"Treasury Strikes at Front Companies Fueling North Korea’s IT Worker Fraud Empire"
- U.S. Treasury sanctions 2 firms and 2 individuals for North Korea's IT worker fraud scheme involving $1M+ in falsified salaries across China, Russia, and Korea. - Sanctions freeze assets and penalize business ties with entities enabling North Korean infiltration of Western companies through deceptive recruitment and data theft. - International collaboration with Japan/South Korea and advanced tactics like deepfakes highlight evolving threats as U.S. intensifies countermeasures against cross-border cyberc
The U.S. Treasury has imposed sanctions on two companies and two individuals for their alleged roles in a North Korea-led IT worker fraud scheme that spanned across China, Russia, and the Korean Peninsula. Shenyang Geumpungri Network Technology Co. in China and the South Korea Sinjin Trading Corporation were identified as key facilitators of the scam, which reportedly funneled over $1 million into North Korean accounts through falsified IT worker salaries and fraudulent activities. The Treasury’s Office of Foreign Assets Control (OFAC) emphasized that the sanctioned entities and individuals will now face financial freezes and legal consequences for any business dealings with them or their affiliated entities.
The Treasury’s announcement underscored the persistent threat posed by North Korean IT workers who infiltrate American businesses under false pretenses, often leading to data theft and ransom demands. Under Secretary of the Treasury for Terrorism and Financial Intelligence, John Hurley, highlighted the administration’s commitment to countering these schemes and holding perpetrators accountable. The sanctioning of Kim Ung Sun, a Russian-based economic and trade consular official for North Korea, and Vitaliy Sergeyevich Andreyev, a Russian accused of orchestrating the scam, further illustrates the international dimension of the operation.
This action builds on a series of recent U.S. efforts to counter North Korean digital fraud. In May 2025, OFAC targeted Chinese companies that facilitated the placement of North Korean IT workers in Western organizations. In June, the U.S. attempted to recover nearly $8 million in payments sent to the North Koreans through similar fraudulent methods. Earlier in the month, the Department of Justice pursued the recovery of over $1 million stolen from a New York-based business by North Korean IT workers. These efforts reflect an intensifying U.S. response to what cybersecurity firm Mandiant described as a pervasive issue among Fortune 500 companies.
Remote work, which gained widespread adoption post-pandemic, has enabled North Korean actors to expand their tactics beyond traditional cyberattacks and into the realm of embedded staff infiltration. These workers often operate with elevated access to company networks, increasing the potential for data exfiltration and financial exploitation. Mandiant reported that many large corporations have admitted to experiencing North Korean IT worker infiltration, underscoring the severity of the issue.
To complicate matters, North Korean scammers are increasingly leveraging advanced technologies, including deepfake methods, to bypass standard verification procedures during recruitment processes. These tactics have proven effective in deceiving employers and embedding fraudulent IT workers into critical organizations. In response, cybersecurity experts have recommended the implementation of robust verification protocols and continuous staff education to mitigate risks.
The Treasury’s actions have also drawn support from international partners. The Japanese and South Korean governments reportedly cooperated with U.S. authorities in the enforcement of these sanctions. Additionally, the U.S. has joined with regional partners in hosting roundtable discussions to develop countermeasures against the growing threat. These collaborative efforts indicate a broader strategy to address cross-border cybercriminal activities linked to North Korea.

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
You may also like
Ethereum News Today: Linea's Airdrop Hype Drives Surge in Stablecoin Supply and DEX Activity
- Linea's stablecoin supply hit $74.5M, driven by USDC inflows ahead of its token airdrop. - DEX volumes spiked to $100M temporarily, with Linea now ranking 34th in blockchain stablecoin supply. - Consensys plans mUSD stablecoin integration with Ethereum and Linea, alongside a 72B LINEA tokenomics framework. - Airdrop analysts highlight Linea's potential, citing 9% early user allocation and $450M in Series D funding.

BlackRock ignites Ethereum rally: $455 million inflows drive Ethereum ETF surge
The world's largest asset management firm, BlackRock, has recently led capital inflows into Ethereum ETFs, injecting $455 million in a single day and pushing the total inflow past $13 billion. Its iShares Ethereum Trust (ETHA) now manages $16.5 billion and holds 3.775 million ETH. Driven by institutional capital, the price of ETH rose 4.5% in a single day, surpassing $4,600. The inflow rate into Ethereum ETFs has now exceeded that of bitcoin ETFs, reflecting strong market demand for Ethereum. Summary generated by Mars AI. This summary was generated by the Mars AI model, and the accuracy and completeness of its content are still being iteratively improved.

South Korea Cracks Down as Crypto Scams Hijack Celebrities' Fame
- South Korean police arrested three in a $4.1M crypto scam, part of global crackdowns on digital asset fraud. - Celebrities' hacked accounts promoted fake tokens like "CR7" and "YZY," causing rapid market collapses and investor losses. - International cases include a $50M gold-laundering arrest in Thailand and a 5-year fugitive caught in Seoul over $13.2M fraud. - Chainalysis reports $2.2B stolen from crypto platforms in 2024, urging stronger regulation and investor education to combat rising scams.

Institutional Bet: Cold Wallet Pours $6.8M into 2025’s Blockchain Workhorses
- Cold Wallet invests $6.8M in 2025's top crypto tokens: POL (Polygon), LINK (Chainlink), and AVAX (Avalanche), highlighting their institutional and retail adoption potential. - POL gains traction as Ethereum's Layer 2 scaling solution, while LINK strengthens DeFi through decentralized oracle networks and cross-chain data integration. - AVAX attracts enterprises with high-performance smart contracts and EVM compatibility, driving growth in dApps and emerging market DeFi protocols. - These tokens represent

Trending news
MoreCrypto prices
More








