惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Vercel News
Vercel News
博客园 - 司徒正美
大猫的无限游戏
大猫的无限游戏
Last Week in AI
Last Week in AI
V
Visual Studio Blog
阮一峰的网络日志
阮一峰的网络日志
小众软件
小众软件
宝玉的分享
宝玉的分享
Apple Machine Learning Research
Apple Machine Learning Research
美团技术团队
WordPress大学
WordPress大学
博客园 - 聂微东
人人都是产品经理
人人都是产品经理
罗磊的独立博客
The Cloudflare Blog
V
V2EX
月光博客
月光博客
有赞技术团队
有赞技术团队
Y
Y Combinator Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
GbyAI
GbyAI
博客园 - 【当耐特】
T
Tailwind CSS Blog

Help Net Security

Your work apps are quietly handing 19 data points to someone ChatGPT advanced account security adds passkeys and hardware keys Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months Automating Pentest Delivery: A Step-by-Step Guide - PlexTrac Open-source privacy proxy masks PII before prompts reach external AI services Shadow AI risks deepen as 31% of users get no employer training Identity is the control plane for distributed infrastructure AI traffic is getting bigger, louder, and less predictable New infosec products of the month: April 2026 cPanel zero-day exploited for months before patch release (CVE-2026-41940) Cisco releases open-source toolkit for verifying AI model lineage Met Police face criticism for using AI to spy on their own officers Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431) Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security IP Fabric MCP server adds governance and control to enterprise AIOps workflows - Help Net Security Aqua Compass MCP server enables real-time investigation and containment of runtime threats - Help Net Security Google brings instant email verification to Android, no OTP needed - Help Net Security If cyber espionage via HDMI worries you, NCSC built a device to stop it - Help Net Security Apple fixes iPhone bug that let FBI retrieve deleted Signal messages(CVE-2026-28950) - Help Net Security GopherWhisper APT group hides command and control traffic in Slack and Discord - Help Net Security OpenAI tackles a bad habit people have when interacting with AI - Help Net Security A year in, Zoom's CISO reflects on balancing security and business - Help Net Security Scenario: Open-source framework for automated AI app red-teaming - Help Net Security GDPR works, but only where someone enforces it - Help Net Security Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks - Help Net Security Google’s Workspace Intelligence promises privacy while running on your data - Help Net Security Cyberattack on French government agency triggers phishing alert - Help Net Security Claude Mythos finds 271 Firefox flaws, Mozilla believes zero-days are numbered - Help Net Security Prove Identity Platform connects verification, authentication, and fraud prevention - Help Net Security New Mirai variants target routers and DVRs in parallel campaigns - Help Net Security
Two US nationals jailed over scheme that generated $5 mil...
Sinisa Markovic · 2026-04-16 · via Help Net Security

Two US nationals have been sentenced for their role in a scheme that placed North Korean IT workers inside American companies under false identities. Over several years, the operation used stolen identities from at least 80 US individuals and brought in more than $5 million for the North Korean government.

North Korean IT workers scheme

Kejia Wang was sentenced to 108 months in prison, and Zhenxing Wang to 92 months. Both pleaded guilty to wire fraud and money laundering charges, with Kejia Wang also pleading guilty to identity theft conspiracy.

Court documents show the activity ran from around 2021 through October 2024. During that time, the defendants and their co-conspirators secured remote jobs at more than 100 US companies, including large corporations, by using false identities. The affected companies reported at least $3 million in losses tied to legal fees, network remediation, and related damage.

Kejia Wang acted as a US-based manager for the operation. He traveled to China in 2023 to meet overseas contacts, including an associate he knew was from North Korea. He later supervised at least five US-based facilitators who hosted company-issued laptops in their homes.

Zhenxing Wang was among those facilitators. He and others received laptops from victim companies and set them up for remote access, allowing overseas workers to log in and operate them from abroad. This included the use of keyboard-video-mouse (KVM) switches, hardware that enables remote control while making activity appear to originate within the United States.

To support the operation, the defendants created shell companies to give the impression that the workers were tied to legitimate US businesses. These entities had no staff or business activity and were used to receive payments from employers.

“The financial accounts established by the two defendants for these shell companies ultimately received millions of dollars from victimized U.S. companies, much of which was subsequently transferred to overseas co-conspirators,” prosecutors said.

The defendants and other facilitators collected nearly $700,000 for their roles.

The operation also exposed sensitive corporate data. In one case, an overseas participant accessed systems belonging to a US-based defense contractor and obtained technical information, including data subject to export controls under International Traffic in Arms Regulations. Authorities said the access took place over several weeks in early 2024 and involved company laptops and internal files.

“This case exposes a sophisticated scheme that exploited stolen American identities and US companies to generate millions of dollars for a hostile foreign regime. By operating so-called ‘laptop farms,’ these defendants enabled overseas actors to infiltrate US businesses, access sensitive data and undermine our economic and national security,” noted U.S. Attorney Leah B. Foley for the District of Massachusetts.

Law enforcement agencies have increased attention on these operations in recent years. Officials warn that hiring processes built for remote work can be exploited when identity checks rely on documents that can be forged or stolen.

The Justice Department has urged companies to strengthen hiring controls, verify worker identities, and monitor unusual login activity.