North Korea Runs Its Largest Export Business Through American Payroll

Rows of open corporate laptops on metal shelving in an American suburban home office, each screen showing an active remote desktop session

A yearlong Wall Street Journal investigation traced one cell that applied to more than 1,000 US companies in three months. The product ships as a direct deposit, files no customs entry, and costs Pyongyang more in American middlemen than it pays its own engineers.

North Korea’s fraudulent remote IT worker scheme generated close to $800 million in 2024, according to the US Treasury. The country’s entire merchandise export book that year came to $360 million. Pyongyang built a business that out-earns everything it legally ships abroad, and routed it through a channel no trade-compliance officer inspects: the payroll run.

A shelf of laptops in a suburban garage

Investigators who searched Christina Chapman’s house in Litchfield Park, Arizona, in October 2023 found more than 90 corporate laptops on racks. Each one carried a sticky note naming the company that shipped it and the stolen American identity attached to it. Chapman had spent three years plugging them in, keeping them online, and forwarding wages. She kept $176,850. The operation moved more than $17 million.

On August 13, 2026, the Journal published the results of a year spent inside that machine, built from leaked browser histories, emails, calendars and screen recordings pulled off the operators’ own computers. The documentary is called “Infiltrated: North Korea’s Secret U.S. Workforce.”

What happened

The Journal followed a single North Korean cell that submitted applications to more than 1,000 companies in a little over three months and landed jobs at a minimum of eight. AI wrote the resumes and the cover letters. Screen recordings caught applicants reading machine-generated answers during live interviews. As recruiters got better at spotting the tell, some operators started testing face-swapping software.

The physical problem is the laptop. An employer ships hardware to a new hire, and a package addressed to Pyongyang ends the game. So the operation rents Americans. Facilitators take delivery of the machines, install remote-access software, open bank accounts, move payments, and in some cases show up on camera. One man in Ohio told the Journal he sits in company meetings while North Korean engineers do the work. On a job paying $75,000 a year, he and the workers split the salary down the middle.

The identity side leaves wreckage. The Journal spoke to a man in Georgia whose personal information was advertised for sale and then used to hold jobs around the country. He can no longer open a bank account, borrow money, or rent a home.

The backstory

The FBI, the State Department and Treasury issued their first joint advisory on North Korean IT workers in May 2022, followed by updated guidance with South Korea in October 2023 and again from the FBI in May 2024. Enforcement has been running ever since, and it keeps landing on Americans rather than North Koreans.

Chapman drew 102 months in July 2025 after prosecutors tied her to jobs at 309 US businesses and two foreign ones, using 68 stolen identities. She forfeited $284,555.92 earmarked for Pyongyang and shipped 49 devices overseas, several to a Chinese city on the North Korean border. In June 2025 the Justice Department searched 29 laptop farms across 16 states, seizing roughly 200 computers, 29 financial accounts and 21 websites tied to work at more than 100 companies. In May 2026 two more facilitators, Matthew Isaac Knoot and Erick Ntekereze Prince, each received 18 months.

Treasury has been putting numbers on the top of the funnel. In January 2025 it estimated the regime withholds as much as 90% of an overseas worker’s wages, and that individual workers can clear more than $300,000 a year. On March 12, 2026, the Office of Foreign Assets Control sanctioned six people and two entities, including the North Korean firm Amnokgang Technology Development Company and a Vietnamese services company run by Nguyen Quang Viet, and put the 2024 revenue figure at nearly $800 million. One facilitator in that network converted about $2.5 million into cryptocurrency between mid-2023 and mid-2025. The chain ran through North Korea, Vietnam, Laos and Spain.

The business model angle

Treat this as a trade story and it reads differently.

Bar chart comparing North Korea's estimated 2024 IT worker scheme revenue of $800 million against $360 million of total merchandise exports, a 2.2x gap

KOTRA, the South Korean trade agency that tracks the North’s commerce, put 2024 merchandise exports at $360.4 million and 2025 exports at $468.6 million. In 2025 the largest single export category was wigs and false eyelashes, at 43.9% of the total. Against that, an $800 million labor-fraud channel is not a side hustle. It is the main line.

Sanctions are a border instrument. They work on things that clear customs, where an importer of record files an entry, a commodity carries a code, and a compliance officer signs off. Pyongyang moved its biggest export to a channel with none of that furniture. The good arrives as a Slack login and gets paid through ACH by an accounts-payable clerk who has never heard the phrase “importer of record” and never needs to. Trade enforcement finds money by following documents. This transaction generates none.

Now price the operation. On the Ohio job, $37,500 of a $75,000 salary goes to the American front. Of the $37,500 that reaches the other side, the regime keeps up to 90%, leaving roughly $33,750 for Pyongyang and $3,750 for the engineer who wrote the code. The American middleman is the largest cost line in the business, and he costs more than the regime nets.

That input is also the one priced inside US jurisdiction, and it trades in two tiers. Chapman ran a logistics tier: she hosted hardware and kept about 1% of the $17 million that passed through her house. The Ohio man runs an identity tier, supplying the face and the voice, and takes half of one salary. Risk and scarcity set the spread, and appearing on camera under a stolen name is both scarcer and more dangerous than owning a shelf.

