Business

WFH in DPRK

The North Koreans sneaking into American coding jobs

Propaganda poster showing North Korean students using computers
Propaganda poster showing North Korean students using computers (Getty Images)

How a daring and sophisticated fraud operation got North Koreans working US tech jobs

A federal indictment says a modest Arizona ranch home operated as a hub of illicit finance for one of the country’s most dangerous enemies.

The Phoenix suburb of Litchfield Park seems an unlikely backdrop for international intrigue. You’d never find Jason Bourne screeching through its sun-banked subdivisions and golf courses in a vintage BMW, though a Club Car could present interesting possibilities.

But in a federal indictment unsealed last month, prosecutors said a modest cocoa-colored ranch home — minutes from the Wigwam Golf Club — operated as a hub of illicit finance for a ballistic-missile program run by one of America’s most dangerous enemies.

Christina Chapman Residence
Image from the November 2023 search warrant issued by the United States District Court for the District of Arizona.

Since November 2016, after the US imposed sanctions restricting North Korea’s access to the American financial system, the isolated totalitarian state has pioneered a range of shadowy online efforts to get the hard currency needed to fund weapons programs critical to Kim Jong Un’s regime.

It’s a broad portfolio of tactics encompassing everything from high-profile crypto heists and crippling ransomware attacks — North Korea’s state hackers are thought to be behind the 2017 WannaCry attack, for example — to one-off ATM scams and poker sites embedded with malware. Business has been good. In 2022, the UN estimated that North Korea took in between $600 million and $1 billion through its crypto-related capers alone. Other estimates suggest that the regime could gain as much as $5 to $7 billion a year through online crimes, which often feature remarkable feats of engineering and hacking. 

Less well known, though, is an unglamorous program in which North Koreans with a passable amount of IT training simply work freelance for Western companies, collecting paychecks in exchange for carrying out the nameless nuts-and-bolts labor of the internet, like web and app development, database creation and animation. 

The US government estimates that thousands of North Koreans, based mostly in China and Russia, are part of the effort, which has expanded with the rise of remote work.

“That definitely enabled this operation to become bigger than it was,” Alex O’Neill said. He’s an analyst who’s studied North Korean cyber operations and recently published a report on the topic for the Royal United Services Institute, a UK defense and security think tank. “So many people are doing remote work now, and also so many people are contracting out work that previously — call it 5 years ago or 10 years ago — you couldn't really contract out. It just made it a lot easier for the North Koreans to get a foothold.”

In May 2022, the US government issued an advisory warning businesses against inadvertently hiring North Koreans and laying out some of the techniques of online subterfuge that help them elude detection. Last year the FBI published updated guidance on such techniques.  

“The North Koreans rely on facilitators. There is no Bank of America in Pyongyang.”

These ruses involve using fake documents purchased off the dark web, private networks and servers, third-party IP addresses, and proxy accounts. There tends to be one significant snag in these operations: the difficulty of getting paid and channeling that money home. Almost all the proceeds are claimed by the North Korean regime, which remains severed from the global financial system.  

“The North Koreans rely on facilitators,” O’Neill said of the complicated and costly networks of humans the regime depends on to handle its financial transactions. “There is no Bank of America in Pyongyang.” 

In a May federal indictment laying out charges of fraud, money laundering, and conspiracy, the Justice Department said that Christina Marie Chapman, a 49-year-old woman recently living in Litchfield Park had been one of these facilitators. The indictment alleges that she carried out the grunt work that make such schemes work, from validating stolen IDs and faking tax documents to receiving and setting up corporate laptops, depositing paychecks, and transferring money overseas.  

“The conspiracy perpetrated a staggering fraud on a multitude of industries,” the indictment said, involving the identities of 60 Americans and interactions with 300 companies, including an unnamed television network, “a premier Silicon Valley technology company,” an aerospace and defense firm, and “one of the most recognizable media and entertainment companies in the world.” A separate application for a search warrant of Chapman’s residence sought information related to Fisker Automotive, MassMutual, Rocket Mortgage, NBCUniversal Media, and Hyatt Hotels, among other companies. The scheme generated some $6.8 million in revenue, Federal prosecutors said. 

