Washington: The U.S. Federal Bureau of Investigation (FBI) is conducting an investigation into how a North Korean remote information technology (IT) worker managed to secure employment with a U.S. federal agency. This development highlights the increasing risks associated with North Korea's IT worker scheme impacting the U.S. government sector.
According to Yonhap News Agency, Todd Hemmen, deputy assistant director of the FBI's Cyber Capabilities Branch, disclosed at a forum last month that the FBI recently identified a North Korean remote IT staffer employed by the U.S. federal government. Hemmen's remarks came in response to inquiries about the impact of North Korea's IT worker scheme on the U.S. government.
"Still kind of unpacking that recent case. It's actually a little bit baffling to me, not understanding this particular agency's process," Hemmen remarked during the July 28 forum hosted by the Digital Government Institute in Washington. "But the short answer is yes, we are seeing remote IT workers not just in the private sector -- although a vastly higher proportion (are) in the private sector -- but we're also seeing this impact the government to a degree," he added.
The FBI official did not provide further details, leaving questions about which U.S. government agency was affected and whether any sensitive information was compromised. This revelation comes as Washington, Seoul, Tokyo, and other countries intensify efforts to block North Korea's IT worker schemes, believed to generate revenue for the regime's nuclear and other weapons of mass destruction programs.
North Korean IT workers are reportedly deployed both within and outside of North Korea, acquiring jobs through false identities and fraudulent methods, thereby remotely earning income to support Pyongyang's weapons programs. The report notes that the recent IT worker incident is not without precedent.
Last year, a Maryland man received a 15-month prison sentence for facilitating a North Korean national in China to work on software development contracts for the Federal Aviation Administration. Furthermore, late last month, South Korea, the U.S., Japan, and eight other countries issued a joint alert about North Korean IT workers, citing their involvement in data exfiltration, cryptocurrency theft, and the theft of sensitive information as insider threats to companies.