Monday, August 3, 2026

Policy & Regulation

US sentences two for running laptop farms for North Korean workers

Two Americans were sentenced to prison for operating "laptop farms" that helped North Korean IT workers infiltrate more than 100 U.S. companies and steal trade secrets.

US sentences two for running laptop farms for North Korean workers

On Wednesday, the U.S. Department of Justice announced the sentencing of Kejia Wang and Zhenxing Wang to prison for their roles in a fake IT worker scheme that placed North Korean remote IT workers in U.S. companies. Kejia Wang was sentenced to seven and a half years in prison, while Zhenxing Wang was sentenced to nine years in prison. The defendants operated laptop farms inside the U.S. to facilitate the fraudulent scheme. A laptop farm is an infrastructure setup that allows remote workers to connect to local laptops to appear as if they are working from a specific country. In this case, the setup enabled North Korean workers to bypass remote work security by appearing to be based in the U.S., ultimately allowing them to infiltrate more than 100 U.S. corporations.

The fraudulent scheme operated between 2021 and 2024 and netted North Korea around $5 million to fund its regime. The operation involved stealing the identities of more than 80 Americans to secure employment at U.S. firms. Once hired, the North Korean IT workers were able to steal trade secrets and source code from the U.S. companies. For their roles in facilitating the operation, Kejia Wang, Zhenxing Wang, and four other facilitators received nearly $700,000. John A. Eisenberg, the DOJ’s assistant attorney general for National Security, stated that “the ruse placed North Korean IT workers on the payrolls of unwitting U.S. companies and in U.S. computer systems, thereby harming our national security.”

The prosecution is part of a wider campaign by the U.S. government to disrupt North Korean state-sponsored fraud. The North Korean regime, led by Kim Jong-Un, relies on these IT worker schemes and cryptocurrency thefts—which amounted to more than $2 billion last year—to bypass sanctions and fund its weapons program. To combat these operations, the U.S. government is offering rewards of up to $5 million for information to counter these schemes. This reward program is specifically seeking details on nine individuals who allegedly worked with the defendants to facilitate the operations.

Why it matters

This case highlights the critical security risks for Western companies hiring remote talent, as state actors increasingly exploit remote work infrastructure to bypass sanctions and fund weapons programs.