Visualização de leitura

TikTok Agrees to $400M Settlement Over Children’s Privacy

TikTok and ByteDance agree to pay up to $400 million to settle US allegations involving children’s data, parental consent and account deletion.

The post TikTok Agrees to $400M Settlement Over Children’s Privacy appeared first on TechRepublic.

US Seizes 1,000+ Domains Used to Illegally Stream FIFA World Cup

illegal World Cup streaming domains

The U.S. Department of Justice has seized more than 1,000 illegal World Cup streaming domains accused of broadcasting FIFA World Cup 2026 matches without authorization, marking a major enforcement action against digital piracy during the tournament. The domains were seized in three separate actions under U.S. copyright law as part of Operation Offsides, an initiative targeting websites involved in unauthorized World Cup broadcasts.

The latest action includes nearly 400 websites seized by the end of June, according to the Department of Justice. The investigation was carried out by U.S. Immigration and Customs Enforcement Homeland Security Investigations (HSI) Washington Field Office and the National Intellectual Property Rights Coordination Center.

Illegal World Cup Streaming Domains Targeted

According to an affidavit filed in support of a seizure warrant in the U.S. District Court for the Eastern District of Virginia, the seized domains were used to offer copyright-protected content through real-time streams of 2026 World Cup matches as they were being played and first broadcast.

HSI special agents confirmed that the domains were actively broadcasting World Cup matches without authorization. The domains were identified with assistance from FIFA, with additional information provided by beIN Media Group, NBC Universal, the Motion Picture Association’s Alliance for Creativity and Entertainment (ACE), Ultimate Fighting Championship (UFC), and Warner Brothers.

FIFA holds the exclusive rights to sanction and stage the FIFA World Cup 2026, which is being hosted across multiple cities in the United States, Canada and Mexico.

Operation Offsides Targets Illegal Streaming

The U.S. action is part of Operation Offsides, which focuses on identifying and seizing websites facilitating unauthorized broadcasts of World Cup matches.

The operation is led by the National Intellectual Property Rights Coordination Center and is being conducted with HSI Washington, D.C., HSI Attaché offices, private sector organizations and law enforcement partners globally.

Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division said the effort to seize more than 1,000 domains was aimed at protecting intellectual property rights and reducing risks to consumers from malicious software associated with some illicit streaming services.

[caption id="attachment_113257" align="aligncenter" width="400"]illegal World Cup streaming domains Source: The U.S. Department of Justice[/caption]

HSI Deputy Executive Associate Director Matthew Millhollin also warned that users accessing unauthorized streaming platforms could face risks including malware and payment information theft.

Operation Red Card Expands Global Crackdown

The U.S. enforcement action was accompanied by international efforts under Operation Red Card, which targeted digital piracy and counterfeiting connected to the World Cup across the Western Hemisphere.

The Justice Department’s International Computer Hacking and Intellectual Property (ICHIP) program coordinated enforcement efforts involving Argentina, Brazil, Chile, Colombia, the Dominican Republic, Ecuador, Paraguay and Peru.

The coordinated actions resulted in hundreds of illegal streaming sites being blocked, including 14 in Argentina, 223 in Ecuador, 28 in Peru, 309 in Brazil, 256 in the Dominican Republic and 1,140 in Colombia.

Colombian authorities also conducted 13 nationwide search-and-seizure operations targeting counterfeit sports apparel, resulting in 11 arrests and convictions.

Cybercrime Group Arrested in Colombia

On July 10, authorities launched Phase II of Operation Red Card in Colombia, conducting simultaneous operations in Bogotá, Soacha, Maríalabaja, Manatí and Sincerín.

An ICHIP-mentored cybercrime prosecutorial team from the Colombian Attorney General’s Office arrested four members of the cybercriminal group Los Ciberinfiltrados. According to the Justice Department, the group had illegally accessed telecommunications systems since 2024 and sold pirated streaming content, including World Cup matches.

