North Koreans posed as US citizens to steal crypto and data from American firms, DOJ says

Partner offers
The Block may may earn a commission if you use our partner offers, at no extra cost to you.

Quick Take

  • The Department of Justice disclosed efforts to combat North Korean schemes in which operatives posed as U.S. citizens to work remotely for American companies and steal cryptocurrency and sensitive information.
  • In one case, four North Korean nationals were accused of stealing over $900,000 in crypto from two companies and laundering the funds through Tornado Cash.

The U.S. Department of Justice has busted several schemes where North Korean suspects posed as U.S. citizens to fraudulently gain employment at American companies, stealing cryptocurrency and sensitive data for the benefit of the North Korean regime.

In a statement released Monday, the DOJ said authorities have taken action against North Korean schemes, including filing two indictments, making an arrest, and seizing 29 financial accounts used to launder illicit funds.

"These schemes target and steal from U.S. companies and are designed to evade sanctions and fund the North Korean regime's illicit programs, including its weapons programs," said John A. Eisenberg, assistant attorney general of the DOJ's national security division.

Specifically, one indictment alleged that between 2021 and October 2024, the defendants used stolen identities from over 80 Americans to fraudulently secure remote positions at more than 100 U.S. companies, including multiple Fortune 500 firms. The scheme resulted in at least $3 million in damages, including legal fees, cybersecurity repairs, and other expenses.

Also, federal prosecutors in Georgia have charged four North Korean nationals with stealing over $900,000 in cryptocurrency from two companies and laundering the funds through sophisticated channels. 

Court documents revealed that the group used Tornado Cash, a cryptocurrency mixing service, to obscure the stolen funds before transferring them to exchange accounts opened with fake Malaysian identity documents. The suspects remain fugitives wanted by the FBI.

"North Korea remains intent on funding its weapons programs by defrauding U.S. companies and exploiting American victims of identity theft, but the FBI is equally intent on disrupting this massive campaign and bringing its perpetrators to justice," said Roman Rozhavsky, assistant director of the FBI Counterintelligence Division.


Disclaimer: The Block is an independent media outlet that delivers news, research, and data. As of November 2023, Foresight Ventures is a majority investor of The Block. Foresight Ventures invests in other companies in the crypto space. Crypto exchange Bitget is an anchor LP for Foresight Ventures. The Block continues to operate independently to deliver objective, impactful, and timely information about the crypto industry. Here are our current financial disclosures.

© 2025 The Block. All Rights Reserved. This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.

AUTHOR

Timmy Shen is an Asia editor for The Block. Previously, he wrote about crypto and Web3 for Forkast.News from Taiwan after spending more than three years in Beijing covering finance, entertainment business and current affairs at Caixin Global and Chinese tech at TechNode. His China-related reporting has also appeared in The Guardian. When he's not chasing headlines, you'll find him savoring hot pot and shabu shabu in a Taipei local haunt. Timmy holds an MS degree from Columbia University Graduate School of Journalism. Send tips to [email protected] or get in touch on X/Telegram @timmyhmshen.

See More
Connect on

Editor

To contact the editor of this story: Vishal Chawla at [email protected]

WHO WE ARE

The Block is a news provider that strives to be the first and final word on digital assets news, research, and data.

+ Follow us on Google News
Connect with the block on