FBI finds North Korean IT worker inside federal agency
The breach pattern that's hit more than 100 private companies has now reached the government, and nobody's saying which agency or what was accessed.
TL;DR
FBI Deputy Assistant Director Todd Hemmen confirmed last week that the bureau identified a North Korean remote IT worker employed at an unnamed federal agency. The disclosure, made at a Digital Government Institute conference, marks the first public acknowledgment that the DPRK's yearslong fraudulent IT-worker campaign, which has targeted over 100 U.S. companies, has breached the federal workforce. The FBI declined to name the agency, the duration of the intrusion, or whether sensitive data was exfiltrated. Experts noted that contractor support roles often bypass the vetting required for direct federal employees, creating an access pathway the campaign appears to have exploited.
The FBI's confirmation that a North Korean remote IT worker infiltrated a federal agency is the inevitable next chapter in a story that's been unfolding in the private sector since at least 2022. What's striking isn't that it happened, it's that the bureau says it's "a little bit baffling" how the worker got through.
Hemmen's choice of words matters. He wasn't describing a sophisticated cyber intrusion. He was describing an agency's hiring process that, in his view, shouldn't have let this person through. That's a remarkable thing for a senior FBI official to say in public about another federal entity.
What the campaign looks like now
The Justice Department has been dismantling pieces of this scheme for over a year. The numbers are staggering: more than 136 U.S. victim companies, over $5 million in illicit revenue generated for the DPRK regime, at least 80 stolen U.S. identities used, laptop farms across 16 states. U.S.-based facilitators have been sentenced to prison terms of up to 108 months. The FBI and international partners issued a global alert on July 31 warning that the threat extends to governments, not just private firms.
And yet an agency (an agency the FBI won't name and whose process Hemmen says he doesn't understand) still hired one. The DPRK campaign has shown clear intent and capability to reach government systems. A Maryland man was sentenced last year for enabling a North Korean national in China to work on FAA software development contracts, with co-conspirators accessing "sensitive U.S. government systems." The FAA case was a warning. The current case is evidence the warning wasn't enough.
Monday for practitioners
For security teams at federal contractors and agencies, the operational takeaway is narrow and uncomfortable. The vector isn't a zero-day, it's a hiring pipeline that doesn't vet contract support staff to the standard their network access demands. Donald Blersch, a former senior government official now at Clearspeed, put it plainly: when support-role contractors aren't vetted comparably to the access they receive, "you're potentially hiring a Trojan horse." The fix isn't technical. It's procedural, and it's overdue.
Published ·Updated ·Deep Fathom