Announcing our $5M seed roundLearn more

Inside the daily life of a North Korean IT worker: the training pipeline, multiple identities, monthly quotas, laptop farms, and what it means for hiring.

A Day in the Life of a North Korean IT Worker

Jason Zoltak Jason Zoltak
8 minute read

Table of Contents

I spoke with an investigative journalist this past week at one of the most notable papers in the world who is actively following North Korean IT workers. We spent a lot of time talking about their day to day.

It got me thinking…most coverage of North Korean IT workers focuses on laptop farms, corporate infiltration, arrests, and dollar figures. Less attention is given to how the operation works day to day: who the workers are, how they are trained, how they manage several jobs, and how the money reaches the North Korean state.

This blog covers all of it.

The pipeline

North Korea identifies students with strong math and computer skills early and directs them into specialized technical programs. Many attend elite institutions such as Kim Chaek University of Technology and Kim Il-sung University, where they study software development, artificial intelligence, cryptography, and foreign languages.

By the time they are deployed, many have spent close to a decade in technical training. They are not simply taught how to deceive employers. They are trained engineers who can pass difficult interviews and perform real production work.

The exact size of the workforce is difficult to measure. However, A 2023 UN estimate placed the number of North Korean IT workers deployed overseas between 3,000 and 10,000.

Workers selected for overseas assignments are usually dispatched in teams. China and Russia remain the main locations, with smaller groups identified in countries including Lagos, Cambodia, Nigeria, Tanzania, Guinea, and Equatorial Guinea. The workers do not choose where they are sent.

Morning

A worker using the alias Koh gave one of the clearest public accounts of life inside the operation. Koh lived in a two-bedroom apartment in China with about ten other North Koreans. The space contained bunk beds, computers, and portraits of North Korean leaders.

Because the workers follow US business hours, their day often begins in the afternoon and ends near sunrise. Koh reported working up to 16 hours a day.

Before logging into an employer’s systems, each worker checks in with a team manager. The manager assigns jobs, coordinates meetings, enforces revenue targets, handles disciplinary issues, and reports to a state handler.

This coordination is necessary because a worker may hold several jobs under different identities. When two meetings overlap, the manager can assign another worker to cover one of the personas.

The workers are also closely monitored. Koh said his manager installed software to track browsing activity. Workers interviewed for human-rights reports have described constant surveillance, restricted movement, and limited opportunities to leave their shared accommodations alone.

Afternoon

The work itself is usually real software engineering that begins in the afternoon. These workers are not pretending to code. They can build applications, review code, fix production issues, and remain employed for months or years without attracting attention.

The widely reported KnowBe4 case, where a North Korean hire attempted to install malware after receiving a company laptop, is not the standard model. More often, the worker performs legitimate work while gaining access to source code, credentials, internal systems, and company data.

A typical shift might include a stand-up for one employer, sprint planning for another, and a code review for a third.

Holding multiple jobs is central to the operation. One person might appear as a backend engineer at one company, a DevOps lead at another, and a contractor at a third. Each identity has its own name, resume, location, communication style, and employment history.

The scale can go beyond two or three identities. The 2025 Multilateral Sanctions Monitoring Team report documented one North Korean IT worker who controlled at least 12 personas across Europe and the United States. The worker used fabricated references and additional fake identities to vouch for those personas during hiring.

AI has made this easier. In 2025, CrowdStrike saw North Korean-linked workers infiltrate more than 320 organizations during 12 months, a 220% year-over-year increase. They found that generative AI was being used throughout the process, from creating identities and applying for jobs to completing interviews and maintaining employment. And those are only cases observed by CrowdStrike, not the total global operation.

The quota

Each worker is expected to generate a set amount of revenue.

Koh said his monthly quota began at roughly $5,000 and rose to $8,000 during the pandemic as remote hiring created more opportunities. More recent government reporting places the standard target at approximately $10,000 per worker each month.

