Treasury/OFAC sanctioned North Korean Ministry of National Defense and Munitions Industry Department front companies in Laos, China.
Social Engineering Examples·6 sources
On January 16, 2025, the U.S. Treasury's Office of Foreign Assets Control (OFAC) sanctioned Department 53 (a weapons-trading entity subordinate to the DPRK Ministry of National Defense/Ministry of the People's Armed Forces), two front trading companies (Korea Osong Shipping Co. and Chonsurim Trading Corp.), Liaoning China Trade Industry Co. (a Chinese hardware supplier), and individuals Jong In Chol and Son Kyong Sik, for facilitating a scheme in which North Korean IT workers used falsified identification credentials to obtain remote employment at companies worldwide, with delegations based in Laos since at least 2021-2022. On July 24, 2025, OFAC designated a second network: Korea Sobaeksu Trading Co. (Sobaeksu United Corp.), a front for the DPRK Munitions Industry Department, plus individuals Kim Se Un, Jo Kyong Hun, and Myong Chol Min, for sending DPRK IT-worker teams to countries including Vietnam under the same fraudulent-identity playbook.
The same week, the FBI issued a public service announcement (July 23, 2025) detailing the tradecraft, and DOJ announced the sentencing of Arizona-based facilitator Christina Chapman to 102 months in prison for running a domestic "laptop farm" that let DPRK IT workers pose as U.S.-based remote employees at 309 U.S. companies and 2 international businesses, generating more than $17 million using 68 stolen American identities.
Treasury and DOJ describe the two halves (foreign front companies and networks; domestic facilitators) as complementary parts of a single DPRK state revenue-generation scheme that funds the regime's weapons, nuclear, and ballistic-missile programs.
DPRK IT workers, operating from North Korea and forward-deployed locations including Laos, China, and Vietnam under front companies linked to the DPRK Ministry of National Defense (via Department 53, subordinate to the Ministry of the People's Armed Forces) and the Munitions Industry Department (via Korea Sobaeksu Trading Co.), obtained remote IT/software jobs at legitimate companies worldwide using stolen or purchased identities and forged/falsified identification documents.
They built false personas, pseudonymous email/social-media/job-platform accounts, and in some cases used AI face-swapping or filters during video interviews to mask their true appearance and location. To make it appear they were working from inside the target country (mainly the U.S.), they recruited or paid U.S.-based facilitators to run "laptop farms": facilitators received company-issued laptops at their own homes, installed KVM (keyboard-video-mouse) switches and remote-desktop/VPN software so the North Korean workers could operate the machines remotely while appearing to log in from a U.S. residential IP, handled the resulting paychecks (often via direct deposit or crypto), and in some cases shipped laptops overseas.
Front trading companies (Korea Osong Shipping, Chonsurim Trading, Liaoning China Trade Industry, Sobaeksu United) provided logistics, hardware (computers, GPUs, HDMI/network equipment), and financial conduits, funneling the workers' withheld wages back to the regime to fund weapons and nuclear/ballistic-missile programs.
The lure was a seemingly ordinary, qualified remote IT/software-engineering job candidate: a plausible resume, a US-based (often stolen) identity and Social Security number, normal-looking video-interview performance (sometimes aided by AI face-altering), and legitimate-looking background-check results because the underlying identity documents were real but stolen.
The tell, when investigators and companies eventually caught it, was cross-case pattern-matching: many "different" remote hires' company laptops were being shipped to or run from the same residential address (Chapman's home, with 90+ laptops eventually seized there); KVM devices allowing remote parties to control a workstation from overseas while it appeared to be logged in domestically; repeated use of the same small set of stolen identities across many employers; payroll deposits routed to accounts controlled by the facilitator rather than the named employee; and inconsistent work-hour/timezone patterns typical of DPRK-based operators.
OFAC designated Department 53, Korea Osong Shipping Co., Chonsurim Trading Corp., Liaoning China Trade Industry Co., and individuals Jong In Chol and Son Kyong Sik on January 16, 2025; and Korea Sobaeksu Trading Co. (Sobaeksu United Corp.) plus individuals Kim Se Un, Jo Kyong Hun, and Myong Chol Min on July 24, 2025, blocking their U.S.-linked assets and barring U.S. persons from dealing with them.
