North Korean IT Worker Tricked New Zealand Business in Clandestine Scheme
- The deception exposed the domestic firm to potential United Nations sanctions breaches and highlights a growing global scheme designed to generate foreign currency for Pyongyang's weapons programs.
- The operation mirrors so-called laptop farm setups identified worldwide, where operatives mask their geographic locations to infiltrate Western companies.
- The ruse unraveled after the New Zealand company grew suspicious of the arrangement and involved the police.
The deception exposed the domestic firm to potential United Nations sanctions breaches and highlights a growing global scheme designed to generate foreign currency for Pyongyang’s weapons programs.
Global Scheme Funding State Programs
The operation mirrors so-called laptop farm setups identified worldwide, where operatives mask their geographic locations to infiltrate Western companies. According to the National Cyber Security Centre, North Korea utilizes these remote information technology workers to accumulate cash while obfuscating their origins.
Data from United States authorities cited in related reporting shows that similar global schemes generated roughly US$800 million, or about NZ$1.4 billion, in 2024. These funds flow directly back to support Pyongyang’s nuclear and ballistic missile programs.
National Cyber Security Centre head Catriona Robinson noted that a large and reputable New Zealand business with sound hiring practices was nonetheless duped by the operative for a period of time. The worker utilized fake identity paperwork, established a local address as a contact point, and enlisted a New Zealand citizen to receive and operate the firm’s laptop.
Extortion Attempt and Warning Signs
The ruse unraveled after the New Zealand company grew suspicious of the arrangement and involved the police. Following the termination of the contract, the worker claimed to have accessed commercially sensitive corporate information and threatened to release it unless paid off, according to the security agency’s report.
The National Cyber Security Centre declined to comment on the extortion threat, noting it remained a matter for the business and law enforcement. Robinson confirmed that police have spoken with the individual who was paid to receive the company laptop.
To combat similar infiltration attempts, the security watchdog outlined specific warning signs for employers. These indicators include requests for salary payments in cryptocurrency, a persistent refusal to participate in video-conference meetings, and unusual working hours.
Recommended defensive measures involve conducting face-to-face interviews and requiring incoming staff to collect their IT equipment in person.