The reason the fraud clears is arithmetic inside the hiring funnel. CareerPlug’s 2025 study of more than 10 million applications found that technology roles need about 191 applicants per hire. A standard employment background check runs $30 to $120 per candidate. Screening the whole pipeline would cost $5,730 to $22,920 for a single hire, against an average cost-per-hire near $4,700. Verifying everyone costs between one and five times the entire hiring budget, so nobody does it. Employers check identity after they have chosen someone, which puts the gate downstream of the deception. Banks verify before onboarding. Employers verify after deciding.

The attacker faces no such constraint. Writing a tailored application used to cost a person an hour; now it costs a fraction of a cent in tokens. The Journal’s cell filed roughly 125 applications per job it won. The legitimate benchmark for a tech role is 191. Read that carefully: the fraudulent applicants converted better than the honest market. There is no statistical anomaly for a recruiter to catch, because the operation looks exactly like a diligent job seeker with unusually good tooling. The application layer that Indeed, LinkedIn and Upwork monetize by volume is the same layer the fraud enters through, and volume is the thing AI just made free.

The vendors have noticed. Gartner expects one in four candidate profiles worldwide to be fake by 2028, and found in a 2025 survey of 3,000 job seekers that 6% admitted to interview fraud. GetReal Security reported in June 2026 that 41% of surveyed enterprises had hired and onboarded a fraudulent candidate. The background screening market sits around $8 billion in 2026 and forecasters have it near $13.9 billion by 2031. Selling checks is a good business. Selling checks that run before the interview instead of after it would be a better one, and that product barely exists at scale.

The risk

Three things could break this reading.

The first is definitional. Chainalysis put North Korean crypto theft above $2.17 billion in the first half of 2025 alone, which dwarfs the payroll channel. Call the IT worker scheme the largest export that arrives looking like a normal commercial transaction, and the claim holds. Call it the largest revenue line and it does not.

The second is measurement. The $800 million is a US government estimate of gross revenue, not an audited figure, and KOTRA’s merchandise data misses services, smuggling and arms sales by construction. Comparing an intelligence estimate to a mirror-trade statistic gives you the right order of magnitude and not much more precision than that.

The third is that squeezing the facilitator may just move the cost. Joshua McKenty of Polyguard has argued that as the operation matures the laptop farm becomes unnecessary. Cloud desktops, residential proxies and contractor arrangements that never ship hardware all remove the American from the chain. Enforcement that raises the price of a domestic front works only while a domestic front is required.

There is also a cost to the fix. Pushing identity verification to the top of the funnel means paying for 191 checks instead of one, and honest applicants absorb the friction. Any company that solves this by making candidates prove who they are before a recruiter will speak to them has decided that a slower, more expensive, more invasive hiring process is worth it. Most have not decided that yet.

Quick questions

How much does North Korea make per worker? Treasury puts individual earnings above $300,000 a year at the top end, with the regime withholding up to 90%. The Journal’s Ohio example sits far below that, at a $75,000 salary split with the facilitator.

Are the companies liable? They carry the losses. In the June 2025 action the Justice Department cited more than $3 million in damages against roughly $5 million the workers earned, and the two facilitators sentenced in May 2026 left victim companies with over $1.5 million in remediation costs. Sanctions exposure and stolen source code sit on top of that.

Is this only a tech company problem? Chapman’s client list included a top-five television network, a carmaker, an aerospace manufacturer and a luxury retailer. Any employer that hires remote knowledge workers and ships them a laptop is in the addressable market.

Does this kill remote work? It raises the cost of hiring strangers at distance, which is a different thing. The trend toward smaller, more distributed operating models, covered in BMA’s piece on the rise of the one-person company, runs on contractor relationships that carry even less verification than employment.

What actually stops it? Verified identity before the first interview, hardware that refuses to run behind remote-access tooling, and payroll controls that flag one bank account receiving deposits under several names. All three cost money that nobody has budgeted, because hiring is measured on time-to-fill.

The Business Model Analyst Take

Pyongyang did not find a security hole. It found a pricing error. Every company on earth pays to verify counterparties in proportion to how much money is at stake in a single transaction, and an employment contract worth $150,000 a year gets less identity scrutiny than a $500 credit card application, because the credit card issuer verifies before the money moves and the employer verifies after.

That error was survivable while forging a convincing application took human effort. Generative models removed the effort and left the pricing untouched, which is why a state with a $360 million export book can run a $800 million labor operation out of the gap. The interesting question for anyone running a company is not whether North Korea is in the pipeline. It is which other processes were built on the assumption that faking something costs the faker time. Vendor onboarding, insurance claims, KYC refresh, customer support escalation and refund requests all sit on the same assumption.

The defensive spend will arrive, and the background screening vendors will collect it. The founders worth watching are the ones building verification that runs at the top of a funnel rather than the bottom, because that is where the unit economics currently forbid it, and forbidden unit economics are where new products come from.

UNLOCK THIS FREE DOWNLOAD

DOWNLOAD NOW

Fill Your E-mail to Receive this Download Directly in Your Inbox.

RECEIVE OUR UPDATES

The Biz Model Club

Get daily, no-fluff insights on the latest business models, startup strategies, and trends delivered straight to your inbox.