Chapman was arrested on May 15 and entered a plea of not guilty. She is in Arizona awaiting an August court date. Repeated efforts to reach her and her attorney for comment were unsuccessful. The government alleges that Chapman operated a “laptop farm,” using her residence to host the corporate laptops that companies sent to workers they believed were in the US.  

As laid out in the indictment, it amounted to an incredibly irritating, and ultimately legal perilous, set of administrative tasks, with Chapman accused of receiving, unpacking, and setting up computers. The documents say she labeled them with the corresponding fake identity of the worker, juggled passwords and login information, and installed software — particularly the remote-worker software AnyDesk. Prosecutors said she relayed dozens of computers from US companies overseas, mostly to the Chinese city of Dandong, just across the Yalu River from North Korea. 

“If they ask WHY you are using two devices, just say the microphone on your laptop doesn’t work right.”

At times, the government says, Chapman was called on in real time to maintain the illusion that the workers were who they said they were. In November 2022, after setting up a computer for a North Korean worker known as “AT,” she fielded a frantic message, the indictment said.

AT: Anydesk is not available, I think it’s probably screen lock issue. Could you please remove anydesk and install it again? … And please unlock screensaver…

AT: Hi, please help me, it’s very urgent. I have to meet team in 30 mins.

The next year, prosecutors said, the same worker — this time under the stolen US identity “Daniel B.” — apparently was under pressure again.

AT: We are going to have laptop setup meeting in 20 mins. Can you join Teams meeting and follow what IT guy say? Because it will require to restart laptop multiple times... 

CHAPMAN: Who do I say I am? 

AT: You don’t have to say, I will be joining there too. 

CHAPMAN: It’s going to have my name on it, right? 

AT: You just mute and listen, then follow what she instruct, she may ask you to restart laptop. …

CHAPMAN: I just typed in the name Daniel. If they ask WHY you are using two devices, just say the microphone on your laptop doesn’t work right. 

AT: Ok

CHAPMAN: Most IT people are fine with that explanation. 

On one occasion, the government said, Chapman was asked to retrieve a physical security badge at what’s described as a “Fortune 500 aerospace and defense manufacturer.” The indictment says Chapman responded that she would send one of her assistants, but added, “They don’t know that you guys use ‘borrowed identities.’” Chapman then asked the IT worker she was corresponding with whether they were indeed “Ryan F.,” the identity on the physical badge. After the worker said no, Chapman replied: “So it’s a stolen identity… and you’re asking me to have my assistant handle something that is illegal,” the indictment said.  

The indictment also says Chapman charged for such services, with IT workers sending nearly $180,000 in payments between November 2021 to October 2023. Numerous individual payments were labeled as “development work,” “service fee,” or “web design.” 

According to the government, Chapman was a cog in a much larger scheme, centered on a website they said was operated by 27-year-old Ukrainian Oleksandr Didenko. He was arrested last month in Poland and is facing extradition. 

The Department of Justice said Didenko’s site connected foreign workers seeking remote work at US companies with fake identities and access to US laptop farms to make it appear that they were in the US. The US says Didenko coordinated with other laptop farms in San Diego, Jefferson City, Tennessee, and Virginia Beach, according to an unsealed indictment against the Ukrainian. 

Amid an investigation of the organization, Chapman’s Litchfield Park address surfaced several times, attracting the attention of the FBI.

The bureau reported that in May 2023, a computer shipped to Chapman’s Arizona residence from an insurance company — a remote worker had claimed it was their parents’ home, where they were recovering from surgery — triggered concern after a suspicious internet-service provider based in the Seychelles, in Africa, tried to log in. The company’s security blocked the connection and turned on the computer’s camera, “capturing a screen shot of Chapman.”

