
A Frightening Possibility: What If Those Helping Them Obtain Jobs Are Organized Groups—or Even Agents of State Power?
By Sung Ku Hong
Head Reporter, News And Post / Editor-in-Chief, The Korea Signal
The North Korean FAKER Act: North Korean Fraudulent Applicants Knowingly Enriching the Regime Act (H.R. 9963), introduced in the U.S. House of Representatives on July 27 by Rep. Young Kim (R-California), is not simply a bill targeting North Korea.
The bill is designed to prevent North Korea from generating foreign currency by placing remote IT workers who use fraudulent identities in jobs at companies overseas. Its purpose, as stated in the bill, is to block “fraudulent applicants known to enrich the North Korean regime.” In practical terms, the legislation would allow the United States to expand its efforts to identify North Korean workers obtaining jobs fraudulently beyond U.S. territory and into foreign countries.
Given today’s industrial structure, in which supply-chain security is essential, actively identifying and blocking North Korean operatives who seek to infiltrate companies not only in the United States but also abroad should be regarded as an essential preventive measure.
The bill would authorize the Secretary of State to strengthen diplomatic coordination with U.S. allies and partner countries in order to:
- detect North Korea’s illicit remote IT-worker activities;
- attribute those activities to their perpetrators; and
- disrupt those activities.
The bill identifies four core U.S. policy objectives:
- Prevent North Korea from generating illicit revenue through identity theft and remote employment fraud.
- Prevent such revenue from being used to support ballistic missiles, nuclear weapons, chemical weapons, biological weapons, and other weapons of mass destruction (WMD) proliferation.
- Strengthen international norms and cooperative mechanisms through coordination with the international community.
- Use diplomatic tools against foreign individuals and entities that assist North Korea in carrying out such activities.
The legislation would give the Secretary of State new authorities, including the ability to coordinate sanctions with allies, exert diplomatic pressure on countries that tolerate North Korean activities, cooperate with private companies, respond to the misuse of artificial intelligence, strengthen reward programs, and publicly attribute North Korean activities.
Secretary of State Marco Rubio, who has long been known for his strong anti-communist stance, would therefore be given additional tools to confront North Korea’s communist dictatorship on a global scale, working through U.S. allies and partners around the world.
In particular, the Secretary of State could designate as priority diplomatic targets countries that tolerate or permit North Korean workers to operate within their territories. South Korea would likely be among the first countries to come under scrutiny.
The bill was drafted on July 23 and introduced in the House Foreign Affairs Committee on July 27, while Rep. Young Kim, chairwoman of the committee’s Subcommittee on East Asia and the Pacific, was leading a bipartisan congressional delegation to South Korea, Japan, and Taiwan from July 24 through August 1.
The fact that Rep. Kim visited countries that could potentially become targets of the legislation while simultaneously advancing the bill through the congressional process is hardly a coincidence.
After returning from her Asia trip, Kim stated:
“From Seoul to Tokyo to Taipei, I saw firsthand that America’s alliances are our greatest strategic advantage and the foundation of a free and open Indo-Pacific. As China works to coerce our friends and rewrite the rules of the region, the United States must stand firmly with our partners to deter aggression, secure our supply chains, and deliver peace through strength. I will always fight to ensure America and our allies have the tools and resolve to keep this critical region free, open, and secure.”
The bill would also authorize the Secretary of State to publicly identify illicit remote-labor organizations linked to North Korea, as well as affiliated companies and support organizations, and to issue joint statements or joint advisories with allied governments.
It would require the Secretary of State to submit an initial report to Congress within 180 days of implementation and annual reports for the following two years. The reports would include an assessment of North Korean remote-worker activities, the status of international cooperation, the results of disruption efforts, cooperation between the State Department and relevant agencies, and recommendations for additional sanctions and legislation.
The significance of the bill lies in the fact that it is designed not simply as another traditional sanctions measure against North Korea, but as a comprehensive “diplomatic cooperation bill” targeting Pyongyang’s illicit foreign-currency earnings.
