The Justice Department photograph looks less like a spy set than a hurried home office: metal shelves, power cords, company laptops, sticky notes, bags, and a cardboard box. That ordinariness is the point.
In the Chapman case, court and sentencing records show that employer-issued devices were hosted in an Arizona home so workers overseas could appear to be inside the United States.
Chapman pleaded guilty and received a 102-month sentence. DOJ said the admitted scheme reached 309 U.S. companies, compromised 68 U.S. identities, generated more than $17.1 million, and left investigators with more than 90 laptops from her residence. Those are case-specific figures—not a national total.
The laptop farm is the physical link between a remote worker abroad and a trusted machine inside an American company. It turns an ordinary address and internet connection into infrastructure for deception.
- 309
- U.S. companiesChapman case
- $17.1M+
- revenueChapman case
- 29
- farms searchedJune 2025 actions
- 8
- sentences in five monthsDOJ, May 2026
Six moves from résumé to revenue.
The reviewed cases vary, but the same operating chain appears again and again.
- 01
Borrow the person
A stolen, purchased, borrowed, or fabricated identity supplies the résumé, documents, tax record, and online profile.
- 02
Pass the interview
The applicant navigates remote hiring—sometimes with an interview stand-in, false history, or an extra staffing layer.
- 03
Receive the machine
The employer ships a company laptop to a U.S. address associated with the identity or a facilitator.
- 04
Open the tunnel
Remote-access software or hardware lets the overseas worker control the U.S.-based machine and appear to use a local internet address.
- 05
Enter the network
The worker performs the job through a trusted device—and, in some cases, reaches source code, proprietary files, or controlled technical data.
- 06
Move the money
Salary passes through payroll, proxy accounts, shell companies, payment services, or facilitators before funds move overseas.
Evidence limit: Not every case used every technique. The sequence combines official guidance with patterns established in multiple court records.
The warning became prison time.
Sentenced conduct and unresolved charges are shown separately. Figures belong to their specific case and may overlap.
309 U.S. companies · 68 identities · more than $17.1 million
Guilty plea; Chapman-case figures.Shared Wang scheme: 100+ companies · 80+ identities · $5 million+
Guilty plea; shared-scheme figures.Shared Wang scheme, including unauthorized access to ITAR-marked data
Guilty plea; shared-scheme figures.40 companies · up to 871 proxy identities · at least three U.S. farms
Guilty plea and sentencing record.Nashville farm · four companies alleged at charging · remote-desktop access
Disposition is adjudicated; scope comes from DOJ's case account.Enabled at least three DPRK IT workers; forfeiture ordered
Disposition is adjudicated.At least 13 companies · more than $970,000 in salary
DOJ says communications indicated the overseas worker was likely North Korean.Trial, extradition, and fugitive postures reported by DOJ
Allegations only. Each person is presumed innocent unless proven guilty.Not one strange house. A national network problem.
The Justice Department's June 2025 coordinated action reported searches of 29 known or suspected laptop farms across 16 states, approximately 200 computers, 29 financial accounts, and 21 fraudulent websites.
A search is not a conviction. The footprint nevertheless shows why the story cannot be reduced to one eccentric home office. The operational surface includes hiring platforms, staffing firms, identities, residences, devices, shell companies, payment services, and corporate networks.
Four labels that keep the story honest.
Adjudicated
Guilty pleas, admitted facts, judgments, sentences, restitution, and forfeiture.
Alleged
Conduct described in indictments, complaints, affidavits, searches, and pending cases.
Assessed
Government attribution about DPRK organizations, revenue, sanctions, and weapons programs.
Unknown
Unresolved overlap, command relationships, downstream data use, and the full national scale.
The conflict once mapped by patrol roads, guard posts, and wire can now arrive through a staffing chain, a residential broadband connection, a company laptop, and a trusted login.
DMZ War analysis
When a fraudulent hire reaches controlled data.
The Wang sentencing record describes an overseas participant accessing files containing ITAR-marked technical data at a defense contractor. That establishes unauthorized access to sensitive material in the court record.
Evidence limit: The record does not justify claiming that every laptop farm conducted espionage, that the material reached a particular North Korean organization, or that the wider IT-worker system is controlled by RGB/GRIB.
The FBI's practical defenses.
Warning signs are prompts for verification—not proof about a person or nationality.
- 01
Verify identity documents, photographs, contact details, education, and prior employment through independent channels.
- 02
Confirm the worker's claimed location during live video and watch for an interview performed by a different person.
- 03
Ship equipment only to a verified identity address; investigate requests to use a different destination.
- 04
Do not grant system access until identity and background checks are complete.
- 05
Review shared or frequently changed payment details and requests for virtual-currency payment.
- 06
Extend the same checks to staffing firms and third-party contractors, then report suspected activity to the FBI or IC3.
Use an FBI field office, the Internet Crime Complaint Center, or 1-800-CALL-FBI. Preserve company logs and follow counsel's incident-response guidance.
Open IC3 ↗The scene is ready. The reporting continues.
The public evidence supports a documentary sequence and a future chapter titled “The Conflict Comes Home.” It does not end the investigation.
The ordinary Arizona room, held long enough for the audience to recognize how mundane the infrastructure looks.
An identity-theft victim and an affected employer explain how a false worker becomes a tax, trust, and network problem.
From infiltration across terrain to infiltration through the trusted processes of American business.
Defense voices, victim-impact records, employer responses, overlap analysis, and an attributable explanation of organizational control.
Read the evidence.
Every source below is an official U.S. government record. The label states what kind of claim it can support.
- 01May 16, 2022 · State · Treasury · FBI↗
Guidance on DPRK Information Technology Workers
Official assessment and guidance
- 02May 16, 2024 · Justice Department↗
Chapman and Didenko charges, searches, and seizures
Charging and probable-cause record
- 03June 30, 2025 · Justice Department↗
Coordinated nationwide DPRK remote-worker actions
Mixed charges, plea, searches, and seizures
- 04July 23, 2025 · FBI↗
North Korean IT Worker Threats to U.S. Businesses
Official warning and mitigation guidance
- 05July 24, 2025 · Justice Department↗
Christina Chapman sentencing
Adjudicated
- 06February 19, 2026 · Justice Department↗
Oleksandr Didenko sentencing
Adjudicated
- 07April 15, 2026 · Justice Department↗
Kejia and Zhenxing Wang sentencings
Adjudicated; other defendants remain pending
- 08May 6, 2026 · Justice Department↗
Matthew Knoot and Erick Prince sentencings
Adjudicated; co-defendant status attributed to DOJ
Follow the conflict beyond the fence.
North Korea Watch tracks new official developments. The RGB / GRIB dossier follows overseas operations without forcing unsupported links between separate cases.