In parallel, DOJ's June 30, 2025 coordinated nationwide actions and the July 24, 2025 sentencing of Christina Chapman (102 months in federal prison) exposed the domestic facilitation side: Chapman admitted to helping DPRK IT workers obtain remote jobs at 309 U.S. companies and 2 international businesses using 68 stolen identities, hosting laptops at her home, and shipping devices overseas; more than 90 laptops were seized.
The State Department also offered rewards up to $3 million for two individuals tied to the Sobaeksu network. Sanctions and prosecutions are ongoing; the scheme's overseas nodes (China, Laos, Vietnam) remain largely outside U.S. law-enforcement reach.
This is a documented case of state-sponsored synthetic-identity fraud operating at industrial scale: a nation-state (not a lone criminal) systematically fabricated remote-worker personas, backed by real stolen identity documents, AI-assisted interview evasion, and physical infrastructure (laptop farms, KVM devices) to make foreign operatives indistinguishable from legitimate domestic remote hires.
It demonstrates that remote-hiring pipelines are now a national-security attack surface, both for direct financial fraud (wages diverted to a sanctioned weapons program) and for potential follow-on espionage or insider access once the fake employee is inside a company's network, and that standard hiring diligence (resume, video interview, background check) can be systematically defeated when the underlying identity itself is stolen rather than merely misrepresented.
Rigorous identity verification for remote hires (notarized ID checks, live biometric verification beyond a single video call), shipping-address/geolocation checks on company-issued equipment to catch "laptop farms," monitoring for anomalous remote-access patterns (KVM switches, always-on VPN from unexpected residential IPs), scrutiny of payroll direct-deposit and money-transfer-service anomalies, background-check rigor including cross-referencing SSNs/identity documents against known-compromised identity databases, OFAC/SDN screening of contractor and staffing intermediaries, and HR/security coordination on multiple-devices-same-address or same-bank-account red flags across candidates.
Social Engineering Examples. “OFAC Sanctions DPRK Ministry of National Defense Front Companies Behind Fake-Persona Remote IT-Worker Fraud”. Accessed 19 September 2026. https://socialengineeringexamples.com/dprk-it-worker-front-company-ofac-sanctions-2025
DPRK IT-worker operations typically begin by acquiring or purchasing stolen or borrowed U.S. persons' identity documents (Social Security numbers, IDs) and building supporting personas, resumes, and job-platform/social-media accounts, consistent with DOJ's description of the Chapman scheme using 68 stolen American identities and the FBI's guidance on facilitators creating job-search-site accounts on the workers' behalf.
stolen-identity documents are hard to distinguish from genuine ones at the application stage because the underlying SSNs and IDs are real; the practical control is rigorous background-check cross-referencing against known-compromised-identity databases and notarized or in-person identity verification before an offer is extended, rather than trusting document appearance alone.
operators typically recruit or pay U.S.-based (or China-, UAE-, or Taiwan-based) collaborators, witting or unwitting, to act as facilitators, per the FBI's July 2025 PSA and DOJ's June 2025 coordinated-actions announcement describing facilitators who receive devices, set up front businesses, and attend interviews on the workers' behalf.
facilitator recruitment happens outside the employer's visibility (gig networks, encrypted channels), so it is not directly defensible at the employer level; the nearest practical control sits at Stage 4, where shipping-address and equipment-geolocation checks expose a facilitator once a company laptop is actually dispatched.
fake personas apply en masse to remote IT/software roles, using AI-generated or AI-polished resumes and, per FBI guidance and independent security research, real-time AI face-swapping or filters during video interviews to defeat visual identity checks.
FBI-recommended interview countermeasures, such as requiring unobscured video, asking candidates to point the camera out a window and describe their surroundings, and asking them to wave a hand in front of their face (which disrupts real-time deepfake/face-swap rendering), can catch AI-manipulated video during the interview itself.
once hired, the employer-issued laptop is shipped to the facilitator's residential address (a "laptop farm"), where the facilitator installs KVM switches and remote-desktop/VPN software so the DPRK worker can operate the machine from overseas while appearing to log in from a domestic residential IP, per DOJ and FBI descriptions of Chapman's and other facilitators' operations.
