The FBI is looking into how a North Korean came to be employed by a United States federal agency. Federal News Network broke the story, citing a senior bureau official who spoke at a conference in Washington on 28 July and confirmed an inquiry into a North Korean working for an agency the report does not name.

How the hire happened is not known. What is known is the shape of the operation behind it. North Korea has run coordinated recruitment fraud against private companies and multinationals for years, and thousands of its IT workers are believed to have found jobs at organisations across the United States and Europe by exploiting soft points in hiring.

The mechanics are consistent. A fabricated identity wins a remote role; the salary is routed back to Pyongyang; intellectual property and internal data are taken along the way; and when the worker is eventually identified, the stolen material becomes leverage for extortion.

What makes this case unusual is where it landed. Vetting and security clearance have largely kept the scheme out of government, though not perfectly. Prosecutors charged a Maryland man in 2024 with helping a North Korean hacker present himself as an American in order to win remote contracting work at the aviation regulator.

Asked about the case on Tuesday, the FBI would not comment. Which agency was affected has not been disclosed, and whether any data or money left the building is likewise unknown.

None of this is a surprise to American authorities, who have been warning about it for years and have brought sanctions and enforcement actions against the networks operating out of Pyongyang and their extensions in Russia and China — as well as against the Americans who maintain the racks of laptops that let someone in North Korea appear to be sitting at a desk in the United States.

The reason the regime bothers is financial. Cut off from the banking system, it behaves less like a state than a transnational criminal organisation, funding a sanctioned nuclear weapons programme through theft. Blockchain forensics firms attribute 76% of all cryptocurrency stolen to the Kim Jong Un government, which took at least $2 billion during 2025 alone.

For anyone hiring remotely, the practical reading is unglamorous. Verifying who a candidate actually is belongs to security, not to onboarding paperwork — and treating it as paperwork is precisely why this keeps working.