Through a variety of recent media reports, podcasts and government warnings, I have become increasingly interested in something I previously knew very little about:
North Korean “laptop farms.”
So, what exactly is a laptop farm?
According to the FBI, North Korean information technology (IT) workers use U.S.-based individuals—sometimes knowingly, sometimes unwittingly—to help them pose as U.S.-based remote workers and obtain jobs with American companies.
A company believes it has hired someone working remotely from somewhere in the United States.
The laptop may indeed be sitting in an American home.
The person operating it may be thousands of miles away.
The laptop is in America. The “employee” may not be.

How It Works
North Korean IT workers obtain remote employment using false or stolen identities. When the employer sends a company laptop to its supposedly U.S.-based employee, the computer may instead be delivered to a facilitator in the United States.
The facilitator can receive and store the laptop, connect it to a U.S.-based internet connection and enable remote-access software.
The North Korean worker can then remotely operate the computer while appearing to the employer to be working from inside the United States.
Some U.S.-based facilitators receive a share of the proceeds.
A U.S. laptop and internet connection can make a North Korean operative thousands of miles away appear to be an ordinary American remote employee.
Why Are They Doing It?
Initially, the primary objective was straightforward:
Money.
North Korea has dispatched thousands of skilled IT workers around the world to obtain technology jobs under fraudulent identities and generate revenue for the regime.
But the threat doesn’t end with a paycheck.
Once hired, the worker has something potentially far more valuable:
Access.
Access to company networks.
Access to source code.
Access to proprietary information.
The FBI has warned that North Korean IT workers have already exfiltrated proprietary and sensitive information, copied company code repositories and, in some cases, extorted their employers.
What begins as employment fraud can become an insider threat.
That should get the attention of anyone responsible for protecting intellectual property.
More Than 90 Laptops in One House
One of the most striking cases involved Christina Marie Chapman of Arizona.
In July 2025, Chapman was sentenced to 102 months in federal prison for participating in a North Korean IT-worker scheme.
According to federal authorities, North Korean IT workers associated with her operation obtained jobs at hundreds of U.S. companies and generated more than $17 million in illicit revenue.
When federal agents searched Chapman’s residence, they discovered more than 90 computers being operated through remote connections.
Think about that for a moment.
More than 90 computers—in one American residence—providing remote workers with apparent U.S.-based access.

A Familiar Playbook
There is another aspect of this story that immediately caught my attention.
We’ve seen the underlying strategy before.
Foreign adversaries sometimes need someone inside the United States to provide something difficult to obtain from overseas:
Access.
Here at IP Probe, we have written repeatedly about China’s use of U.S.-based private investigators in cases involving efforts to locate, investigate or surveil members of the Chinese diaspora.
We have also seen cases involving Iran seeking U.S.-based investigative assistance to determine the movements of Iranian dissidents.
North Korea’s laptop farms are different operationally, but the underlying principle is familiar.
When a foreign adversary cannot easily operate inside the United States, find someone who can.
The U.S.-based facilitator becomes the bridge.
IP PROBE TAKEAWAY
The term “laptop farm” almost makes the scheme sound quaint.
It isn’t.
Behind those company-issued laptops may be foreign operators successfully placing themselves inside American organizations while physically remaining thousands of miles away.
The immediate objective may be generating revenue for North Korea.
But once an adversary has legitimate credentials and trusted access to an organization’s systems, the potential consequences extend far beyond payroll fraud:
Intellectual property theft.
Data theft.
Extortion.
Cyber operations.
We spend enormous resources trying to prevent foreign adversaries from breaking into our networks.
The laptop-farm strategy raises a much more troubling possibility:
What happens when we hire them, issue them credentials—and mail them the computer ourselves?
Additional Resources & Further Reading
U.S. Government & Law Enforcement
- FBI: North Korean IT Worker Threats to U.S. Businesses
- FBI: North Korean IT Workers Conducting Data Extortion
- FBI: North Korea Leverages U.S.-Based Individuals to Defraud U.S. Businesses and Generate Revenue
- DOJ: Arizona Woman Sentenced for $17 Million North Korean IT Worker Fraud Scheme
Documentaries, Reporting & Podcasts
- Bloomberg Investigates: How North Korea Hid an IT Workforce Inside U.S. Companies
- The Wall Street Journal: Inside North Korea’s Operation to Conquer the American Job Market
- On with Kara Swisher: The Cyberattack We’re Not Ready For
- To Catch a Thief with Nicole Perlroth: North Korea on Our Payroll
Previous IP Probe Coverage
- Second Chinese NYPD Officer Fired Following FBI Transnational Repression Investigation
- Unveiling the CCP’s Use of Private Investigators: Insights from the U.S. House Select Committee
- Another Wake-Up Call for PIs Duped by the Chinese State
Disclaimer: IPProbe.Global is a service to the professional IP community. While every effort has been made to check the information in this blog, we provide no guarantees or warranties, express or implied, regarding the content provided in IPProbe.Global. We disclaim all liability and responsibility for the qualification or accuracy of representations made by the contributors or for any disputes that may arise. It is the responsibility of the readers to independently investigate and verify the credentials of such persons and the accuracy and validity of the information provided by them. This blog is for general information only and is not intended to provide legal or other professional advice.

0 comments on “Laptop Farms: How North Korea Is Getting Inside American Companies”