Get the Global IP Investigations and Enforcement Perspective

Industry content delivered straight to your inbox.
Email address
Secure and Spam free...

Laptop Farms: How North Korea Is Getting Inside American Companies

Through a variety of recent media reports, podcasts and government warnings, I have become increasingly interested in something I previously knew very little about:

North Korean “laptop farms.”

So, what exactly is a laptop farm?

According to the FBI, North Korean information technology (IT) workers use U.S.-based individuals—sometimes knowingly, sometimes unwittingly—to help them pose as U.S.-based remote workers and obtain jobs with American companies.

A company believes it has hired someone working remotely from somewhere in the United States.

The laptop may indeed be sitting in an American home.

The person operating it may be thousands of miles away.

The laptop is in America. The “employee” may not be.

Laptop farm operated by Christina Chapman containing numerous computers used by remote North Korean IT workers
An actual “laptop farm” discovered in Christina Chapman’s Arizona residence. Notes attached to the computers identified the U.S. companies and identities associated with individual laptops. Photo: U.S. Department of Justice.

How It Works

North Korean IT workers obtain remote employment using false or stolen identities. When the employer sends a company laptop to its supposedly U.S.-based employee, the computer may instead be delivered to a facilitator in the United States.

The facilitator can receive and store the laptop, connect it to a U.S.-based internet connection and enable remote-access software.

The North Korean worker can then remotely operate the computer while appearing to the employer to be working from inside the United States.

Some U.S.-based facilitators receive a share of the proceeds.

A U.S. laptop and internet connection can make a North Korean operative thousands of miles away appear to be an ordinary American remote employee.


Why Are They Doing It?

Initially, the primary objective was straightforward:

Money.

North Korea has dispatched thousands of skilled IT workers around the world to obtain technology jobs under fraudulent identities and generate revenue for the regime.

But the threat doesn’t end with a paycheck.

Once hired, the worker has something potentially far more valuable:

Access.

Access to company networks.

Access to source code.

Access to proprietary information.

The FBI has warned that North Korean IT workers have already exfiltrated proprietary and sensitive information, copied company code repositories and, in some cases, extorted their employers.

What begins as employment fraud can become an insider threat.

That should get the attention of anyone responsible for protecting intellectual property.


More Than 90 Laptops in One House

One of the most striking cases involved Christina Marie Chapman of Arizona.

In July 2025, Chapman was sentenced to 102 months in federal prison for participating in a North Korean IT-worker scheme.

According to federal authorities, North Korean IT workers associated with her operation obtained jobs at hundreds of U.S. companies and generated more than $17 million in illicit revenue.

When federal agents searched Chapman’s residence, they discovered more than 90 computers being operated through remote connections.

Think about that for a moment.

More than 90 computers—in one American residence—providing remote workers with apparent U.S.-based access.

Additional computers and equipment discovered inside Christina Chapman's North Korean IT worker laptop farm
Additional computers and equipment found during the federal investigation of the Chapman laptop farm. Photo: U.S. Department of Justice.

A Familiar Playbook

There is another aspect of this story that immediately caught my attention.

We’ve seen the underlying strategy before.

Foreign adversaries sometimes need someone inside the United States to provide something difficult to obtain from overseas:

Access.

Here at IP Probe, we have written repeatedly about China’s use of U.S.-based private investigators in cases involving efforts to locate, investigate or surveil members of the Chinese diaspora.

We have also seen cases involving Iran seeking U.S.-based investigative assistance to determine the movements of Iranian dissidents.

North Korea’s laptop farms are different operationally, but the underlying principle is familiar.

When a foreign adversary cannot easily operate inside the United States, find someone who can.

The U.S.-based facilitator becomes the bridge.


IP PROBE TAKEAWAY

The term “laptop farm” almost makes the scheme sound quaint.

It isn’t.

Behind those company-issued laptops may be foreign operators successfully placing themselves inside American organizations while physically remaining thousands of miles away.

The immediate objective may be generating revenue for North Korea.

But once an adversary has legitimate credentials and trusted access to an organization’s systems, the potential consequences extend far beyond payroll fraud:

Intellectual property theft.

Data theft.

Extortion.

Cyber operations.

We spend enormous resources trying to prevent foreign adversaries from breaking into our networks.

The laptop-farm strategy raises a much more troubling possibility:

What happens when we hire them, issue them credentials—and mail them the computer ourselves?


Additional Resources & Further Reading

U.S. Government & Law Enforcement

Documentaries, Reporting & Podcasts

Previous IP Probe Coverage

Disclaimer: IPProbe.Global is a service to the professional IP community. While every effort has been made to check the information in this blog, we provide no guarantees or warranties, express or implied, regarding the content provided in IPProbe.Global. We disclaim all liability and responsibility for the qualification or accuracy of representations made by the contributors or for any disputes that may arise. It is the responsibility of the readers to independently investigate and verify the credentials of such persons and the accuracy and validity of the information provided by them. This blog is for general information only and is not intended to provide legal or other professional advice.

Did you find this post useful?
I agree to have my personal information transfered to MailChimp ( more information )
Join other IP protection professionals, i.e., investigators, attorneys, and brand protection specialists and receive updates straight to your inbox.
We hate spam. Your email address will not be sold or shared with anyone else.

Ron Alvarez is an IP investigations and protection consultant and writer in South Florida. He is a former NYPD lieutenant where he investigated robbery, narcotics, internal affairs, and fine art theft cases. Ron has since coordinated the private investigation of international fraud and money laundering cases, as well as IP-related investigations and research involving the four pillars of IP: copyright, patents, trademarks, and trade secrets. Ron is a graduate of the FBI National Academy and earned a B.A. in Government and Public Administration from John Jay College of Criminal Justice in Manhattan. He has written a number of articles for various investigative publications, as well as publishing "The World of Intellectual Property (IP) Protection and Investigations" in November 2021. In 2022 he published the revised edition of his first murder/mystery novel "Pilgrimage to Ruin" and in 2024 he published his Quantum spy thriller novel "Bird in the Cage."

0 comments on “Laptop Farms: How North Korea Is Getting Inside American Companies

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Get the Global IP Investigations and Enforcement Perspective

Industry content delivered straight to your inbox.
Email address
Secure and Spam free...

Discover more from IP PROBE - Blog

Subscribe now to keep reading and get access to the full archive.

Continue reading