Canada, allies warn North Korea IT staff pose ‘insider threat’ abroad – National

Canada and 10 of its closest allies issued a warning Friday that North Korean IT staff pose an “insider threat” by remotely obtaining work and income abroad to fund the rogue regime’s nuclear and ballistic weapons programs.

The joint advisory says the distant employee scheme is an element of a broader effort to evade international sanctions, and urged countries and firms to “deepen their understanding” of the tactics used and implement measures to counter them.

It adds North Korea “has increased connectivity with the international economic system through diversified revenue generation activities, including IT employee schemes,” despite those sanctions and efforts to strengthen them.

Global Affairs Canada and the RCMP were joined by foreign affairs departments and police forces from its Five Eyes partners Australia, Recent Zealand, the U.S. and the U.K., together with South Korea, Japan, France, Italy, Germany and the Netherlands.

Story continues below commercial


Click to play video: 'North Korea says it would never give up nuclear weapons, pushes ahead with artillery'


North Korea says it will never quit nuclear weapons, pushes ahead with artillery


In accordance with the advisory, North Korean IT staff will falsify their nationality or identity to register for online accounts and seek employment.

The employees are “increasingly likely” to make use of third-party proxies to create those accounts on their behalf, in addition to take part in job interviews “and even establish in-person contact to create a false sense of trust and acquire work contracts,” the advisory adds.

Get breaking Canada news delivered to your inbox as it happens so you won't miss a trending story.

Get breaking National news

Get breaking Canada news delivered to your inbox because it happens so you will not miss a trending story.

“North Korean IT staff employ increasingly sophisticated methods, including the combination of AI, to obfuscate their identities and expand their activities globally,” it says.

“These staff hunt down contracts with the intent of remitting their salaries to their parent North Korean agencies. Additionally they pose an insider threat to firms and are involved in data exfiltration, cryptocurrency theft, and theft of sensitive information.”

Once employed, the North Korean IT staff will often try to avoid being paid by direct deposit and as a substitute request payment through either money transfer or cryptocurrency. The advisory says third-party bank accounts are sometimes used to receive payments, that are then transferred by a proxy to a chosen foreign account for a fee.

Story continues below commercial

The advisory notes the employees have “high-level” IT skills and are searching for work in wider areas, including web page and mobile app development, software and blockchain services.


Click to play video: 'North Korea has stolen US$1.2B through hacking since 2017: Park Jin'


North Korea has stolen US$1.2B through hacking since 2017: Park Jin


It adds that North Korean IT staff can also use VPNs and other software tools to hide their true location or run “laptop farms” that receive company-provided laptops for staff to access remotely. Staff often reside in North Korea, China, Russia, and Southeast Asian and African countries.


Last yr, an American woman pleaded guilty to federal charges and was sentenced to eight and a half years in prison for operating a “laptop farm” on behalf of North Korean IT staff, which U.S. prosecutors said generated over US$17 million in illicit revenue over quite a few years.

Officials within the U.S., Canada, South Korea, Japan and other allies have been warning concerning the North Korean IT employee scheme since a minimum of 2022. Friday’s advisory points to several warnings issued last yr alone, with the scheme detailed in reports by the UN-mandated Multilateral Sanctions Monitoring Team and the G7’s Financial Motion Task Force.

Story continues below commercial

Corporations with online platforms are advised to be looking out for the next characteristics, particularly if several of them apply to a single employee searching for employment:

  • Frequent changes to account information, contact details and banking info;
  • Mismatched names on an applicant’s checking account;
  • Multiple accounts created with the identical ID document;
  • The looks of forged or altered ID documents;
  • Multiple accounts registered from a single IP address;
  • A single account accessed from multiple IP addresses in a brief time frame;
  • An account stays logged in for an “unusually long” time period;
  • Unnaturally high cumulative work hours or related metrics; and
  • False reviews posted by a user to spice up their account’s rating.

Human resources and hiring departments are also advised to look at for these warning signs:

  • Errors or “unnatural expressions” in an account profile “that seem like the results of inaccurate machine translation”;
  • Manipulated or artificially generated video feeds, photo ID mismatches and other discrepancies during video conference meetings;
  • Refusal to take part in video conference meetings;
  • Offers to work at below-market rates;
  • Signs that an account is being operated by multiple individuals depending on the time of day; and
  • Requests for payment in cryptocurrency.

The advisory adds that North Korean IT staff participating in a distant work scheme often operate in teams.

It notes that UN member states are required to repatriate any North Korean nationals earning income in that country’s jurisdiction.

Story continues below commercial

“Moreover, contracting with North Korean IT staff and paying them for services rendered can also violate the domestic laws of many countries, including Japan, america, and the Republic of Korea, and will lead to legal consequences or financial penalties,” the advisory says.

&copy 2026 Global News, a division of Corus Entertainment Inc.

Related Post

Leave a Reply