Some earn far more. The Multilateral Sanctions Monitoring Team found that high-performing workers can generate up to $100,000 in a month, although targets vary between teams and state organizations. The report estimated an average monthly income of roughly $10,000 for an overseas IT worker.

The worker keeps only a small portion; some of it goes to the managers, facilitators, affiliated agencies, and the organizations controlling the team. A large chunk, however, goes to the North Korean state, where US authorities say it helps fund the country’s weapons programs. US estimates put the operation’s 2024 revenue at around $800 million.

Workers who miss their quotas may lose their pay. Repeated failures can lead to public reprimands, additional work, or punishment.

Night

Before finishing, workers submit reports to their manager covering completed work, meetings, schedules across different identities, and progress toward the monthly target.

The reports allow the manager to track both job performance and revenue. A worker who falls behind may be required to continue working into the next shift.

Personal time is limited and usually spent inside the apartment. Koh described shared meals like packaged ramen, occasional foreign television, and short periods online after others had gone to sleep.

The internet was necessary for his work, but it also exposed him to information unavailable inside North Korea. Koh said that reading foreign reporting about the country eventually changed how he understood the regime and contributed to his decision to defect.

Sunday

Sunday is nominally a day off for workers who meet their targets.

Koh described occasional group runs, restaurant visits, and shopping trips. Even then, workers stayed together and remained under supervision.

He remembered buying a North Face jacket with his share of the income. It was a rare personal purchase inside a system where the state controlled where he lived, how he worked, and where most of his earnings went.

The laptop farm

The operation depends on making overseas workers appear to be inside the United States.

When a company hires a remote employee, it may ship a laptop to the address provided during onboarding. A North Korean worker operating from China or Russia cannot receive that device directly without exposing their actual location.

Instead, the laptop is sent to a US-based facilitator. That person receives it, installs remote-access software, keeps it connected, and sometimes manages payroll accounts or job-platform profiles. The worker then controls the laptop from overseas.

To the employer, the activity appears to come from a company-issued device connected through a domestic IP address. The FBI says facilitators may also attend interviews, create front businesses, open financial accounts, and reship company devices overseas.

The laptop farm is not a small edge case. In June 2025, the Justice Department announced searches of 21 suspected laptop-farm locations across 14 states. The FBI seized approximately 137 laptops. The broader operation also targeted 29 financial accounts and 21 fraudulent websites used to support the scheme.

One of the largest known operations was run by Christina Chapman from her home in Arizona. According to the Justice Department’s case against her:

  • North Korean workers obtained jobs at 309 US companies and two international companies.
  • Sixty-eight American identities were stolen or misused.
  • The operation generated more than $17.1 million.
  • More than 90 company laptops were found in Chapman’s home.
  • Chapman shipped another 49 devices overseas.

She was sentenced to 102 months in prison.

When the worker is discovered

Termination does not always end the risk.

The FBI has documented cases where North Korean IT workers copied private code repositories, stole proprietary data, retained company credentials, and demanded payment after being discovered.

Some threatened to publish source code or give sensitive information to a competitor. Others kept session cookies or account credentials that allowed them to reconnect after employment ended.

This is why the operation is no longer only a sanctions or payroll problem. A worker who is successfully hired receives legitimate access to company systems. The threat enters through onboarding rather than through a conventional network intrusion.

What this means for hiring

Every part of the system leads to the same place: a candidate entering a legitimate company’s hiring process.

From the employer’s perspective, the applicant may look like an ordinary remote engineer. The resume is polished, the interviews are convincing, the laptop appears to be in the United States, and the work gets done.

The operation is built to maintain that appearance at scale. Estimates place the deployed workforce at roughly 100,000 people, generating hundreds of millions of dollars each year. Some reporting suggests the operation grew by 220 percent within a 12-month period.

Companies that catch these workers early usually identify them before access is granted, while the person is still an applicant. Companies that miss them may not discover the fraud until months later, after salaries have been paid and company systems, code, and data have already been exposed.

This is our hiring market in 2026.

« Back to Blog