It is particularly noteworthy because the bill effectively adds provisions that could enable the United States to impose a form of secondary sanctions on key U.S. allies—South Korea, Japan, and Taiwan—that are critical to America’s supply-chain security.
At a time when the current South Korean government is increasingly being portrayed as having a pro-China and anti-American orientation, the enactment of this legislation could turn the messages Washington has been sending to Seoul into concrete action.
In fact, although the bill approaches the issue primarily as a problem of illicit foreign-currency generation through fraudulent employment, it could ultimately lead to a much broader crackdown on espionage within the labor sector.
That is because enforcement could expand to local facilitators who assist North Korean cyber-espionage operations.
Remote employment overseas conducted online requires people on the ground to facilitate it.
On Friday, July 31, the governments of 11 countries, including the United States, issued a joint advisory warning about North Korea’s practice of disguising its IT workers and placing them in overseas jobs. The participating countries included the United States, Japan, South Korea, the United Kingdom, Germany, France, Italy, Australia, Canada, the Netherlands, and New Zealand.
North Korean IT workers have been concealing their actual locations from employers by using virtual private networks (VPNs) and remote-access tools in North Korea, China, Russia, Southeast Asia, Africa, and elsewhere.
In the United States, authorities have also uncovered so-called “laptop farms,” in which company-issued laptops are physically managed so that North Korean IT workers can remotely access their jobs.
According to a July 2025 announcement by the Department of Justice, Christina Chapman, an Arizona resident, was sentenced to eight years in prison for operating a laptop farm from her home between 2020 and 2023. She allegedly managed more than 90 laptops used by North Korean IT workers to obtain remote employment with U.S. companies.
According to a Justice Department announcement on May 6 of this year, Matthew Isaac Noot, a Nashville, Tennessee, resident, and Eric Ntekereze Prince, a New York resident, were each sentenced to 18 months in prison for facilitating fraudulent remote employment for North Korean IT workers. They became the seventh and eighth individuals sentenced to prison within a five-month period for providing laptop-farm services.
Washington Must Not Miss the Lessons of Coupang
The House Judiciary Committee has focused on the Coupang incident primarily as an example of alleged discrimination by the South Korean government against an American company. But there is another issue that must not be overlooked.
The Chinese former Coupang employee suspected in the incident did not hack Coupang’s computer network using sophisticated technology. Instead, he reportedly accessed the system using an ID and password that he had legitimately used while previously employed by the company.
That means the same method could potentially be used by anyone who has access to a company’s internal systems—including a spy among current employees.
The problem of North Korean IT workers obtaining jobs under false identities should therefore not be viewed merely as an issue of foreign-currency generation. It also creates the possibility of “hacking without hacking”—a form of access that could ultimately have implications for national security.
But consider an even more frightening possibility:
What if the people facilitating fraudulent employment are part of an organized group? What if those facilitators possess or operate under the protection of governmental power in a particular region or country?
Organized infiltration by North Korean personnel would not necessarily be limited to companies within that country. It could extend to foreign companies operating there and eventually spread to that country’s allies and, ultimately, around the world.
And it could happen rapidly, without effective sanctions or countermeasures.
Therefore, the North Korean IT-worker problem must be addressed not only by identifying the workers themselves, but also by preventing their potential facilitators from infiltrating positions of power or receiving protection from those in power.
South Korea presents troubling circumstances in this regard.
There have been cases in which labor-union officials were accused of receiving direction from North Korea, while individuals with backgrounds in such organizations have subsequently been appointed to senior government positions.
The People’s Summit for Korea, an international gathering advocating what organizers describe as national self-determination, was held in New York from July 25 to 27, 2025, culminating in a highly visible rally in Times Square on July 27.
The event was led by Nodutdol, a Korean-American organization in the United States characterized by pro-North Korean and anti-imperialist positions. Leaders of the Korean Confederation of Trade Unions (KCTU) participated, along with representatives of overseas far-left and anti-war organizations that have expressed support for Hamas and Philippine insurgent groups.
