYOD) policy. Pay goes to third-party accounts, transfer services or cryptocurrency, with a commission for the intermediary.

A laptop farm is an address where a local facilitator receives corporate computers from deceived employers and lets operatives connect remotely, which hides their true location. Facilitators appear most often in court proceedings. In April 2026 two U.S. citizens were sentenced for running laptop farms with the stolen identities of more than 80 people, which generated more than USD 5 million for the regime, and in May 2026 two others received 18 months for hosting computers that benefited around 70 companies and generated USD 1.2 million.

For defenders, the scheme is a chain. The operative has to get through every phase, while the organization needs to break only one.

What changed in 2025 and 2026?

Generative AI lowered the cost of entry. CrowdStrike reports that FAMOUS CHOLLIMA used it at every stage of hiring and employment, from résumé writing to programming support and, according to the available data, real-time deepfake video in interviews. Grammatical errors and poor English no longer work as warning signs, and a video interview, on its own, no longer proves identity.

The motive has widened too. The Google Threat Intelligence Group (GTIG) found that since late October 2024 IT workers have stepped up extortion attempts and gone after larger organizations: once dismissed, they threatened to leak the employer’s sensitive data, source code included, or hand it to competitors. GTIG noted that the rise coincided with tougher judicial action in the United States and raised the possibility that this pressure is pushing the workers toward more aggressive tactics.

Activity has also moved toward Europe. In April 2025, GTIG documented more active operations there, linked to Germany, Portugal and the United Kingdom, and tied the shift to greater public awareness, Department of Justice indictments and the difficulty of verifying the right to work in the United States. It also found that since January 2025 workers have been operating in BYOD environments, where shipping addresses and software inventories leave no trace.

Governments reacted on July 31, 2026. The U.S. Department of State and the FBI, with authorities from Japan, South Korea, Australia, Canada, France, Germany, Italy, the Netherlands, New Zealand and the United Kingdom, issued the joint alert. It acknowledges that the workers integrate AI to conceal their identities, asks platforms to strengthen identity verification with strict document review and in-person interviews, recalls that UN Security Council Resolution 2397 requires member states to repatriate North Korean nationals who earn income in their jurisdiction, and warns that hiring and paying these workers may breach national law.

Why is this an intelligence problem, not only a cybersecurity one?

Because the actor works with valid credentials and, much of the time, does real work, purely technical tools see little that looks abnormal. The useful signals sit in different systems with different owners: selection (camera refusal, recycled application data), identity and access (locations and schedules incompatible with what was declared, remote access tools), payroll (an account holder who is not the contractor, requests to be paid in crypto-assets), procurement (opaque subcontracting, interchangeable staff) and development teams (unusual volumes of repository cloning).

No single owner sees the whole pattern, so the analytical value lies in correlation. The report’s organizational answer is an identity risk desk with authority to stop or condition a critical hire: a joint committee of HR, Security, Procurement, Finance, Legal and the data protection officer, under one accountable owner.

Dismissal does not close a case. Dismissed workers have tried to be rehired with references from their other identities, and extortion can follow, so indicators such as infrastructure, application patterns and payment accounts need to be retained, within data protection limits, and shared with the sector.

How exposed are Spanish organizations to North Korean IT workers?

The primary sources consulted document activity in Germany, Portugal and the United Kingdom, plus a general expansion toward Europe, and they contain no list of incidents in Spain. The report therefore treats Spanish exposure as a risk analysis and not as a documented fact. That absence does not mean the risk is absent: the operating model rests on global hiring platforms, distributed teams, video-based selection and international payments, none of which depends on the country.

Spain also sits outside both the joint alert and the MSMT, while four EU member states, France, Germany, Italy and the Netherlands, belong to both. Spanish organizations therefore do not receive the same institutional early-warning signal.

The report lists six exposure factors: remote hiring and freelance platforms, BYOD and virtualized access, strategic sectors such as defense, aerospace, energy and transport, blockchain and fintech, supply chain and subcontracting, and AI translation tools that remove the language barrier. It develops four hypothetical scenarios, none of them a documented incident: a subcontracted developer, a position at a tier-2 defense or infrastructure supplier, extortion after dismissal and re-infiltration. By the analyst’s qualitative judgment, the first three rank as high priority and the last as medium.

The most distinctive conclusion concerns the entry route. The report infers, with medium-low confidence, that the likeliest vector in Spain is a third party, a freelancer or a supplier’s staff member, and not a direct employee. A Spanish employment contract requires a NIF or NIE tax identification number, Social Security registration, tax withholdings and, as a rule, a bank account in the SEPA area. Those frictions disappear or can be outsourced in freelance work and subcontracting. The inference is not documented in primary sources and should be tested against real cases when they exist.

What should organizations do about North Korean IT workers?

The report proposes nine recommendations in three blocks and states that there is no need to wait for NIS2 to be transposed into Spanish law in order to start.

  • Governance, within weeks and with little investment: one accountable owner of employment identity risk, an inventory of critical positions, verification proportionate to each position and control of payments.
  • Device, access and supplier controls: managed corporate devices without BYOD for sensitive roles, least privilege with gradual access, and contract clauses and due diligence for suppliers and freelancers. These close the routes most profitable for the attacker.
  • Detection, response and sector cooperation: correlation of signals from selection, access, payroll and suppliers, a five-phase response protocol tested in an annual exercise, and sharing of indicators, not personal data, through CERTs: INCIBE-CERT for the private sector, CCN-CERT for the public sector and ESPDEF-CERT for defense. These take longer but reduce residual risk and prevent re-infiltration.

Payment control is among the cheapest measures and, in the report’s assessment, has one of the best impact-to-cost ratios: pay only to an account whose holder matches the contracted person or entity. Identity checks scale with the position, in three levels, and in-person verification, direct or through a trusted third party, is reserved for the most critical roles, because AI can imitate an image but cannot replace a physical person.

No single warning sign should block a candidate. The report proposes grouping signals into three families, identity, conduct and money, and triggering reinforced verification by someone other than the person who selected or manages the candidate when signals coincide across two families or three appear within one, which it labels an analyst judgment and not an official rule. Screening by nationality, language or surname is ruled out: operatives claim third-country nationalities, so it fails, and it would discriminate against legitimate candidates. A suspected case should not be confronted. The advice is to preserve evidence, restrict access discreetly and involve Legal Counsel and the data protection officer, bearing in mind the GDPR’s 72-hour window to notify the supervisory authority of a personal data breach that poses a risk to individuals.

On compliance, the report asks organizations to add the risk to their sanctions compliance assessment and NIS2 readiness plans and to document the verification process as evidence of reasonable diligence. Screening names against sanctions lists is necessary but insufficient, because the identities these operatives use are false or stolen and do not appear on them. The EU sanctions framework is Council Regulation (EU) 2017/1509.

Controls will not remove the risk. An actor with a solid local facilitator and a high-quality stolen identity can still get past remote checks. The realistic goal is to raise the cost of entry, shorten detection time and limit the damage a malicious identity can do.

What does the evidence support, and what does it not?

The report separates what the sources state from what the analyst concludes. Confidence is high that the threat is active and adapting, that generative AI lowers the cost of fabricating credible identities, and that local facilitators are the weakest link and the one with the most convictions. It is medium that Spanish organizations have been or will be targeted by the same operating model, and medium that real infiltrations far exceed what is publicly documented. Vendor figures are labeled as such, probabilities and priorities are qualitative judgments, and the report says all of it should be reviewed if a first case is confirmed in Spain.

Scroll to Top