The group allegedly used fraudulent credentials, VPNs, interception of security codes and manipulation of corporate system profiles to distribute the pirated content.

In Europe, ICHIP Bucharest also coordinated with Europol and international counterparts to address illegal streaming activities during the World Cup.

World Cup Streaming Crackdown Intensifies

The latest action follows a June 2026 announcement by the U.S. Department of Justice involving the seizure of nearly 400 websites accused of illegally broadcasting FIFA World Cup 2026 matches.

That earlier enforcement action, also conducted under Operation Offsides, targeted websites accused of copyright infringement by offering unauthorized live streams of World Cup matches for profit.

With more than 1,000 domains now seized in the U.S. actions, authorities continue to target unauthorized streaming platforms and digital piracy networks linked to the tournament.

Alleged Scattered Spider Member Arrested in Finland, Extradited to U.S.

Scattered Spider

An alleged member of the Scattered Spider cybercrime group has been extradited from Finland to the United States to face federal charges related to conspiracy, cyber intrusion, and fraud. U.S. authorities said the case marks another step in their ongoing efforts to prosecute individuals accused of participating in high-profile cybercrime operations linked to the notorious hacking group.

Peter Stokes, 19, a dual U.S. and Estonian citizen, made his initial appearance in federal court in Chicago after being extradited from Finland.

According to the U.S. Department of Justice, Stokes was arrested by Finnish authorities in April following an Interpol Red Notice and was transferred to the United States last week. A criminal complaint filed in the Northern District of Illinois accuses him of participating in cyberattacks carried out as part of the Scattered Spider group.

Scattered Spider Linked to More Than 100 Network Intrusions

According to the complaint, Scattered Spider, also known as Octo Tempest, UNC3944, and 0ktapus, has been associated with more than 100 network intrusions. Authorities allege the group's activities have resulted in over $100 million in ransom payments and millions of dollars in additional damages suffered by victims.

Investigators said the group targeted companies across the United States by obtaining access to employee accounts through fraudulent methods.

Once inside corporate networks, the attackers allegedly encrypted data or exfiltrated sensitive information to remote servers before demanding cryptocurrency payments to restore access or prevent the public release of stolen data.

Complaint Details Alleged Luxury Retailer Cyberattack

The criminal complaint describes an alleged cyber intrusion that occurred in May 2025 involving a luxury jewelry retailer.

Federal prosecutors allege that Stokes and other co-conspirators breached the retailer's computer systems, exfiltrated company data, and demanded approximately $8 million in cryptocurrency as ransom. According to court documents, the retailer's security team successfully removed the threat actors from its network before any ransom payment was made.

Although the company did not pay the ransom, authorities said it still incurred losses of at least $2 million due to business disruption, investigation costs, and mitigation efforts following the incident.

Operation Riptide Targets Cybercrime Networks

The extradition and criminal charges were announced by the Department of Justice, the U.S. Attorney's Office for the Northern District of Illinois, and the FBI. The investigation also involved the FBI's Copenhagen Law Enforcement Attaché Office, the FBI Las Vegas Field Office, the Justice Department's Office of International Affairs, and Finland's National Bureau of Investigation.

Officials said the case forms part of Operation Riptide, an ongoing FBI campaign focused on disrupting cybercriminal actors, infrastructure, financial networks, and fraud schemes targeting Americans.

According to the FBI, Americans reported more than $20 billion in cybercrime losses last year, representing a 26% increase compared with the previous year.

Authorities Cite International Cooperation

Assistant Attorney General A. Tysen Duva said the charges stem from years of investigative work by the Justice Department, the U.S. Attorney's Office, and the FBI, adding that authorities would continue working together to pursue cybercriminals operating across international borders.

U.S. Attorney Andrew S. Boutros said the alleged attacks caused significant disruption to businesses across the United States and emphasized the government's commitment to prosecuting individuals involved in cyber intrusions.

