Financial Crime · North Korea / DPRK

The Code Is Real.
The Identity Is Fake.

How payment platforms are detecting and disrupting North Korea’s IT-worker networks.

The work is real. The code gets written. The tickets get closed. Only the identity is fake.

Most financial crime begins with a transaction that looks wrong. This threat can begin with a job that looks completely ordinary.

A developer applies for a remote role, passes a technical assessment, writes functioning code, closes tickets and receives a salary. The employer may be satisfied with the work. The payment may look entirely consistent with legitimate freelance activity.

Yet behind the apparently ordinary engagement may sit a false identity, a remote-access arrangement and a state-sponsored revenue operation. That is what makes North Korea’s IT-worker networks unusually difficult to detect—and why this is not simply a sanctions-screening problem.

The playbook

The broad mechanics are now well documented. The Democratic People’s Republic of Korea has dispatched skilled IT workers abroad, particularly to China and Russia, to obtain remote work from companies around the world. They use stolen or fabricated identities, aliases, front companies, false websites, freelance marketplaces and cross-border payment services to conceal who is actually performing the work.

Some networks rely on facilitators in the United States or elsewhere. Those facilitators may create accounts, establish front businesses, receive employer-issued laptops or make domestic internet connections available to workers operating overseas. The result can look convincing: a domestic identity, a local device and a plausible company—all telling the same false story.

The revenue matters because U.S. authorities say it supports North Korea’s weapons programs. The risk to an employer can extend far beyond an improper salary payment: recent cases have also involved alleged data theft, access to sensitive systems, cryptocurrency theft and extortion.

What the public record reveals

In 2018, the U.S. Treasury sanctioned China-based Yanbian Silverstar Network Technology and its Russia-based sister company, Volasys Silver Star, describing them as North Korea-controlled IT operations designed to generate revenue while obscuring the workers’ true nationality.

In October 2023, the U.S. Department of Justice announced the seizure of 17 website domains used by DPRK IT workers. The action followed earlier court-authorized seizures of approximately $1.5 million connected to the same group. Importantly, the announcement also credited information sharing with freelance and payment platforms, whose own investigations helped identify and close thousands of additional accounts.

By June 2025, the scale had become even clearer. The Justice Department announced coordinated actions across 16 states involving searches of 29 known or suspected laptop farms and seizures of 29 financial accounts, 21 fraudulent websites and approximately 200 computers. Court documents alleged that compromised identities had been used to obtain work at more than 100 U.S. companies.

At the same time, the threat was becoming more international. Google Threat Intelligence reported in 2025 that DPRK IT-worker activity was expanding into Europe and becoming more aggressive, including through extortion and the use of corporate virtualized infrastructure.

This is not a static typology. It is an operating model that learns.

Why conventional screening struggles

Traditional sanctions controls are essential, but they are not enough when the person presenting to the platform is using someone else’s identity and nothing in the transaction description says “state-sponsored revenue generation.”

The payment itself may be genuine compensation for genuine work. A name screen can therefore return no match, a transaction rule can see an ordinary salary and a customer-support interaction can appear routine. Each event may look harmless when examined alone.

The signal appears in the relationships: whether identity, location, device, access, payment behavior and account history continue to support the same story over time. Location, in this context, is not merely a field in a customer record. It is a relationship among many pieces of evidence.

That requires a different kind of compliance thinking. Instead of asking only whether a person matched a list at onboarding, institutions must also ask whether the identity remains coherent throughout the customer lifecycle.

Detection must be a living system

There is no single rule that solves this problem—and no control that remains sufficient forever.

When a new pattern emerges, the response has to extend beyond one alert or one account. It may mean strengthening identity assurance around higher-risk account events, widening the history considered by account-takeover detection, identifying clusters through shared signals and feeding confirmed outcomes back into the detection framework.

That work depends on compliance, fraud, cybersecurity, operations, data and legal teams seeing the same threat rather than treating it as six separate problems. A control that closes one pathway will prompt a determined actor to test another. The program must be able to observe, learn and change with it.

This is adaptive compliance in practical form: not abandoning rules, but surrounding them with continuous learning and governance capable of responding when yesterday’s assumptions stop being true.

Partnership changes the odds

No payment company, employer or government agency can solve a state-sponsored threat alone. The most meaningful disruptions have come from public-private partnership: platforms sharing what they see with law enforcement, and government partners sharing intelligence and known indicators back with industry.

The 2023 Justice Department action explicitly recognized this model. The FBI’s 2025 guidance similarly encouraged companies to build direct relationships with its private-sector coordinators. Internationally, the Multilateral Sanctions Monitoring Team was established in October 2024 after Russia’s veto ended the mandate of the UN Security Council’s Panel of Experts, preserving a mechanism for reporting on sanctions evasion.

The private sector often sees the first fragments of a network. Government may hold the context that explains what those fragments mean. Neither view is complete on its own; together, they can turn an isolated anomaly into a disruption.

Five questions for compliance leaders

  1. Do our controls test the continuing integrity of an identity after onboarding, especially when access or account details change?
  2. Can we connect signals across KYC, devices, account access, payments and customer-support events, or are those clues trapped in separate systems?
  3. Do sanctions, fraud, cybersecurity, workforce risk and legal teams review this threat together?
  4. How quickly can a confirmed pattern become a governed detection change?
  5. Do we have a trusted, tested route for sharing intelligence with law enforcement and relevant industry partners?

What comes next

North Korea will keep adapting. The encouraging part is that platforms and governments can adapt too.

The direction is already visible: stronger identity assurance, smarter behavioral and network analysis, faster feedback loops, better information sharing and clearer accountability for decisions supported by advanced analytics and AI.

Trust is not preserved by a perfect one-time check. It is preserved by an institution’s ability to notice when the story stops making sense—and to act before the inconsistency becomes a network.

For the payments industry, disrupting these schemes is not a compliance box to check. It is central to the trust customers place in the financial system and to keeping that system out of the hands of those who would exploit it.

Public sources

The factual chronology and public typologies referenced above were verified against public materials from the U.S. Department of the Treasury; the U.S. Department of Justice’s October 2023 and June 2025 actions; the FBI’s guidance on North Korean IT-worker threats to U.S. businesses; Google Threat Intelligence; and the Republic of Korea Ministry of Foreign Affairs’ materials on the Multilateral Sanctions Monitoring Team.

Continue the conversation. For speaking, media or advisory enquiries, contact Micheal.

Continue exploring

Global payments and connected financial-crime intelligence.

Related work on KYC, sanctions, payment transparency and emerging threats.

Global Payments & Financial Crime

Explore the complete collection across identity, transactions, networks and geopolitical risk.

Explore the theme →

Global Standards, Local Proof

Why global KYC should standardize outcomes while localizing evidence.

Read the KYC paper →

Transformation Case Studies

Public-safe operating lessons from KYC, transaction monitoring and sanctions modernization.

Explore case studies →