Monday, August 3, 2026

Policy & Regulation

US court jails man for facilitating North Korean worker fraud

A Ukrainian man was sentenced to five years in prison for running an identity theft operation that helped North Korean workers infiltrate U.S. companies.

US court jails man for facilitating North Korean worker fraud

A U.S. federal court has sentenced 29-year-old Oleksandr Didenko to five years in prison for his role in a sophisticated identity theft operation. According to U.S. prosecutors, Didenko, who was a resident of Kyiv, ran a scheme designed to help overseas North Korean workers secure fraudulent employment at dozens of U.S. companies. The wages earned by these workers were subsequently funneled back to Pyongyang, which the regime used to fund its internationally sanctioned nuclear weapons program. Didenko was arrested by Polish authorities, extradited to the United States, and subsequently pleaded guilty. The conviction is the latest in a series of legal actions targeting individuals who facilitate these ongoing North Korean IT worker schemes.

Didenko facilitated this scheme by operating a website called Upworksell. The platform allowed individuals working overseas, including North Korean workers, to buy or rent stolen identities to gain employment with U.S. firms. The Justice Department attributed that Didenko handled more than 870 stolen identities during the operation. The FBI seized Upworksell in 2024 and diverted its traffic to its own servers to disrupt the network.

As part of the operation, Didenko paid individuals to receive and host computers at their homes in California, Tennessee, and Virginia. These setups functioned as “laptop farms”—defined as rooms containing racks of open laptops allowing remote work—which enabled the North Korean workers to remotely perform their jobs as if they were physically located in the United States.

Security researchers describe these North Korean workers as a “triple threat” to U.S. and global businesses. According to these researchers, the workers violate U.S. sanctions, steal sensitive company data, and extort those victim companies into not publicly releasing corporate secrets. The security firm CrowdStrike reported seeing a sharp rise in the number of North Korean workers infiltrating companies, often in remote technical software engineering or developer roles, to bypass international sanctions and enrich the regime.

Why it matters

The sentencing of Oleksandr Didenko marks a significant development in the ongoing crackdown on North Korean “IT worker” schemes that use stolen identities to infiltrate U.S. companies and fund sanctioned nuclear programs.