Amazon Blocked 1,800 North Korean It Infiltration Attempts

Amazon blocked 1800 North Korean IT infiltration attempts

Amazon’s security chief says the company stopped more than 1,800 suspected DPRK-linked hiring attempts, as governments and firms warn the “fake remote worker” threat is growing.​

Lead

Amazon says it has identified and blocked more than 1,800 attempts by North Korea-linked operatives to land IT roles at the company, according to comments from Amazon Chief Security Officer Steve Schmidt at an Amazon-hosted event this week. The disclosure adds detail to a broader, fast-evolving threat: North Korean “remote IT worker” schemes that use fake or stolen identities to obtain legitimate jobs, access company systems, and generate revenue for Pyongyang.​

What Amazon reported

Schmidt said Amazon’s teams have “identified and blocked more than 1,800” suspected North Korea attempts to secure IT positions at Amazon. He also described the activity as “prolific” and warned that many organizations underestimate organized efforts to get people hired specifically to reach valuable data.​

Amazon’s security chief linked the risk to roles that can provide access to sensitive systems and highly valuable information, pointing to the attractiveness of well-paid positions—particularly around AI/ML work—and the “troves of valuable data” those roles can touch. Amazon also said it has seen a 27% quarter-over-quarter increase in the number of suspected North Korean applications during 2025.​

Schmidt described how the playbook has shifted over time—from fully fabricated online personas to the use of identities purchased from Americans with legitimate backgrounds—making fraud harder to spot using traditional résumé screening alone.​

How the infiltration attempts work

Industry and government reporting describes a consistent pattern: operators apply for remote IT jobs using fraudulent identities, get hired, and then work from outside the target country while appearing to be local—sometimes with help from facilitators. In some cases, facilitators physically host corporate laptops (commonly described as “laptop farms”) so overseas workers can remotely access employer-issued devices while geolocating as if they are inside the U.S.​

The U.S. Department of Justice has publicly described these schemes as involving North Korean individuals fraudulently obtaining remote IT employment at U.S. companies using stolen and fake identities. The Record reported that the DOJ and FBI described laptop-farm activity enabling North Koreans to illegally work at more than 100 U.S. companies, with some incidents involving access to sensitive employer data and source code, including ITAR-related data at a defense contractor.​

The FBI has also warned that, once discovered on networks, some North Korean IT workers have escalated into data extortion—stealing proprietary information (including source code) and threatening to release it unless paid. The FBI warning specifically noted that workers have copied company code repositories (for example, GitHub repositories) to personal accounts and cloud storage, creating large-scale intellectual-property risk.​

Key timeline and signals

The Amazon disclosure arrives amid a steady cadence of public warnings, enforcement actions, and threat-intelligence reporting tied to North Korean remote-worker tactics.​

Date (published) What happened Why it matters
June 30, 2025 Microsoft Threat Intelligence reported tracking North Korean remote IT worker activity as “Jasper Sleet” and said it suspended 3,000 Microsoft consumer accounts created by North Korean IT workers. ​ Shows scale and the use of mainstream consumer platforms in the identity-and-application pipeline. ​
June 29, 2025 The Record reported DOJ action targeting “laptop farms,” saying FBI officials believed the farms enabled illegal work at more than 100 U.S. companies and describing cases involving sensitive data and source code exposure. ​ Highlights how physical infrastructure inside the U.S. can make remote infiltration look legitimate to employers. ​
July 2, 2025 DOJ announced coordinated nationwide actions to combat North Korean remote IT worker schemes using stolen/fake identities to gain employment with U.S. companies. ​ Signals a whole-of-government disruption approach, not just corporate defenses. ​
Dec. 16, 2025 Amazon CSO Steve Schmidt said Amazon blocked more than 1,800 suspected North Korean attempts to secure IT roles, and described the activity as prolific. ​ One of the clearest big-tech datapoints quantifying attempted hiring-based intrusion at a single firm. ​

How Amazon says it detects attempts

Amazon says its defenses combine automation and human review, and Schmidt said the company has refined parts of this process over the past two years. He described AI-enabled tools trained to look for suspicious patterns, alongside human-led prevention efforts that validate identity and detect anomalous signals.​

Schmidt gave concrete examples of indicators Amazon looks for, including how some operatives list contact details—such as using a plus symbol at the front of a phone number, which he said most Americans do not do. He also said Amazon has identified roughly 200 academic institutions that show up repeatedly on résumés used by suspected IT worker operatives.​

More broadly, Amazon described deploying AI to speed up security analysis work and to spot suspicious activity at scale, reflecting how large platforms are trying to meet automation with automation.​

Why this threat is rising across the tech sector

Threat reporting suggests the “North Korean IT worker” model is expanding in reach and efficiency, partly because remote work has normalized distributed engineering teams and cross-border contracting. Fortune reported that CrowdStrike observed a sharp rise in companies unknowingly hiring North Korean software developers, describing a 220% increase over 12 months and estimating infiltration into more than 320 companies in that period.​

The operational incentives are clear: these jobs can generate steady salary income and offer pathways to sensitive access, including source code, credentials, and internal documentation. As the DOJ has described, the schemes can involve identity theft and organized facilitation to bypass background checks and appear legitimate during onboarding.​

The risk is not limited to payroll fraud, because access to code repositories and internal systems can open doors to follow-on compromise, intellectual-property theft, or extortion—outcomes the FBI has explicitly warned about.​

