Countries Respond to UN Report on North Korean IT Worker Exploitation with Legal Actions

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Multiple countries have initiated legal actions against North Koreans and local facilitators following a United Nations report detailing Pyongyang’s illicit IT worker scheme. The Multilateral Sanctions Monitoring Team (MSMT), a U.S.-led international committee, released a report highlighting the thousands of North Korean nationals working abroad in various sectors, including IT.

This report expands on a previous 140-page study published by the UN last October, which specifically addressed the IT worker scheme where North Korean nationals illegally obtain IDs to secure high-paying IT jobs. According to the UN, these workers reside illegally in China and approximately 40 other countries.

In response to the findings, Argentina has opened an investigation into Antonia Doroganova, who is accused of laundering funds earned by North Korean IT workers. The Argentine government has also frozen some assets linked to her activities. Meanwhile, in Pakistan, authorities have detained Syeda Aliya Batool Zaidi, an alleged forger who provided fraudulent identification documents to North Korean IT workers. The Pakistani Federal Investigation Agency is investigating Zaidi along with two other individuals accused of facilitating North Korean IT work.

Increased Surveillance in China

The report also noted heightened scrutiny of North Korean IT workers in China, where incidents have raised alarms among Chinese officials. The MSMT indicated that these workers are facing stricter surveillance, with reports of arrests for alleged espionage activities. For instance, a North Korean IT worker was reportedly detained in April 2025 for attempting to steal military secrets.

Due to these challenges, a North Korean company has resorted to leasing a building in Sinuiju, allowing IT workers to access Chinese internet services and earn foreign currency without physically entering China. Similar issues have been reported in Laos, where North Korean IT workers have been subjected to increased surveillance, prompting a relocation from the capital Vientiane to Vang Vieng.

Global Implications

Despite multiple UN resolutions mandating the repatriation of North Korean nationals and prohibiting them from earning income in member states, the MSMT reports that around 100,000 North Koreans continue to work abroad, primarily in China and Russia. An estimated 20,000 to 70,000 North Korean workers are in China, with up to 30,000 in Russia, engaged in various sectors including manufacturing and agriculture. Notably, up to 90% of their earnings are reportedly confiscated by North Korean authorities.

The MSMT’s findings underscore the extensive network of local facilitators and North Korean officials managing these workers and transferring their earnings back to Pyongyang. Lara Strangways, a spokesperson for Global Rights Compliance, emphasized the urgent need to confront the issue of state-sponsored forced labor, calling for the identification and sanctioning of labor brokers and companies profiting from this exploitation.

For further details, refer to the full report by the MSMT here.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

France outlines 2035 national security plan emphasizing military transformation and technological independence

MILAN — French President Emmanuel Macron announced a comprehensive national security plan for 2035, emphasizing military transformation and technological independence in response to escalating...

Ransomware Developer Sentenced to 13 Years in Switzerland Amid Rising Cyber Threats

A Ukrainian IT specialist has been sentenced to nearly 13 years in prison by a Zurich court for his role in developing ransomware that...

Cybersecurity Awareness Essential to Combat Identity Theft and Financial Scams

Inadequate cybersecurity can lead to identity theft and significant financial loss, as highlighted by the Federal Deposit Insurance Corporation (FDIC). Scammers primarily aim to...

SimuPhish Advocates for Continuous Human Risk Management to Combat AI-Driven Cyber Threats in the Middle East

SimuPhish co-founders Shubh Arya and Hritik Jain explain why continuous behavioural intelligence is essential for building workforce cyber resilience As AI-driven threats become increasingly sophisticated,...