First Source
Security · July 31, 2026
Joint international alert · published via FBI IC3 · ic3.gov/CSA/2026/260731.pdf · July 31, 2026

An alert published this morning describes a job applicant your clients have already interviewed: strong portfolio, below-market rate, camera that never turns on — and, if you watch closely, a different person on Tuesdays.

Somewhere in your client list, an operations manager just found a full-stack developer with a beautiful portfolio at two-thirds the going rate, and is feeling clever about it. This morning’s alert — published through the FBI’s Internet Crime Complaint Center, with participating governments contributing the indicators — is about that developer.

North Korea runs a network of skilled IT workers who impersonate nationals of other countries to win remote work through hiring platforms and direct contracts. The salaries go home to their parent agencies; the alert says plainly that the income funds the country’s nuclear weapons and ballistic missile programs. And the same workers, once inside, are “involved in data exfiltration, cryptocurrency theft, and theft of sensitive information.”

None of that is new. What’s new is the level of operational detail the governments chose to publish today — down to how the laptop gets received.

Verbatim — joint alert, July 31, 2026
North Korean IT workers are known to use third-party proxies as facilitators overseas, such as in the United States, to run “laptop farms” which receive company-provided laptop computers for North Korean IT workers to remotely access, obfuscating their true location.
forged IDproxy interviewlaptop farmyour payroll

The supply chain of a fake employee, exactly as the alert lays it out: identity documents supplied by third parties, a stand-in for the interview and even in-person meetings, a U.S. address to receive the company laptop, and a salary that exits through someone else’s bank account.

The bank account is its own tell: the alert describes workers who avoid direct deposit, route pay through a third party’s account for a fee, or ask for cryptocurrency.

The alert’s most useful section is a plain checklist of what these accounts and applicants look like from the hiring side. Three of the flags are things any client of yours can check this week without buying anything: the applicant refuses video calls, or the video feed shows discrepancies — the alert names “photo ID mismatches or video feeds that appear to be manipulated or artificially generated.” The name on the payment account doesn’t match the name on the contract. And the rate is below market — listed in the alert, in those words, as a warning sign.

Then there’s the flag that sounds like fiction and isn’t: the person changes. “North Korean IT workers often operate in teams, and the individual whom a hiring or procuring official interacts with may change depending on the time of day.” The contractor who is sharp in the morning and oddly different at night may literally be two people.

One more thing the alert is honest about, and your clients should be too: the old language tells are dying. Broken English in a profile used to be a screen; the alert notes these workers now use translation services and large language models to produce convincing profiles and communications. The text reads clean. The flags that survive are the structural ones — the camera, the account name, the laptop’s shipping address, the rate.

Make the camera non-negotiable, and say why
Refusal to join video calls is a named indicator in a government alert as of this morning — that’s a sentence a client can put in their hiring SOP today. And train interviewers to actually look: ID-photo mismatches and manipulated or AI-generated feeds are named alongside it.
Match three names before the first payment
Contract name, payee account name, ID name. The alert singles out the mismatch between account holder and payment recipient, plus requests for crypto or third-party transfers, as the money-side tells. This is a five-minute payroll control, not a security product.
Ask where the laptop physically goes
If the shipping address doesn’t plausibly belong to the person hired — or the same address has received more than one contractor’s hardware — that is the laptop-farm pattern, and it is operating inside the United States by design.
Reframe the bargain rate
“Offers to work at rates lower than the general market rate” is on the list. The pitch to your clients isn’t fear — it’s procurement discipline: a rate that beats the market by a third is a data point about the seller, and this morning a group of governments told you which seller.
Also in the alert — the legal exposure

Paying these workers isn’t just a security problem. Under UN Security Council Resolution 2397, member states must repatriate North Korean nationals earning income in their jurisdictions — and the alert states that contracting with and paying North Korean IT workers “may also violate the domestic laws of many countries, including Japan, the United States, and the Republic of Korea, and may result in legal consequences or financial penalties.” A client who hired one hasn’t just leaked data; they may have made a sanctioned payment.