Christina Marie Chapman
An image of Christina Marie Chapman, taken from the search warrant issued for her Litchfield Park, Ariz., home. (USDC for the District of Arizona.)

In an application for a search warrant for the premises, agent Cody Rehrer noted a June 6, 2023 post on TikTok, which appeared to be taken at the house. 

“The TikTok video appears to be taken on a cellular phone, based on the movement of the camera during the video,” the affidavit said. “The video appears to show roughly more than ten laptops that appear to be running.” 

By last October, Rehrer was surveilling the house.

While the North Korean remote-worker program appears to be a relatively small piece of the cybercrime revenue the regime relies on, the size of the pie has been growing.

Last year, Anne Neuberger, deputy national-security adviser for cyber and emerging technology, said that roughly half of North Korea’s ballistic-missiles program was funded by cybercrime and crypto theft. 

Even if they’re not the most remunerative cyber ops, North Korean IT workers still present a security threat to Americans and companies, analysts and officials said.

That’s because these workers have been known to probe vulnerabilities once they gain access to the IT systems of companies, looking for opportunities to steal data, worker information, and intellectual property, as well as code-in back doors to allow future access. It’s even thought that the relatively low-level IT workers can pass along their access to more sophisticated hacking operations run by the regime. 

But such exploits seems to be the exception more than the rule, O’Neill said.

“What appears to be much more common is they just do some freelance IT work,” he said.  

More Business

See all Business
business
Tom Jones

Prime Day is here again and Amazon’s subscription service has never been more popular

Well, it’s that time of year again: many have made their wish lists, people are scraping together the money they’ve saved to pick out a perfect gift, some are presumably leaving out refreshments for the weary delivery drivers and, more and more, drones.

It’s Amazon Prime Day — meaning that it’s the second day of the four-day promotional event that Amazon still calls Prime Day — of course, and it’s even come early this year, with the company bringing the period into late June from July, when it’s been traditionally held for the last five years.

The Prime Age

Alongside the eyes and endless clicks that the arbitrary stream of listicles on “The Best Prime Day Deals” that almost every media outlet pours into, Amazon will also be cheering the fact that there’s now more Prime users than ever before to devour the retailer and its sellers’ sometimes-contested “discounts.” Indeed, according to the latest annual estimates from Consumer Intelligence Research Partners (CIRP), there were just over 200 million American shoppers using Amazon’s massive subscription service at the end of 2025.

business

Electronic Arts launches a platform to put more ads in its games

Video game publishing giant EA launched a new platform on Monday designed to make the process of selling immersive ad space in its popular games easier.

The company says the platform, called EA Advertising, allows brands to “integrate directly into gameplay through dynamic, real-time placements, from stadium signage to custom in-game content.”

More so than other studios, EA has incorporated advertising into its most popular titles. As Kotaku points out, the company’s ad efforts stretch as far back as 2006. Several of its sports franchises already feature partnerships with brands like Visa, Lowe’s, Red Bull, and PepsiCo.

In-game advertising hasn’t exactly been embraced by fans, but industry experts expect it to ramp up as companies seek more revenue to offset higher games budgets and surging memory costs. EA rival Take-Two has taken a different approach, with CEO Strauss Zelnick recently saying the company was “not at risk of doing brand partnerships” in the forthcoming “Grand Theft Auto VI,” and that ads in full-price games seems “unfair.”

The $55 billion deal to take EA private, led by Saudi Arabia’s Public Investment Fund, is set to close at the end of this month. Being the largest leveraged buyout in history, EA will likely look for more ways to boost revenue to cover interest payments.

More so than other studios, EA has incorporated advertising into its most popular titles. As Kotaku points out, the company’s ad efforts stretch as far back as 2006. Several of its sports franchises already feature partnerships with brands like Visa, Lowe’s, Red Bull, and PepsiCo.

