A software contractor you hired six months ago has been quietly forwarding your company's laptop to a stranger's spare bedroom in Arizona — and that stranger has been logging into your systems every night on your contractor's behalf. That is not a hypothetical. It is the exact scheme two U.S. nationals, Kejia Wang and Zhenxing Wang, were just sentenced to federal prison for running: 108 months and 92 months, respectively, for operating a "laptop farm" that let North Korean IT operatives fake their way into more than 100 U.S. companies.
If you have ever hired a remote developer, designer, or IT contractor you've never met in person, this case is worth five minutes of your time.
What a "Laptop Farm" Actually Is
The scheme is simpler — and more mundane-looking — than most people expect. It doesn't require hacking. It requires a hiring pipeline and an accomplice with a spare room.
Here's how it worked in the Wang case, according to the Justice Department's account of the scheme:
- Stolen or fabricated identities. The operation used more than 80 stolen U.S. citizen identities to build convincing job-applicant personas — real Social Security numbers, real names, believable work histories.
- Shell companies and fake websites. The defendants created front businesses (prosecutors named Tony WKJ LLC, Hopana Tech LLC, and Independent Lab LLC) and fraudulent financial accounts, giving each fake worker a paper trail that looked legitimate to a hiring manager or a bank.
- A literal laptop farm. When a hiring company shipped a company laptop to its new remote employee's U.S. address, it arrived at a house run by one of the co-conspirators — not the person who'd actually interviewed. Zhenxing Wang physically hosted the laptops and kept them online around the clock so the real workers, based in North Korea, could remote in and do the job without the company ever detecting a change in location.
- The actual labor. North Korean IT workers — often skilled developers — did the day-to-day coding, tickets, and stand-ups, collecting a paycheck that flowed back to the North Korean government rather than the person on the résumé.
Over roughly three years (2021 to October 2024), the scheme generated more than $5 million for North Korea's government and caused an estimated $3 million in direct damages to the companies that unknowingly hired the fraudulent workers. More than 100 companies were affected, including a number of Fortune 500 firms — proving that even organizations with real HR and security teams got fooled. A Ukrainian national, Oleksandr Didenko, was separately sentenced to five years for supplying the stolen identities that made the personas believable in the first place. Nine additional defendants remain at large, and the U.S. State Department is offering up to $5 million for information leading to their capture.
Why This Isn't Just a Big-Company Problem
It's tempting to read "Fortune 500" and assume this doesn't apply to you. It's the opposite. Security researchers who track these schemes note that North Korean operators specifically favor smaller companies and startups hiring through freelance platforms and remote job boards, precisely because the vetting is lighter and a single contractor slips through with less scrutiny than at a company with a dedicated background-check vendor. Mandiant's Charles Carmakal told a security conference that "literally every Fortune 500 company has at least dozens, if not hundreds, of applications from North Korean IT workers" — and if the volume is that high at the top of the market, the smaller, faster-moving companies further down are getting hit just as often, with fewer people watching for it.
If you run a small business, an agency, or an indie software product and you've ever posted a remote developer role on a job board, this is squarely in your risk profile.
The Financial and Legal Exposure You're Actually Carrying
This isn't only a security story — it's a bookkeeping and compliance one. U.S., EU, UK, and UN sanctions law prohibits employing or indirectly paying North Korean nationals, and that prohibition applies whether or not you knew who you were actually paying. A company that unknowingly pays a North Korean worker through a shell identity can still face scrutiny over sanctions compliance, on top of the direct financial loss when the fraud is discovered — stopped payments, clawback attempts, wasted onboarding costs, and in some cases exposed source code or customer data that walked out the door before anyone noticed the location mismatch.
This is exactly the kind of exposure that clean, auditable financial records help you catch early. If every contractor payment in your books is tagged with who was paid, through what account, and on what schedule, a payment routed through a suddenly-changed bank account or a virtual-currency request stands out immediately — instead of blending into a spreadsheet of undifferentiated "contractor expense" line items months later when someone finally asks questions.
Red Flags to Check Before You Hire
Security researchers and the FBI have compiled a consistent list of warning signs from real cases. None of these alone proves fraud, but several together should slow you down:
- No verified, live on-camera interview. Insist on at least one video call where the candidate can respond to questions in real time. During it, ask them to describe their surroundings out the window, or briefly turn the camera — AI face-swapping tools tend to glitch under unscripted movement.
- Interview identity doesn't match onboarding identity. In several documented cases, one person passed the interview and a different person did the actual work once hired. Spot-check by asking on-the-job questions that reference earlier interview conversations.
- Mismatched or inconsistent documents. Misspellings, inconsistent name formats, or ID photos that don't quite match video-call appearance are common tells.
- Unverifiable work and education history. Call the references and the listed employer directly — don't rely solely on what's written on a resume or LinkedIn.
- A shipping address that changes right before onboarding. This is the single most laptop-farm-specific signal: if a new hire asks you to ship their company laptop to an address that doesn't match their ID, or changes the delivery address at the last minute, treat it as a hard stop until you can independently verify the new address.
- Payment requests outside normal channels. Be wary of a contractor who wants payment via cryptocurrency, a third-party payment processor unrelated to their stated location, or frequent changes to their payout bank account.
- Odd login patterns after hiring. Multiple "different" employees logging in from the same IP address, logins from unexpected countries routed through a VPN, or a work style that sounds more like a call center than a solo home office are all documented indicators from FBI and industry advisories.
What to Actually Do With This List
You don't need an enterprise security team to act on most of this. A few low-cost habits close most of the gap:
- Standardize a live-video ID check as a non-negotiable last step before any remote hire starts, even for a small one-person contract.
- Ship equipment only to the address on file with the hire's verified identity documents, and treat any last-minute change request as something to confirm through a second channel (a phone call, not just a chat message) before you act on it.
- Keep a simple log of contractor payment details — bank routing changes, payment method, and any anomalies — so a pattern is visible instead of buried across months of transactions.
- Verify prior employment by calling the company, not just checking a resume line or a LinkedIn endorsement.
Keep Your Contractor Payments Auditable
A remote-hiring scam like this one is much easier to catch when your books make every payment traceable — who was paid, through which account, on what recurring pattern, and whether anything changed without explanation. Beancount.io gives you plain-text accounting that's fully transparent and version-controlled, so a contractor payment that suddenly shifts to a new bank account or an unusual payment method doesn't get lost in a spreadsheet — it shows up as a change you can see and question. Get started for free and keep every dollar you send to a remote hire fully accounted for.