Two New Jersey men ran US "laptop farms" and shell companies that let North Korean IT workers pose as American remote employees at 100+ US firms, generating over $5 million for the DPRK regime and enabling theft of ITAR-controlled defense data before both were sentenced to federal prison in April 2026.
Reviewed by the Social Engineering Examples team.
Kejia "Tony" Wang and Zhenxing "Danny" Wang, two US nationals based in New Jersey, ran a multi-year scheme (roughly 2021 to October 2024) that placed North Korean IT workers into remote jobs at more than 100 US companies by disguising them as ordinary US-based remote employees. The workers used stolen identities of over 80 real Americans to get hired, and the Wangs created shell companies (Hopana Tech LLC, Tony WKJ LLC, Independent Lab LLC) plus "laptop farms" at their own residences to host victim-company laptops and route remote access to the overseas workers via KVM hardware. The scheme generated more than $5 million for the DPRK government and caused victim companies at least $3 million in remediation costs; one victim, a California AI/defense contractor, had ITAR-controlled technical data stolen by an overseas co-conspirator in early 2024. DOJ unsealed charges in June 2025, both men pleaded guilty (September 2025 and January 2026), and both were sentenced to federal prison in April 2026.
From roughly 2021 to October 2024, North Korean IT workers and overseas co-conspirators (in China, the UAE, and Taiwan) used stolen and fabricated identities, compromising more than 80 real US persons, with fake driver's licenses and Social Security cards, to apply for and win remote IT jobs at over 100 US companies, including many Fortune 500 firms. Kejia "Tony" Wang served as the US-based manager, traveling to Shenyang and Dandong, China in 2023 to coordinate with overseas actors, including a North Korean former classmate, and supervising at least five US facilitators. Zhenxing "Danny" Wang was one of those facilitators. Once a fake candidate was hired, the victim company shipped a work laptop to a facilitator's US residence; the facilitators ran "laptop farms" of hundreds of hosted machines and connected each laptop to KVM (keyboard-video-mouse) switches or remote-desktop software, letting the real overseas worker operate it as if physically present in the US. The Wangs set up shell companies with matching websites and bank accounts, including Hopana Tech LLC, Tony WKJ LLC, and Independent Lab LLC, that had no real employees or operations but existed solely to receive victim-company wage payments and launder them onward to overseas co-conspirators. Separately, between January 19 and April 2, 2024, an overseas co-conspirator used this remote-access setup to break into the network of a California-based AI/defense contractor ("Company C" in court filings) and exfiltrate technical data marked as controlled under the International Traffic in Arms Regulations (ITAR).
The lure was a convincing "remote US-based IT professional" package: a stolen but real American identity (name, SSN, ID documents), a plausible resume, and a corporate laptop that authenticated and behaved as if it were sitting in a US facilitator's home, exactly what employers expect from a legitimate remote hire, especially post-pandemic when in-person verification norms had relaxed. The tell that eventually unraveled it was investigative and forensic rather than something the victim companies caught in real time: FBI/DCIS searches recovered more than 70 physical laptops and KVM devices from facilitator residences, seized 29 financial accounts and dozens of fraudulent domains tied to the shell companies, and traced wage payments from the Hopana Tech/Tony WKJ/Independent Lab accounts overseas. Publicly, the broader DPRK IT-worker campaign (documented by Microsoft, Unit 42, and other security researchers and incident-response firms) has been caught via secondary tells: device/network telemetry showing KVM or RMM software installed immediately after laptop provisioning, logins from Chinese/Russian IPs or Astrill VPN, workers who avoid camera use or fail unscripted personal questions, and shipping addresses that don't match the claimed identity.
Charges were unsealed June 27-30, 2025 in the District of Massachusetts: Zhenxing Wang was arrested and indicted on a five-count indictment alongside eight overseas co-defendants (Chinese nationals Jing Bin Huang, Baoyu Zhou, Tong Yuze, Yongzhe Xu, Ziyou Yuan, and Zhenbang Zhou, and Taiwanese nationals Mengting Liu and Enchia Liu, all still at large as of April 2026); Kejia Wang was charged separately by criminal information and had already agreed to plead guilty. Kejia Wang pleaded guilty in September 2025 to conspiracy to commit wire fraud, money laundering, and identity theft; Zhenxing Wang pleaded guilty in January 2026 to conspiracy to commit wire fraud and money laundering. On April 15, 2026, US District Judge Nathaniel M. Gorton sentenced Kejia Wang to 108 months and Zhenxing Wang to 92 months in prison, each with 3 years of supervised release, $600,000 in forfeiture ($400,000 already recovered), and $29,236.03 in restitution from Kejia Wang. The action was part of a coordinated nationwide DOJ/FBI/DCIS/HSI effort that also searched 29 suspected laptop farms across 16 states, seized 29 financial accounts, 21 fraudulent websites, and roughly 200 computers, and separately charged a North Korean scheme that stole ~$900,000 in virtual currency from an Atlanta blockchain firm.
This case is one of the most fully-documented US prosecutions showing how the DPRK's remote-IT-worker revenue scheme actually operates end to end: stolen identity plus a domestic laptop farm plus shell-company banking is enough to make a foreign, sanctioned operative look, to an employer's HR and IT systems, indistinguishable from a legitimate US remote hire. It matters for the deepfake/synthetic-identity education angle because it sits inside a documented wave of DPRK operations (per Microsoft, Unit 42, and CNN research on the same 2021-2024 timeframe) that increasingly layers AI-generated resumes, face-swapped ID photos, and even real-time deepfake video/voice on top of this same laptop-farm infrastructure, meaning organizations should assume identity verification, video interviews, and background checks can all be defeated simultaneously, and that the strongest signal is often behavioral/technical telemetry after hire (KVM/RMM installs, foreign IPs, VPN use) rather than anything visible during hiring itself. It also demonstrates concrete national-security fallout beyond fraud: theft of ITAR-controlled defense technology by workers who were never who they claimed to be.
DOJ/FBI guidance issued alongside the case (and echoed by Microsoft's Jasper Sleet research and Unit 42's False Face report on the same DPRK campaign) recommends: requiring cameras on for every interview round and flagging candidates who report chronic video/audio "technical issues"; using unexpected, personally-anchored questions (e.g., local/historical references) that scripted or AI-assisted personas struggle with; verifying identity documents against live biometric/liveness checks rather than static uploads; scrutinizing resumes/background-check submissions for name, address, and date inconsistencies across platforms; calling references by phone or video rather than relying on email; flagging laptop shipping addresses that don't match the verified identity address or that change post-offer; monitoring for corporate-issued laptops authenticating from foreign IPs, KVM/RMM software installed immediately after provisioning, or use of VPN services (e.g., Astrill) associated with DPRK IT-worker infrastructure; and treating remote-only IT hiring pipelines as a distinct fraud-risk surface requiring HR-security collaboration, not just a staffing convenience.
Binance CCO Patrick Hillmann claimed scammers built an AI deepfake "hologram" of him from his TV interview footage and used…
A Brighton-area kitchen fitter lost roughly £76,000, including four loans he was pressured into taking out, after a Facebook ad…
An attacker impersonated LastPass CEO Karim Toubba with an AI voice clone over WhatsApp, but the targeted employee spotted the…