FBI Special Agent-in-Charge Douglas S. DePodesta also highlighted the role of international law enforcement partnerships in identifying alleged members of the hacking group and pursuing cross-border cybercrime investigations.

Recent Guidance on Scattered Spider Threat

The arrest follows recent law enforcement efforts targeting the Scattered Spider threat group. In July 2025, the FBI and CISA released updated guidance describing the group's latest attack techniques, including the use of DragonForce ransomware to encrypt VMware ESXi servers.

The advisory urged organizations to maintain isolated offline backups, implement phishing-resistant multifactor authentication (MFA), and apply application controls to manage software execution.

Separately, in November 2025, two alleged Scattered Spider members appeared before Southwark Crown Court in the United Kingdom and pleaded not guilty to charges related to the August 2024 cyberattack on Transport for London (TfL).

The Department of Justice emphasized that the complaint against Stokes contains allegations only. As with all criminal cases, he is presumed innocent unless and until proven guilty in court.

U.S. Seizes Nearly 400 Illegal FIFA World Cup Streaming Domains

Illegal World Cup Streaming Domains

The Illegal World Cup Streaming Domains crackdown has intensified as the U.S. Department of Justice announced the seizure of nearly 400 websites that were illegally broadcasting FIFA World Cup 2026 matches. The enforcement action, launched ahead of the tournament's knockout stage, targets websites accused of violating copyright infringement laws by offering unauthorized live streams of World Cup matches for profit.

According to the Justice Department, the domains were seized under U.S. copyright law as part of Operation Offsides, an international initiative focused on disrupting digital piracy networks linked to the World Cup.

Illegal World Cup Streaming Domains Targeted Under Operation Offsides

Assistant Attorney General A. Tysen Duva of the Justice Department's Criminal Division said the operation was designed to disrupt international networks profiting from the global popularity of the World Cup.

"We have seized hundreds of domains, used to illegally stream World Cup matches for profit, to disrupt the international networks that profit from the global popularity of the World Cup," Duva said.

He added that the Criminal Division will continue efforts to disrupt and, where appropriate, prosecute websites and individuals involved in the illegal activity.

[caption id="attachment_112952" align="aligncenter" width="602"]Illegal World Cup Streaming Domains Banner posted on seized sites[/caption]

The domain seizures are part of Operation Offsides, led by the National Intellectual Property Rights Coordination Center in coordination with HSI, HSI Attaché offices, private sector organizations, and international law enforcement agencies.

Investigation Supported by FIFA and Industry Partners

According to an affidavit filed in the Eastern District of Virginia, investigators found that the seized websites were providing unauthorized real-time streams of FIFA World Cup 2026 matches as they were being officially broadcast.

HSI special agents confirmed that the domains were actively streaming matches without authorization.

Authorities identified the domains with assistance from FIFA, while additional supporting information was provided by beIN Media Group, NBC Universal, the Motion Picture Association's Alliance for Creativity and Entertainment (ACE), Ultimate Fighting Championship (UFC), and Warner Brothers.

FIFA holds the exclusive rights to organize and stage the FIFA World Cup 2026, which is being hosted across cities in the United States, Canada, and Mexico.

Officials Warn of Copyright and Cybersecurity Risks

Director Ivan J. Arvelo of the National Intellectual Property Rights Coordination Center said unauthorized broadcasts violate intellectual property rights and financially benefit criminal organizations.

He said the operation disrupted networks responsible for stealing and distributing copyrighted content while helping ensure fans access matches through legitimate channels.

HSI Washington Field Office Special Agent in Charge Eric Weindorf also warned that illegal streaming sites may expose users to cybersecurity threats.

According to Weindorf, viewers using unauthorized streaming platforms could face malware risks, insecure connections, and the potential compromise of personal and financial information, in addition to the copyright violations committed by the operators of such sites.