requiring that company equipment only ship to the address on file in verified identity documents, monitoring for KVM-switch or unauthorized remote-desktop software installation, and flagging logins from residential IP ranges inconsistent with the claimed employee's location directly targets the laptop-farm infrastructure.
the DPRK worker performs the job, in some documented cases swapping the person behind a single persona, while paychecks are routed via direct deposit, crypto, or facilitator-controlled bank accounts, consistent with DOJ's description of Chapman receiving and forging payroll checks in stolen identities' names.
ongoing verification during employment, periodic re-capture and comparison of employee photos or video, and monitoring for behavioral or timezone inconsistencies can catch worker-swapping and non-local work patterns after hire.
facilitators and front trading companies (Korea Osong Shipping, Chonsurim Trading, Liaoning China Trade Industry, Sobaeksu United) move proceeds through shell companies, currency conversion, and hardware trans-shipment to obscure the funds' origin and route them back to DPRK-controlled entities, per Treasury's designation rationale and DOJ's money-laundering charges against Chapman.
payroll and banking anomaly detection, such as flagging multiple "different" employees who share a bank account, routing number, or facilitator-controlled deposit account, plus financial institutions' standard AML/KYC monitoring of rapid international transfers, targets the laundering step directly.
the DPRK government withholds up to 90% of the wages according to Treasury, funneling the proceeds, an estimated hundreds of millions of dollars annually across the wider program, to the Ministry of National Defense/Department 53 and the Munitions Industry Department to fund weapons, nuclear, and ballistic-missile programs.
OFAC/SDN sanctions designations and asset-blocking, the Treasury actions this case documents, are the systemic backstop, cutting the named front companies and individuals off from the U.S. financial system once earlier controls fail, though enforcement reach is limited for actors operating entirely outside U.S. jurisdiction in North Korea, Laos, China, and Vietnam.
Browse by what this case has in common with others in the library.
An unidentified impersonator used an AI-cloned voice and a hacked personal-contacts list to pose as White House Chief of Staff…
A Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew…
A Bengaluru retiree lost Rs 6.88 lakh after an AI-generated deepfake Facebook video falsely showed Finance Minister Nirmala Sitharaman endorsing…
A Lapsus$ affiliate bought a contractor's stolen Uber password, flooded them with MFA push prompts, then posed as Uber IT…
Fraudsters impersonating Ubiquiti's CEO and an outside law firm tricked its Hong Kong finance controller into wiring $46.7M abroad.
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
Google's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG).
The FBI's 2025 Internet Crime Report introduced its first dedicated AI-fraud tracking category, logging $893 million in losses.
Fraudsters impersonating FACC's CEO by email convinced finance staff to wire roughly EUR 50M for a fake acquisition project.
Noma Security researchers hid a multi-step prompt-injection payload inside a public Salesforce Web-to-Lead form's 42,000-character Description field.
A single cybercriminal used Anthropic's Claude Code as an autonomous operator to breach ~17 organizations and generate psychologically targeted.
Fugitive hacker Kevin Mitnick impersonated a vacationing Novell employee on a "top-secret" project.
A compromised email address was used to redirect a $30,750 solar-panel-installation payment from a Wheeling.
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
The FTC's first major consumer alert on QR-code scams (Dec 6, 2023) warned of fake QR stickers on parking meters…
A single phishing email opened by an Anthem subsidiary employee in Feb 2014 seeded a nation-state intrusion that stole data…
The FBI's 2025 Internet Crime Report introduced its first dedicated AI-fraud tracking category, logging $893 million in losses.
An Atlantic City woman posed as a life-insurance/retirement-benefit representative on burner-phone calls to recently widowed elderly victims.
Chinese state-linked hackers used spear-phishing links and an unpatched Internet Explorer zero-day to breach Google, Adobe.
Russia's Sandworm Team used spear-phishing emails with malicious Office macro attachments to plant BlackEnergy3 malware inside three Ukrainian power.
A single spear-phishing email titled "2011 Recruitment Plan," with a booby-trapped Excel attachment.
Russian GRU-linked Forest Blizzard (APT28/Fancy Bear) used OpenAI's GPT-4-family LLM services to research satellite communication protocols and radar.
Google's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG).
A nation-state cyberweapon crossed an air gap into Iran's Natanz nuclear facility on infected USB drives carried in by trusted…