Flagship investigation

North Korea's American laptop farms

How suburban rooms, stolen identities, and company-issued computers became access points for a state revenue operation—and what the court record actually proves.

Metal shelves filled with labeled company laptops and cables in the Chapman residence
The room. A DOJ-released evidence photograph associated with the Christina Chapman case shows company laptops arranged on metal shelving. Official source ↗
The conflict comes home

The Justice Department photograph looks less like a spy set than a hurried home office: metal shelves, power cords, company laptops, sticky notes, bags, and a cardboard box. That ordinariness is the point.

In the Chapman case, court and sentencing records show that employer-issued devices were hosted in an Arizona home so workers overseas could appear to be inside the United States.

Chapman pleaded guilty and received a 102-month sentence. DOJ said the admitted scheme reached 309 U.S. companies, compromised 68 U.S. identities, generated more than $17.1 million, and left investigators with more than 90 laptops from her residence. Those are case-specific figures—not a national total.

The laptop farm is the physical link between a remote worker abroad and a trusted machine inside an American company. It turns an ordinary address and internet connection into infrastructure for deception.

309
U.S. companiesChapman case
$17.1M+
revenueChapman case
29
farms searchedJune 2025 actions
8
sentences in five monthsDOJ, May 2026
The machine

Six moves from résumé to revenue.

The reviewed cases vary, but the same operating chain appears again and again.

  1. 01

    Borrow the person

    A stolen, purchased, borrowed, or fabricated identity supplies the résumé, documents, tax record, and online profile.

  2. 02

    Pass the interview

    The applicant navigates remote hiring—sometimes with an interview stand-in, false history, or an extra staffing layer.

  3. 03

    Receive the machine

    The employer ships a company laptop to a U.S. address associated with the identity or a facilitator.

  4. 04

    Open the tunnel

    Remote-access software or hardware lets the overseas worker control the U.S.-based machine and appear to use a local internet address.

  5. 05

    Enter the network

    The worker performs the job through a trusted device—and, in some cases, reaches source code, proprietary files, or controlled technical data.

  6. 06

    Move the money

    Salary passes through payroll, proxy accounts, shell companies, payment services, or facilitators before funds move overseas.

Evidence limit: Not every case used every technique. The sequence combines official guidance with patterns established in multiple court records.

Case status

The warning became prison time.

Sentenced conduct and unresolved charges are shown separately. Figures belong to their specific case and may overlap.

PersonStatusResultRecord
Christina Marie ChapmanSentenced102 months

309 U.S. companies · 68 identities · more than $17.1 million

Guilty plea; Chapman-case figures.
Kejia “Tony” WangSentenced108 months

Shared Wang scheme: 100+ companies · 80+ identities · $5 million+

Guilty plea; shared-scheme figures.
Zhenxing “Danny” WangSentenced92 months

Shared Wang scheme, including unauthorized access to ITAR-marked data

Guilty plea; shared-scheme figures.
Oleksandr DidenkoSentenced60 months

40 companies · up to 871 proxy identities · at least three U.S. farms

Guilty plea and sentencing record.
Matthew Isaac KnootSentenced18 months

Nashville farm · four companies alleged at charging · remote-desktop access

Disposition is adjudicated; scope comes from DOJ's case account.
Erick Ntekereze PrinceSentenced18 months

Enabled at least three DPRK IT workers; forfeiture ordered

Disposition is adjudicated.
Minh Phuong Ngoc VongSentenced15 months

At least 13 companies · more than $970,000 in salary

DOJ says communications indicated the overseas worker was likely North Korean.
Ashtor, de los Reyes, Jin & PakPending as of May 6Charges unresolved

Trial, extradition, and fugitive postures reported by DOJ

Allegations only. Each person is presumed innocent unless proven guilty.
The enforcement footprint

Not one strange house. A national network problem.

The Justice Department's June 2025 coordinated action reported searches of 29 known or suspected laptop farms across 16 states, approximately 200 computers, 29 financial accounts, and 21 fraudulent websites.