Kept honest. The flags are indicators, not verdicts — the alert frames them as characteristics that, when several apply together, suggest a fraudulent applicant; any one alone convicts nobody, and plenty of legitimate contractors negotiate on rate or hate cameras. The alert publishes no victim counts and names no companies, so nobody can tell you the odds — only the mechanics. The legal-exposure line is the alert’s language, not legal advice — “may violate” is doing real work in that sentence, and a client who suspects they’ve paid one needs counsel, not a checklist. And the platform-side indicators — same IP across multiple accounts, one account from many IPs, self-reviews, unnaturally high logged hours — are in the PDF for any client who runs a marketplace; they’re omitted above only because most of your clients hire, they don’t host.

Source (primary, fetched and read in full this morning): “Alert to Countries, Companies, and Other Entities Regarding North Korean IT Workers,” published July 31, 2026 via the FBI’s Internet Crime Complaint Center (IC3), four pages. All quoted language — the laptop-farm sentence, the funding and insider-threat characterizations, the team-operation and time-of-day line, the manipulated-video and below-market-rate indicators, the UNSCR 2397 and domestic-law passages, and the note that workers now use translation services and large language models — is verbatim from that document. The alert references the August 2025 Japan–U.S.–ROK Joint Statement on North Korean IT Workers and the October 2025 Multilateral Sanctions Monitoring Team report as prior art; advisories have also been issued by the U.S., Japan, the Republic of Korea, the United Kingdom, Australia, and Canada, per the alert itself.

Meschelle Peterson
code63labs

LinkedIn-ready text

A government alert published this morning describes a job applicant your company may have already interviewed.

Strong portfolio. Below-market rate. Camera never turns on. And — if you pay attention — a different person on Tuesdays.

The alert, published through the FBI's IC3, is about North Korea's remote IT workers: skilled developers who impersonate other nationalities to win contracts through hiring platforms and direct engagements. The salaries fund the country's weapons programs, in the alert's own words. And once inside, the same workers are "involved in data exfiltration, cryptocurrency theft, and theft of sensitive information."

What's actually new today is the operational detail the governments chose to publish. The supply chain of a fake employee, straight from the document:

Forged ID → proxy interview → laptop farm → your payroll.

That third step deserves a slow read: "North Korean IT workers are known to use third-party proxies as facilitators overseas, such as in the United States, to run 'laptop farms' which receive company-provided laptop computers for North Korean IT workers to remotely access, obfuscating their true location."

The company laptop ships to a U.S. address. Someone receives it, plugs it in, and the person working through it is somewhere else entirely.

The hiring-side flags in the alert, translated into checks any company can run this week:

1. The camera. Refusing video calls is a named indicator as of this morning. So are "photo ID mismatches or video feeds that appear to be manipulated or artificially generated." Make video non-negotiable and train interviewers to look.

2. Three names must match: contract, payee account, ID. The alert singles out account-name mismatches, third-party transfer requests, and crypto payment requests as the money-side tells. That's a payroll control, not a security product.

3. Where does the laptop physically go? If the shipping address doesn't plausibly belong to the hire — or has received more than one contractor's hardware — that's the pattern.

4. The bargain rate. "Offers to work at rates lower than the general market rate" is on the list. A rate a third under market is a data point about the seller.

And the flag that sounds like fiction: "North Korean IT workers often operate in teams, and the individual whom a hiring or procuring official interacts with may change depending on the time of day."

One honest note the alert itself makes: the old language tells are dying. These operations now use translation services and LLMs to write clean, convincing profiles. The flags that survive are structural — the camera, the names, the address, the rate.

And the exposure isn't only data. Under UN Security Council Resolution 2397, paying these workers "may also violate the domestic laws of many countries... and may result in legal consequences or financial penalties." A company that hired one may have made a sanctioned payment.

The flags are indicators, not verdicts — several together, not one alone. But they're free, they're structural, and as of this morning they're official.

Source: "Alert to Countries, Companies, and Other Entities Regarding North Korean IT Workers," July 31, 2026, via FBI IC3 — ic3.gov/CSA/2026/260731.pdf. Every quote above is verbatim from the document.

Your narrated animation

A finished, narrated animation of this edition came with your email (MP4, 1080×1350 — sized for LinkedIn and Instagram). Post it as-is.

FIRST SOURCE · one verified original-source finding, composed for one reader · this edition: security — written for the firms whose clients think a bargain contractor is a procurement win until it's an incident report