In-game advertising hasn’t exactly been embraced by fans, but industry experts expect it to ramp up as companies seek more revenue to offset higher games budgets and surging memory costs. EA rival Take-Two has taken a different approach, with CEO Strauss Zelnick recently saying the company was “not at risk of doing brand partnerships” in the forthcoming “Grand Theft Auto VI,” and that ads in full-price games seems “unfair.”

The $55 billion deal to take EA private, led by Saudi Arabia’s Public Investment Fund, is set to close at the end of this month. Being the largest leveraged buyout in history, EA will likely look for more ways to boost revenue to cover interest payments.

business

JM Smucker says it sold $1 billion worth of Uncrustables in FY2026

After years of booming sandwich sales, JM Smucker has finally earned a billion-dollar crust.

On Tuesday, the company reported results for fiscal year 2026, highlighting better-than-expected profits driven by higher prices for coffee and sweet baked goods. However, at another point on the earnings call, CEO Mark Smucker pointed to one particularly jammy figure: in line with previous forecasts, the company sold $1 billion worth of its (almost always) crustless sandwiches, Uncrustables, in the last year alone.

business

Paramount reportedly offers concessions to resolve multistate antitrust investigation

Paramount has reportedly offered up some concessions in an effort to prevent an antitrust lawsuit by California and about 10 other states, according to Bloomberg reporting on Monday.

Reuters first reported on the potential suit from a group of unnamed states last week, which could throw a wrench in Paramount’s plans to buy rival Warner Bros. Discovery in a Hollywood megamerger.

The list of concessions is unknown, though Bloomberg previously reported that Paramount is open to divesting some of its kids TV assets to appease EU regulators.

Late last month, reports said US regulators appeared likely to approve the $110 billion merger, following a meeting between Paramount CEO David Ellison and DOJ antitrust staffers.

The list of concessions is unknown, though Bloomberg previously reported that Paramount is open to divesting some of its kids TV assets to appease EU regulators.

Late last month, reports said US regulators appeared likely to approve the $110 billion merger, following a meeting between Paramount CEO David Ellison and DOJ antitrust staffers.

$98B ⛽

The IATA released its latest financial outlook for the airline industry over the weekend, forecasting a $98 billion jump in the sector’s collective fuel bill. The world’s largest trade group representing airlines expects the oil spike to halve profits by 49% from last year to $23 billion.

The group also expects profit margins to halve year over year, falling from 2025’s 4.2% to 2%. Still, revenue is expected to climb to $1.17 trillion from $1.07 trillion.

A surge in the cost of jet fuel has rocked US and global airlines this year, leading Delta Air Lines, United Airlines, American Airlines, Southwest Airlines, JetBlue, and others to raise fares and ancillary charges like bag fees. Low-cost carriers, which operate on smaller margins, have been squeezed the hardest, resulting in Spirit’s shutdown.

“It’s a tough year for all airlines, especially those whose balance sheets had not yet recovered from COVID. And, of course, for those operating in the Gulf,” said IATA Director General Willie Walsh, who added that demand is holding up and about half of passengers expect to spend more on travel this year. “That bodes well for a strong northern summer peak season. The big unknown is how long travelers and shippers can tolerate the higher costs of connectivity.”

Latest Stories

Sherwood Media, LLC and Chartr Limited produce fresh and unique perspectives on topical financial news and are fully owned subsidiaries of Robinhood Markets, Inc., and any views expressed here do not necessarily reflect the views of any other Robinhood affiliate, including Robinhood Markets, Inc., Robinhood Financial LLC, Robinhood Securities, LLC, Robinhood Crypto, LLC, Robinhood Money, LLC, Robinhood U.K. Ltd, Robinhood Derivatives, LLC, Robinhood Gold, LLC, Robinhood Asset Management, LLC, Robinhood Credit, Inc., Robinhood Ventures DE, LLC and, where applicable, its managed investment vehicles.