North Korea's Fake-Employee Scheme Now Recruits Workers From Iran and Lebanon
What began as a North Korean operation to sneak remote workers into U.S. tech companies has grown into a multinational scheme, with recruits now drawn from Iran and Lebanon.

Key points
- U.S. Government agencies and foreign partners have confirmed North Korea's fake-worker programme now includes recruits from Iran and Lebanon.
- The scheme places foreign nationals as remote employees inside American companies to generate revenue and, in some cases, steal data.
- Multiple cybersecurity researchers corroborate the expansion, first reported by NBC News.
- No single regulator has sole jurisdiction: the FBI, the Treasury Department's OFAC (Office of Foreign Assets Control, which enforces U.S. Sanctions), and allied intelligence agencies all have a stake.
North Korea has spent years quietly placing fake remote workers inside American companies. Recruits use stolen or fabricated identities to get hired, then funnel their salaries back to Pyongyang. Now, according to U.S. Government agencies, foreign partners, and cybersecurity researchers, that operation has expanded: workers are being recruited from Iran and Lebanon.
The mechanics are straightforward. A person applies for a remote job, typically in software development or IT support, using a false identity. Once hired, the salary flows back to North Korean state coffers. In some cases, the workers have also stolen company data or planted malicious code during their tenure.
How did North Korea end up recruiting people from Iran and Lebanon?
Pyongyang appears to be casting a wider net, presumably because scrutiny of North Korean nationals has tightened. Using recruits from other countries makes the operation harder to detect. Iran and Lebanon are not close U.S. Allies, which limits practical options for law-enforcement cooperation when a case is identified.
It also signals that the infrastructure behind the scheme, cover identities, payment channels, coaching on how to pass job interviews, is mature enough to onboard workers from different countries and languages. Our story on 31 August 2026, "North Korea's Fake Worker Scheme Now Reaches Into Hospitals and Sales Teams", found the same apparatus already moving beyond tech into healthcare and sales roles.
Should hiring managers be worried?
Yes, and this is where the story lands in the real world. Any company that hires remote workers, particularly in technical roles, is a potential target. Polished CVs, confident video interviews run through face-altering software, and references that check out because they are also fabricated: none of these alone trips an alarm.
The FBI has warned that these workers sometimes use laptop farms, where a hired local person physically operates a laptop on their behalf in the target country, so the IP address (the numerical label identifying a device's internet connection) looks domestic.
This isn't a niche espionage problem. It's a jobs-market fraud that ordinary HR teams are expected to catch, without adequate tools to do so. That's the part regulators haven't fully reckoned with yet.
What companies and job applicants should watch for
Hiring teams should apply additional verification to fully remote candidates for sensitive technical roles. A candidate who resists turning on their camera, or whose face appears oddly smooth or static on video, warrants closer scrutiny. Gaps between a candidate's spoken language skills and their written application deserve a follow-up.
For employees working alongside remote colleagues, someone evasive about their location, keeping unusual hours without explanation, or requesting access beyond their job description is worth flagging to your security team.
Companies that discover they have unknowingly employed one of these workers should contact the FBI and consult sanctions lawyers before taking any action. OFAC rules mean that even an unwitting salary payment to a sanctioned party can carry legal consequences.



