U.S. Sentences ‘Laptop Farmers’ in Crackdown on North Korean IT Infiltration of Crypto Industry
North Korea has long deployed IT workers using stolen or false identities to apply for overseas remote jobs. U.S.-based accomplices receive company laptops on their behalf and install remote-access software, making the workers appear to be located in the United States. The scheme generates revenue for the sanctioned North Korean regime while giving its personnel access to corporate networks. Cryptocurrency companies are especially attractive targets because they hold readily transferable assets and operate critical infrastructure.
The U.S. Justice Department said on May 6, 2026, that Matthew Isaac Knoot and Erick Ntekereze Prince had each been sentenced to 18 months in prison. The two cases affected nearly 70 U.S. companies and generated more than $1.2 million for North Korea. Knoot was sentenced on May 1 and ordered to pay $15,100 in restitution and forfeit another $15,100. Prince was sentenced on May 6 and ordered to forfeit $89,000.
All Coverage
1 original reportsThe Backstory
The history behind this eventUS Treasury Sanctions North Korean IT Fraud Network and Crypto-Laundering Channels
North Korea has long dispatched IT workers overseas to apply remotely for technology jobs using false identities, stolen data belonging to U.S. residents and “laptop farms,” then remit most of their salaries to Pyongyang. Such operations target blockchain and cryptocurrency companies and may also involve planting malware and stealing confidential information. The proceeds are alleged to fund North Korea’s nuclear weapons and ballistic missile programs.
On March 12, 2026, the U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) sanctioned six individuals and two entities, saying the network generated nearly $800 million for North Korea in 2024. A Vietnam-based operator converted about $2.5 million in cryptocurrency between mid-2023 and mid-2025. On April 15, the U.S. Justice Department separately announced that two accomplices had been sentenced to 92 and 108 months in prison for helping infiltrate more than 100 companies and generate over $5 million in revenue.
North Korea Recruits Foreign IT Workers to Infiltrate US Firms
North Korea has long used false identities to place remote IT workers at overseas companies, diverting salaries to state-linked organizations to evade sanctions and finance its nuclear weapons and ballistic missile programs. The campaign is more than employment fraud: once hired, operatives can gain legitimate access to corporate systems, creating an insider threat that includes data exfiltration, theft of sensitive information and cryptocurrency losses.
NBC News reported on Sept. 11 that North Korean teams were recruiting IT workers in Iran, Lebanon and other third countries through LinkedIn to sit interviews under false identities before operatives took over the jobs. Threat-intelligence firm Flare said at least 14 Iranians had joined the operation since 2024 and two received formal offers from US employers. Some part-time “interview associates” were offered $500 a month in cryptocurrency. The US State Department, FBI and agencies from 10 partner countries issued a joint alert on July 31.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →