WASHINGTON – The person who got inside was not a hacker. There was no zero-day exploit, no phishing chain, no spoofed credential that penetrated a layer of government security from the outside. The employee applied for a remote IT position at a US federal agency, passed whatever vetting the agency used, received system access, and went to work. The salary they earned went to Pyongyang.
The FBI confirmed this month that it is investigating the case of a North Korean national who was hired for a remote IT job at an unnamed US federal government agency, a disclosure made by a senior Bureau official at a conference in Washington on July 28 and first reported by TechCrunch. The agency involved has not been identified publicly. The Bureau declined to comment further when contacted by TechCrunch on Tuesday. Whether the worker accessed classified systems, exfiltrated data, or what specifically triggered the investigation has not been disclosed.
The fact of the penetration, not its details, is what the disclosure establishes: North Korea’s sprawling remote-work infiltration program, previously understood primarily as a private-sector problem, has now reached inside a US government institution.
The program is extensive. Cybersecurity researchers and US officials have for several years described a system in which thousands of North Korean nationals work remotely at Western companies under fabricated identities, earning wages funneled in violation of international sanctions directly to the Kim regime in Pyongyang. The workers take IT positions requiring no physical presence, cycle through stolen identities, and in some cases operate laptop farms: rigs of dozens of machines managed through VPNs to mask the geographic origin of their work. Cases involving private employers have typically resulted in corporate embarrassment and, in some instances, extortion attempts when the operative’s cover was blown.
Early this month, eleven governments issued a joint advisory warning that North Korean IT workers have added real-time AI deepfakes to their methods, deploying them during video hiring interviews specifically to defeat the identity-verification checks companies had introduced to counter the scheme, Tech Times reported on August 2. The advisory represented the most explicit multinational acknowledgment yet that the program has adapted to circumvent practical countermeasures.
North Korea’s response came quickly. State media called the Western cybersecurity coordination effort a “ghost mechanism” and Pyongyang formally rejected the advisory’s findings, framing the multinational response as another iteration of a hostile containment campaign rather than a legitimate security concern.
The government case changes the texture of the threat in ways the private-sector disclosures have not. North Korea’s missile unit deployment to Russia and its accelerating military expansion have commanded the bulk of Western security attention toward Pyongyang in 2026, with Beijing, Moscow, and Pyongyang condemning Japan’s defense paper as reinvasion-minded just last week. The IT worker case arrives from a different direction: not Pyongyang’s conventional military posture, but its economic intelligence infrastructure, now confirmed to be operating inside a system its operatives were not supposed to be able to reach.
The case moves qualitatively beyond what earlier US government cases involved. A Maryland man was charged with helping a North Korean hacker gain remote access to the Federal Aviation Administration through facilitation, TechCrunch reported: a scheme built on external intrusion with an inside enabler. The agency case involves something different: a North Korean operative who cleared the government’s own hiring process and arrived with authorized access to federal IT systems, without a known co-conspirator.
What the case also does not explain is how the operative maintained cover through the vetting process. US federal agencies use background checks more rigorous than most private employers. Whether the North Korean worker used the AI deepfake methods described in the August 2 advisory, exploited gaps in how remote hires are verified for identity, or deployed a different approach entirely has not been disclosed by the Bureau. That question has implications beyond this specific case: if North Korean operatives can navigate the US government’s hiring process, the methodological gap it represents matters across agencies, not just the one under investigation.
The EU and UK’s coordinated sanctions against Russian state hackers in July illustrated Western governments’ growing willingness to treat state-sponsored cyber activity as a sanctionable offense. North Korea’s IT worker program sits in a different legal category: the workers, when they are not exfiltrating data, are performing legitimate labor, billing real hours, delivering real output. The line between sanctions evasion, economic espionage, and ordinary employment, when conducted under a false identity inside a federal institution, is a legal question the US government has not fully resolved.
What is clear is that the FBI is investigating, that an agency was penetrated, and that the specific details, including which agency, for how long, and what was accessed, remain undisclosed. The Bureau’s silence on the substance of the case is its own signal. The investigation is active.

