On August 13, 2026, I sat in a briefing room at the InfraGard Central Texas chapter meeting and listened to Supervisory Special Agent Justin Akers of the FBI's Austin Cyber Task Force walk through a threat that is quietly hitting businesses of every size across the country. It is called the North Korean IT worker scheme, and according to Agent Akers, nearly every organization that hires remote workers has either been targeted by it or already victimized by it. If your business has posted a remote job listing in 2026, this is worth ten minutes of your time.
What Is at Stake
The scheme works like this. North Korean IT workers, using stolen or purchased American identities, apply for and get hired into legitimate remote IT and development jobs at U.S. companies. A U.S.-based facilitator, often someone recruited online for a modest monthly fee, hosts a "laptop farm," a residence full of company issued laptops that the North Korean worker logs into remotely so the employer believes the work is happening inside the United States.
The FBI's most well known case involved an Arizona woman named Christina Chapman, who ran a laptop farm out of her home and helped North Korean workers get hired at more than 300 U.S. companies, generating over 17 million dollars for the North Korean regime between 2020 and 2023. Nike unknowingly paid more than 75,000 dollars to one of these workers before the scheme was uncovered. Chapman was sentenced to 8.5 years in federal prison.
Agent Akers told our chapter that current FBI estimates put the total revenue from this scheme at roughly 800 million dollars a year, funding North Korea's ballistic missile and nuclear weapons programs. The FBI, State Department, and international partners issued a renewed joint advisory on this threat in 2026, and the Department of Justice has sentenced eight individuals so far this year for their roles in these schemes.
The money is the primary motive, but Agent Akers was clear that the secondary risks, cyber espionage, intellectual property theft, and in some cases data extortion or ransomware, are what should concern business owners most, because once one of these workers has legitimate access to your network, what they do with it is up to them.
Why Central Texas Businesses Face This Challenge
Central Texas, and Austin in particular, is one of the most IT and technology dense regions in the country, and remote work has been standard practice here since the pandemic. That combination makes this market a natural target. Agent Akers noted that these workers are not picky. They apply for contract and full time roles, for salaries anywhere from 20,000 to 200,000 dollars a year, and they rarely negotiate pay or ask for benefits, which can quietly make them the most attractive looking candidate in a stack of resumes.
Many Central Texas companies also lean on third party staffing firms to fill technical roles quickly. Agent Akers pointed out a real mismatch in incentives there: the staffing firm gets paid to fill the seat, while your business needs a trusted person in that seat, and the firm will typically do only what the contract requires in terms of vetting. A 10 to 250 employee business without a dedicated security team reviewing every hire is exactly the profile these operators are counting on.
How CTTS Helps Close the Gap
CTTS cannot run your background checks or make your hiring decisions, but the technical side of this threat, the side that shows up after someone is already sitting in a remote role, is squarely inside what Complete Care Coverage and Co-Managed IT are built to catch. That is exactly why more Austin businesses are asking about co-managed IT: it extends CTTS's monitoring, documentation, and access controls to work alongside your existing HR and IT staff instead of replacing them.
Agent Akers described several technical indicators our monitoring tools are built to flag: mismatches between a login's IP address and where an employee claims to work, use of VPN services associated with this scheme, KVM devices that let someone else quietly control a company laptop, and unusually long video conferencing sessions where a screen is being shared with someone off camera. He also stressed something we tell every client: the businesses that catch these workers fastest are the ones where IT, HR, and hiring managers are actually talking to each other, not working in silos. Co-managed IT Austin businesses trust gives your internal team the same visibility and alerting our own analysts use, so a red flag in a login log and a red flag in an exit interview do not sit in two separate places.
Co-Managed IT Austin Businesses Can Rely On: Red Flags to Watch For
None of these signs proves someone is a North Korean IT worker on their own, but Agent Akers was clear that a cluster of two or three should stop your hiring or onboarding process cold.
What Are the Warning Signs During Hiring and Interviews?
Watch for AI generated resumes with generic, near identical work histories, reused phone numbers across multiple applications, and a reluctance to appear on camera or odd behavior when they do, including face filters or lighting that does not match their claimed location. Agent Akers shared a countermeasure some interviewers now use: casually asking a candidate a specific, verifiable question about the city or region they claim to live in. A real local rarely stumbles on it, and someone fabricating a location often does.
How Do You Verify Employment and Education History Before You Hire?
Traditional background checks often will not catch this scheme, because the identity being checked usually belongs to a real person whose profile was copied or stolen. Agent Akers recommended going a step further: calling the university directly to confirm a degree, calling a listed former employer rather than relying only on an emailed reference, and asking your third party staffing firm exactly how they vet the people they send you.
What Onboarding and Post-Hire Behavior Should Raise Concern?
A last minute request to ship a company laptop to a different address, a request to be paid in cryptocurrency, unusually long video calls where little visible work is happening, and requests to elevate system permissions that do not match the role are all patterns Agent Akers flagged directly from FBI casework. So is an employee who never turns on their camera and gives inconsistent answers about where they live from one week to the next.
Get HR, Hiring Managers, and IT Talking to Each Other
Agent Akers said the organizations that catch these workers fastest are the ones where a hiring manager's gut feeling and a SOC analyst's login alert reach the same person. Building that habit, and giving your team the visibility to act on it, is core to what co-managed IT is designed to do.
If You Find One, Assume There May Be More
Workers in this scheme frequently refer other North Korean operatives for open roles at the same company. If you identify one bad hire, Agent Akers recommended reviewing everyone that person referred or vouched for, along with a full review of what systems and data they had access to.
Take the Next Step
This threat is not hypothetical for Central Texas businesses. It is showing up in interview pipelines and onboarding processes across the region right now, and the FBI's own advisory says most organizations that hire remotely have already encountered it in some form.
The most direct way to see where your business stands is a free Executive IT Risk Assessment from CTTS, a clear look at your current access controls, monitoring, and exposure, with no obligation attached.
Frequently Asked Questions
What is the North Korean IT worker scheme?
It is a fraud scheme in which North Korean operatives use stolen or purchased American identities to get hired into legitimate remote IT and development jobs at U.S. companies, funneling their pay back to the North Korean government while sometimes stealing data or intellectual property along the way.
How common is this threat for small and mid sized Central Texas businesses?
More common than most owners realize. FBI officials told our InfraGard chapter that nearly every organization hiring for remote roles has been targeted or victimized, and Central Texas's dense IT sector and remote-friendly job market make it an especially active target.
What should we do if we think we already hired someone tied to this scheme?
Do not confront the individual directly. Contact your IT provider to lock down and review their system access immediately, preserve logs and equipment, and report the incident to your local FBI field office, since these cases are actively investigated as federal fraud and sanctions violations.
Contact CTTS today for IT support and managed services in Austin, TX. Let us handle your IT so you can focus on growing your business. Visit CTTSonline.com or call us at (512) 388-5559 to get started!