What companies can do now

Security and law-enforcement reporting points to a practical takeaway: hiring is now part of the security perimeter, and defenses must cover identity proofing, device logistics, and continuous monitoring. Steps commonly emphasized across these reports include verifying identity and location at multiple points (not only at offer stage), scrutinizing patterns in contact information and résumé metadata, and monitoring for unusual code-repository behavior such as large-scale copying or unexpected uploads to personal accounts.​

Organizations can also reduce exposure by tightening controls around employer-issued laptops (shipping, custody, and verification), and by implementing monitoring that detects remote-access tooling patterns consistent with “laptop farm” enablement described in DOJ-linked reporting. Finally, firms should ensure incident-response and legal processes are prepared for extortion scenarios, because the FBI has warned that stolen proprietary data and code have been used as leverage for ransom demands and, in some cases, public release threats.​

What happens next

Amazon’s report that it blocked 1,800 suspected North Korean IT infiltration attempts underscores how aggressively the DPRK-linked remote-worker pipeline is targeting high-trust technical roles at major companies. With Microsoft describing thousands of consumer accounts tied to the ecosystem and DOJ actions targeting facilitators and laptop farms, the public record increasingly shows a full-stack operation spanning identity fraud, infrastructure, and post-hire data risk.​

For employers, the implication is straightforward: robust hiring verification, tighter device controls, and monitoring for data-exfiltration and code-theft behaviors are now essential to protecting systems—because the “intruder” may arrive through onboarding, not a phishing email.​


Subscribe to Our Newsletter

Related Articles

Top Trending

How Teachers Use AI To Cut Planning Time In Half
How Teachers Use AI To Cut Planning Time In Half
How To Choose Marketing Automation Software
How To Choose Marketing Automation Software Without Overbuying
Why Students Struggle With Productivity Apps
Why Students are Still Struggling with Productivity Apps?
Marketing Automation
What Is Marketing Automation And How Does It Work?
Best Smart Home Hubs and Controllers
12 Best Smart Home Hubs and Controllers for a More Reliable Connected Home

Fintech & Finance

Neobanking disruption shown through mobile banking, fintech analytics, and contactless payments beside a traditional bank.
Neobanking Disruption: Revolutionizing Traditional Banking With Neobanks and Fintech
LG 7 kg Washing Machine Buying Guide
LG 7 kg Washing Machine Buying Guide 2026: How to Pick the Right One for Your Family
Instant Personal Loans for Short-Term Financial Emergencies
How Instant Personal Loans Help Manage Short-Term Financial Emergencies
Side Hustle Projects
Top 10 Side Hustle Projects That Will Generate MRR In 2027
long term social impact
Building a Legacy: Why People Invest in Long-Term Social Impact?

Sustainability & Living

Smart Home Sustainability
Smart Home Sustainability: Which Devices Actually Help and Which Ones Just Add Clutter
vote with your wallet
10 Ways to Vote With Your Wallet and Make Every Purchase Count
environment impact of plant-based diet featured image. Plant based meal with legumes, grains, vegetables, and a globe showing the environmental value of sustainable food choices.
The Environment Impact of Plant-Based Diet Choices
Swedish supply chain traceability platforms
6 Swedish Supply Chain Traceability Platforms Transforming Global Industries
Local Climate Actions
11 Local Climate Actions That Compound Beyond One Household

GAMING

How Esports Tournaments Make Money
Top 6 Ways How Esports Tournaments Make Money
How Esports Teams Operate
How Esports Teams Operate: Inside Their Internal Structure and Business Models
How to Keep Up with Gaming News ZeroMagGaming
How to Keep Up with Gaming News: ZeroMagGaming Updates and Industry Insights
list of esports leagues and tournaments
Comprehensive List of Esports Leagues and Tournaments
Software Gaming Bageltechnews
The Future of Software Gaming: Insights from BagelTechNews

Business & Marketing

How To Start A Digital Marketing Consultancy From Scratch
How To Start A Digital Marketing Consultancy From Scratch
Ecommerce Data Analysis with Claude
The Complete Guide to Ecommerce Data Analysis with Claude
SaaS valuation decline
Why $50B SaaS Valuations Won't Survive: 10 Top Reasons Explained
Enterprise AI Agent Strategy
The Age of AI Agents: How to Build an Enterprise AI Agent Strategy
Side Hustle Projects
Top 10 Side Hustle Projects That Will Generate MRR In 2027

Technology & AI

How Teachers Use AI To Cut Planning Time In Half
How Teachers Use AI To Cut Planning Time In Half
How To Choose Marketing Automation Software
How To Choose Marketing Automation Software Without Overbuying
Why Students Struggle With Productivity Apps
Why Students are Still Struggling with Productivity Apps?
Marketing Automation
What Is Marketing Automation And How Does It Work?
Best Smart Home Hubs and Controllers
12 Best Smart Home Hubs and Controllers for a More Reliable Connected Home

Fitness & Wellness

aromatherapy products and diffusers
10 Aromatherapy Products and Diffusers Worth Bringing Home
Electric Massage Ball for Spine Injury
Living With Spine Injury: How to Try an Electric Massage Ball Without Rushing It
A Complete Guide on TheLifestyleEdge com
The Lifestyle Edge: Your Complete Guide to Wellness and Modern Living
Stretching Accessories That Make a Difference
7 Stretching Accessories That Make a Difference for Flexibility, Mobility, and Recovery
air quality wellness devices
13 Air Quality and Wellness Devices Worth Considering for a Healthier Home