The U.S. Justice Department has prosecuted one of the largest North Korean IT worker fraud schemes it has charged to date, involving an American woman, three North Korean nationals, and more than 300 US companies deceived into hiring workers who were never who they claimed to be. The case, resolved with a sentencing in July 2025, shows in granular detail how North Korea uses stolen American identities to fund its weapons programs through ordinary remote tech jobs.
Background of the Scheme
Christina Chapman, of Litchfield Park, Arizona, ran the operation from October 2020 to October 2023 alongside three North Korean nationals identified in court documents by the aliases Jiho Han, Haoran Xu, and Chunji Jin, all of whom remain at large. Chapman and her co-conspirators deceived more than 300 US companies into hiring North Korean IT workers who posed as American citizens using stolen identities.
The companies affected, none named directly in court filings, included a top-five television network, a Silicon Valley technology company, an aerospace manufacturer, an American car manufacturer, a luxury retail store, and a major media and entertainment company, several of them Fortune 500 corporations. The North Korean operatives also attempted to obtain remote positions with two US government agencies. The scheme ran through what prosecutors called laptop farms, arrangements where company-issued laptops were kept running at a US address so employers would see US-based network activity. At the same time, the actual work was done remotely from overseas.
The Mechanism of Fraud
Chapman used the stolen and purchased identities of 68 Americans to build employee profiles and credentials for the North Korean workers. She hosted at least 90 laptops at her home, connected remotely by the overseas workers, and shipped 49 additional company-issued devices overseas herself, including several to a Chinese city near the North Korean border. This setup let the workers appear to be logging in from inside the United States, bypassing the location checks companies rely on for remote hires. According to the Justice Department, the scheme generated more than 17 million dollars, funds that funded her own compensation and were funneled back to North Korea.
Legal Outcome
Chapman pleaded guilty in February 2025 to conspiracy to commit wire fraud, aggravated identity theft, and conspiracy to launder monetary instruments. She was sentenced on July 24, 2025, to 102 months in prison, just over eight and a half years, followed by three years of supervised release. She was ordered to forfeit $ 284,555.92 and pay an additional judgment of $ 176,850.
Chapman wasn't an isolated case. In a related scheme, Oleksandr Didenko, a Ukrainian national, was separately sentenced to five years in prison for running a similar identity-theft operation supporting North Korean IT workers, managing as many as 871 proxy identities and operating at least three US-based laptop farms of his own. Together, the two cases point to a broader pattern of North Korea relying on paid US and third-country collaborators to get its IT workers past employer verification checks at scale.
What Companies Should Take From This
The scale of this case, more than 300 companies including multiple Fortune 500 corporations, shows that employer verification processes widely in use were not sufficient to catch it. Companies hiring remote IT workers should tighten identity verification beyond document checks, monitor for signs of shared or rotating laptop locations, and treat unusually routine remote access patterns as worth a closer look rather than an automatic pass.
The same underlying problem, attackers exploiting the remote IT hiring process itself, shows up in a different form in the Lazarus Group's Sapphire Sleet campaign, which targets IT job seekers directly through fake skills assessment portals rather than working through a US-based intermediary. For more on that mechanism, see Kraken IO's feature, " Exploiting Aspirations: How the Lazarus Group's Sapphire Sleet Sub-Cluster Targets IT Job Sitters."
Sources
US Department of Justice, US Attorney's Office for the District of Columbia, "Arizona Woman Sentenced in $17M IT Worker Fraud Scheme That Illegally Generated Revenue for North Korea." justice.gov/usao-dc/pr/arizona-woman-sentenced-17m-it-worker-fraud-scheme-illegally-generated-revenue-north
US Department of Justice, US Attorney's Office for the District of Columbia, "Ukrainian Pleads Guilty in DC 'Laptop Farm' Scheme That Generated Income for North Korean IT Workers." justice.gov/usao-dc/pr/ukrainian-pleads-guilty-dc-laptop-farm-scheme-generated-income-north-korean-it-workers
NPR, "Arizona woman to serve 8 years for identity theft scheme benefiting North Korea." npr.org/2025/07/25/nx-s1-5479906/north-korea-identity-theft-sentencing
The Register, "Laptop farmer behind $17M North Korean IT worker scam locked up for 8.5 years." theregister.com/2025/07/24/laptop_farmer_north_korean_it_scam_sentenced