# North Korea's Secret U.S. IT Workforce Exposed _An investigation by The Wall Street Journal reveals how North Korean operatives are infiltrating U.S. companies, using stolen identities and AI to secure IT jobs and send millions back to the regime._ **Updated:** 2026-08-22 **Published:** 2026-08-15 **Source:** https://www.startuphub.ai/ai-news/artificial-intelligence/2026/north-korea-s-secret-u-s-it-workforce-exposed --- A sophisticated and extensive operation orchestrated by North Korea to infiltrate American companies and generate revenue has been revealed. The Wall Street Journal's documentary "The North Korean Operatives Hiding Inside U.S. Companies" details how thousands of high-skilled IT workers, dispatched by their government, are using stolen identities and fabricated resumes to secure positions in U.S. firms. These operatives are estimated to be funneling around $800 million per year back to Kim Jong-Un's regime, with recent estimates suggesting the money helps fund North Korea's nuclear program. NK Infiltrates US ITDriverthousands of high-skilled IT workers dispatched by their government secure positionsFrom the articleA sophisticated and extensive operation orchestrated by North Korea to infiltrate American companies and generate revenue has been revealed.Stolen Identities & AICoreoperatives use fabricated resumes, stolen identities, and AI to secure jobsFrom the article 5 mentionsCompanies" details how thousands of high-skilled IT workers, dispatched by their government, are using stolen identities and fabricated resumes to secure positions in U.S. firms.NK AdaptabilityContextNorth Korea demonstrates sophisticated and extensive operation to generate revenueFacilitators & NetworksContextfacilitators coordinate efforts through private Discord servers, crafting resumesFrom the article 2 mentionsA critical component of the scheme involves U.S. persons acting as facilitators.Millions Funneled BackEffectFrom the article 2 mentionsThese operatives are estimated to be funneling around $800 million per year back to Kim Jong-Un's regime, with recent estimates suggesting the money helps fund North Korea's nuclear program.EagleVision OperationCoreFrom the article 2 mentionsThe investigation, based on a trove of hacked data, mapped out the operations of a team codenamed "EagleVision." This team, led by a figure using the codename EagleVision, consists of multiple individuals posing as tech workers under various fake or stolen identities.Funds Nuclear ProgramOutcomeFrom the articleThese operatives are estimated to be funneling around $800 million per year back to Kim Jong-Un's regime, with recent estimates suggesting the money helps fund North Korea's nuclear program. ## The "EagleVision" Operation The investigation, based on a trove of hacked data, mapped out the operations of a team codenamed "EagleVision." This team, led by a figure using the codename EagleVision, consists of multiple individuals posing as tech workers under various fake or stolen identities. They coordinate their efforts through private Discord servers, meticulously crafting resumes and cover letters for numerous applicant aliases. Their preparation for interviews includes extensive homework, such as looking up how to pronounce their cover names. ## Exploiting Remote Work and AI The global shift towards remote work, exacerbated by the COVID-19 pandemic, presented a significant opportunity for North Korea. The operatives are exploiting the fact that physical presence is often not required, making it easier to misrepresent their identities. Furthermore, they are actively using AI tools like ChatGPT to help answer interview questions, demonstrating a significant advancement in their methods. ## The Role of Facilitators and Stolen Identities A critical component of the scheme involves U.S. persons acting as facilitators. These individuals, sometimes knowingly and sometimes unwittingly, enable the IT workers to set up company laptops, attend meetings, and open bank accounts. The investigation uncovered that personal identities are being sold on platforms like Telegram, with North Korea developing strategies to steal identities at scale. Documents found on computers of other North Korean IT worker cells offer guidance on acquiring stolen identities and using government websites like e-Verify to pass background checks. ## Widespread Infiltration and Financial Networks The report indicates that these IT workers are not only targeting tech companies but also governments, defense contractors, and banking institutions. The money earned, estimated to be up to 90% of their income in some cases, is funneled back to North Korea through a complex network involving foreign bank accounts, couriers, cryptocurrency transactions, and money launderers. Cybersecurity researchers have traced some of these payments to Ryonbong, a company sanctioned by the U.S. for its role in Pyongyang's weapons program. ## North Korea's Adaptability and Innovation The investigation highlights North Korea's remarkable innovation and relentless hustle in finding ways to generate revenue amidst long-standing sanctions. From early cyberattacks like the Sony hack to pivoting towards cryptocurrency hacking after the Bank of Bangladesh heist, North Korea has consistently demonstrated its creativity in adapting to global financial systems. The current IT worker scheme represents another evolution, showcasing their ability to exploit new opportunities presented by the digital age. --- Original analysis from [startuphub.ai](https://www.startuphub.ai), the #1 AI startup directory. © StartupHub.ai. All rights reserved. You may not republish this article in full without a license. Search engines and AI research tools may crawl and summarize for reference. Bulk reproduction or model training on this content requires a license. See https://www.startuphub.ai/terms.