At the rally, KCTU Vice Chairman Ham Jae-gyu made a series of statements portraying the Korean Peninsula as a colony of the United States. He argued that “peace in Northeast Asia is being seriously threatened by the United States” and that “South Korea is not a mercenary state of the United States,” among other claims.
On September 4, 2025, U.S. immigration authorities conducted a large-scale raid at the construction site of the Hyundai Motor Group–LG Energy Solution joint venture battery plant, Hyundai Motor Group Metaplant America, in Savannah, Georgia.
A total of 475 workers were arrested and detained, including approximately 300 South Korean nationals. On the surface, the allegations involved workers performing actual labor at the construction site while entering the United States under visa-waiver status through ESTA or on short-term B-1 business visas rather than obtaining the appropriate employment visas.
But there appears to be more to the story.
A Georgia Republican told News And Post that, while visiting an immigration enforcement office to assist local Korean Americans, he saw investigators comparing photographs taken at the Times Square rally in New York with the faces of workers arrested at the Georgia plant.
This is where serious concerns inevitably arise.
Seok Kwon-ho, director of organizational disputes at the KCTU, was prosecuted for allegedly conducting espionage activities under orders from North Korea. The Supreme Court ultimately upheld his sentence of nine years and six months in prison, along with nine years and six months of suspension of qualifications. Seok was reportedly involved in introducing fellow union officials to North Korean contacts.
Yet after taking office, the government of President Lee Jae Myung took the extraordinary step of appointing several former KCTU officials to prominent government positions.
Former KCTU Chairman Kim Young-hoon was appointed Minister of Employment and Labor. Former KCTU Senior Vice Chairman Kim Kyung-ja was appointed as a senior presidential secretary. And former senior vice chairman of the Korean Teachers and Education Workers Union (KTU), Choi Kyo-jin, was appointed Minister of Education.
Furthermore, since taking office, President Lee has personally invited KCTU Chairman Yang Kyung-soo and other labor leaders to the presidential office for regular meetings.
There is nothing inherently improper about a president meeting with labor leaders. But given the allegations concerning North Korean influence penetrating deeply into South Korea’s labor movement, the situation is understandably cause for concern.
From Washington’s perspective, appointing officials from an organization with individuals who have previously been accused of acting under North Korean orders to cabinet-level positions—and maintaining regular meetings between that organization and the executive branch—can inevitably send a negative signal.
It is difficult to dismiss the reasonable possibility that North Korean operatives posing as union members could be working within Korean companies operating in the United States, or within American companies operating in South Korea. In South Korea, in particular, there is concern that such individuals could potentially receive protection from government authorities.
Indeed, a Christian left-wing group argued the day after the Supreme Court upheld Seok Kwon-ho’s conviction that he had been unjustly subjected to a political witch hunt. Then, in May 2026, two other defendants who had been indicted alongside Seok were acquitted at the first trial. There are now concerns that additional individuals accused of espionage could also be acquitted in the future.
Washington Must Expand Its Investigations Beyond the Workers Themselves
In conclusion, given the circumstances in South Korea, the U.S. government should expand the scope of its investigations into North Korean IT-worker fraud to include local facilitators and support organizations operating in allied countries.
At the same time, Washington should establish procedures that allow the United States to independently verify relevant individuals, accounts, equipment, and financial flows rather than relying solely on the investigative findings of the governments of allied countries.
Rep. Young Kim’s legislation reflects growing international awareness of North Korea’s IT-enabled cyber activities. It should therefore be welcomed as an important effort to strengthen Washington’s ability to monitor and respond to a South Korean government that is increasingly perceived as sympathetic to North Korea.
With the conflicts in Iran and Ukraine moving toward their final stages, speculation is growing that President Donald Trump may turn his attention next to North Korean leader Kim Jong Un. The recent start of Ambassador Michelle Steel’s official activities in South Korea could also be viewed as preparation for North Korea-related issues that may soon move to the forefront.
Unfortunately, however, the 119th Congress has only a little more than four months remaining.
The key question now is whether Congress can pass the bill before the current session comes to an end.