A search is not a conviction. The footprint nevertheless shows why the story cannot be reduced to one eccentric home office. The operational surface includes hiring platforms, staffing firms, identities, residences, devices, shell companies, payment services, and corporate networks.

What the files establish

Four labels that keep the story honest.

01

Adjudicated

Guilty pleas, admitted facts, judgments, sentences, restitution, and forfeiture.

02

Alleged

Conduct described in indictments, complaints, affidavits, searches, and pending cases.

03

Assessed

Government attribution about DPRK organizations, revenue, sanctions, and weapons programs.

04

Unknown

Unresolved overlap, command relationships, downstream data use, and the full national scale.

The conflict once mapped by patrol roads, guard posts, and wire can now arrive through a staffing chain, a residential broadband connection, a company laptop, and a trusted login.

DMZ War analysis
Beyond the paycheck

When a fraudulent hire reaches controlled data.

The Wang sentencing record describes an overseas participant accessing files containing ITAR-marked technical data at a defense contractor. That establishes unauthorized access to sensitive material in the court record.

Evidence limit: The record does not justify claiming that every laptop farm conducted espionage, that the material reached a particular North Korean organization, or that the wider IT-worker system is controlled by RGB/GRIB.

For employers

The FBI's practical defenses.

Warning signs are prompts for verification—not proof about a person or nationality.

  1. 01

    Verify identity documents, photographs, contact details, education, and prior employment through independent channels.

  2. 02

    Confirm the worker's claimed location during live video and watch for an interview performed by a different person.

  3. 03

    Ship equipment only to a verified identity address; investigate requests to use a different destination.

  4. 04

    Do not grant system access until identity and background checks are complete.

  5. 05

    Review shared or frequently changed payment details and requests for virtual-currency payment.

  6. 06

    Extend the same checks to staffing firms and third-party contractors, then report suspected activity to the FBI or IC3.

Report suspected activity

Use an FBI field office, the Internet Crime Complaint Center, or 1-800-CALL-FBI. Preserve company logs and follow counsel's incident-response guidance.

Open IC3 ↗
Documentary & book desk

The scene is ready. The reporting continues.

The public evidence supports a documentary sequence and a future chapter titled “The Conflict Comes Home.” It does not end the investigation.

Opening scene

The ordinary Arizona room, held long enough for the audience to recognize how mundane the infrastructure looks.

Human story

An identity-theft victim and an affected employer explain how a false worker becomes a tax, trust, and network problem.

Historical bridge

From infiltration across terrain to infiltration through the trusted processes of American business.

Still needed

Defense voices, victim-impact records, employer responses, overlap analysis, and an attributable explanation of organizational control.

Primary record

Read the evidence.

Every source below is an official U.S. government record. The label states what kind of claim it can support.

  1. 01
    May 16, 2022 · State · Treasury · FBI

    Guidance on DPRK Information Technology Workers

    Official assessment and guidance

  2. 02
    May 16, 2024 · Justice Department

    Chapman and Didenko charges, searches, and seizures

    Charging and probable-cause record

  3. 03
    June 30, 2025 · Justice Department

    Coordinated nationwide DPRK remote-worker actions

    Mixed charges, plea, searches, and seizures

  4. 04
    July 23, 2025 · FBI

    North Korean IT Worker Threats to U.S. Businesses

    Official warning and mitigation guidance

  5. 05
    July 24, 2025 · Justice Department

    Christina Chapman sentencing

    Adjudicated

  6. 06
    February 19, 2026 · Justice Department

    Oleksandr Didenko sentencing

    Adjudicated

  7. 07
    April 15, 2026 · Justice Department

    Kejia and Zhenxing Wang sentencings

    Adjudicated; other defendants remain pending

  8. 08
    May 6, 2026 · Justice Department

    Matthew Knoot and Erick Prince sentencings

    Adjudicated; co-defendant status attributed to DOJ

Continue the investigation

Follow the conflict beyond the fence.

North Korea Watch tracks new official developments. The RGB / GRIB dossier follows overseas operations without forcing unsupported links between separate cases.

Open North Korea Watch →Open the RGB / GRIB dossier →