A new, powerful Citizen Portal experience is ready. Switch now

FBI highlights North Korean ‘laptop farms’ and remote‑worker schemes as growing national‑security risk

February 25, 2026 | Foreign Claims Settlement Commission, Department of Justice (DOJ), Executive, Federal


This article was created by AI summarizing key points discussed. AI makes mistakes, so for full details and context, please refer to the video of the full meeting. Please report any errors so we can fix them. Report an error »

FBI highlights North Korean ‘laptop farms’ and remote‑worker schemes as growing national‑security risk
Brett Leatherman, assistant director of the FBI’s Cyber Division, and Mike Machtinger, the bureau’s deputy assistant director for cyber intelligence, told listeners that a Wall Street Journal account (Feb. 15) exposed an organized North Korean effort to place operatives in remote IT roles that target U.S. employers.

“The goal there, along with about 10 other operatives crowded into a 2 bedroom dormitory…was to fake their job, fake opportunities to get into remote IT jobs in The United States,” Leatherman said, summarizing the report. He and Machtinger described the operation as large-scale and profitable: Leatherman said partners estimate the scheme could “generate up to $800,000,000” for the regime in a single year and that the regime takes roughly 90% of that revenue.

Machtinger framed the schemes as insider threats, emphasizing that operatives may gain access to sensitive corporate and defense‑industry information. “What do these folks have access to? What can they exfiltrate back to DPRK or other, nefarious players?” he asked, warning the access could be “weaponized.”

Leatherman and Machtinger also reviewed recent law‑enforcement responses. Leatherman said a coordinated Justice Department action in June produced indictments and arrests, searches of 29 laptop farms, seizures of approximately 200 computers, 29 financial accounts and 21 fraudulent websites. The FBI called those disruptions important but incomplete: both officials urged industry to report suspected cases so investigators can connect incidents across companies.

Industry reporting, the bureau said, helps investigators identify operatives who may target multiple employers. “If that individual is working for your company…don’t let law enforcement know, you know, it's very possible that they're victimizing multiple other companies at the same time,” Machtinger said, adding that sharing information in ways comfortable to companies improves the bureau’s ability to find additional victims.

Why it matters: the speakers tied the revenue and access gained through these schemes to broader national‑security concerns, including espionage and the funding of regime priorities. They said law enforcement actions reduce the actors’ capabilities but that meaningful, sustained disruption requires both prosecutions and industry cooperation.

What’s next: the FBI recommended that organizations notify law enforcement when they suspect phantom remote workers, strengthen hiring verification where practical and follow FBI advisories on detection and reporting.

Don't Miss a Word: See the Full Meeting!

Go beyond summaries. Unlock every video, transcript, and key insight with a Founder Membership.

Get instant access to full meeting videos
Search and clip any phrase from complete transcripts
Receive AI-powered summaries & custom alerts
Enjoy lifetime, unrestricted access to government data
Access Full Meeting

30-day money-back guarantee