International Enforcement Targets Online Piracy Networks

The domain seizure operation was coordinated with international partners through the International Computer Hacking and Intellectual Property (ICHIP) Network.

Authorities targeted servers and domains associated with online piracy in Peru and Bulgaria, which officials identified as known centers of illegal streaming activity. Additional ICHIP-supported enforcement actions took place in Croatia, Romania, Poland, and Colombia after U.S. authorities shared intelligence to help identify domains involved in unauthorized World Cup broadcasts.

The Justice Department said the operation demonstrates ongoing cooperation between domestic and international law enforcement agencies in combating cross-border piracy.

DOJ Continues Cybercrime and IP Enforcement

The Justice Department noted that its Computer Crime and Intellectual Property Section (CCIPS) investigates and prosecutes cybercrime and intellectual property offenses alongside domestic and international partners.

Since 2020, CCIPS has secured the conviction of more than 180 cybercrime and intellectual property offenders and obtained court orders returning more than $350 million in victim funds.

The latest enforcement follows a similar HSI-led operation during the 2022 FIFA World Cup, when authorities seized more than 70 websites involved in unauthorized streaming.

The Justice Department said Operation Offsides will continue to focus on identifying and shutting down websites that facilitate illegal broadcasts while protecting intellectual property during the FIFA World Cup.

Conti Ransomware Conspirator Pleads Guilty in $150M Scheme

Conti ransomware

A Ukrainian national has pleaded guilty to his role in the Conti ransomware operation, one of the most prolific cybercrime campaigns in recent years. The U.S. Department of Justice announced that Oleksii Oleksiyovych Lytvynenko, 44, admitted to participating in a conspiracy that deployed Conti ransomware against more than 1,000 victims worldwide, resulting in at least $150 million in ransom payments. Lytvynenko entered his guilty plea after being extradited from Ireland to the United States. He pleaded guilty to participating in a wire fraud conspiracy connected to the ransomware scheme that targeted organizations across the United States and dozens of other countries.

Conti Ransomware Targeted Victims Worldwide

According to court documents, the Conti ransomware group carried out attacks between 2020 and 2022, compromising computers and networks in 47 U.S. states, the District of Columbia, Puerto Rico, and 31 foreign countries. Investigators allege that members of the operation gained unauthorized access to victim networks, encrypted critical data, and demanded ransom payments in exchange for restoring access. Victims were also threatened with public exposure of stolen information if they refused to pay. The FBI estimates that, by January 2022, the ransomware campaign had generated at least $150 million in ransom proceeds, making Conti one of the most financially damaging ransomware operations ever investigated by U.S. authorities. Assistant Attorney General A. Tysen Duva said the defendants used the ransomware variant to terrorize businesses and individuals globally, causing extensive financial losses and operational disruption.

Defendant Admitted Role in Malware Development

Court filings show that Lytvynenko joined the conspiracy no later than September 2021. He admitted to possessing stolen data belonging to eight U.S. victims and four international victims whose information had been compromised by members of the group. Authorities also stated that he worked as part of a team directed by another Conti conspirator and assisted in developing a malware "loader." Such tools are commonly used to deploy malicious software and execute additional attacks on compromised systems. The admission provides investigators with further insight into the technical infrastructure behind the Conti ransomware operation and the roles played by individual members within the criminal enterprise.

International Cooperation Led to Arrest and Extradition

The case highlights the growing collaboration between international law enforcement agencies in combating cybercrime. U.S. authorities worked alongside multiple Irish agencies, including the Irish Department of Justice, Home Affairs and Migration, the Office of the Attorney General, and the Garda National Cyber Crime Bureau to secure Lytvynenko's arrest and extradition. Assistant Director Brett Leatherman of the FBI Cyber Division described the guilty plea as an important step toward holding cybercriminals accountable for the damage caused to victims around the world. The U.S. Secret Service also emphasized that international borders would not prevent authorities from pursuing individuals involved in ransomware operations. Officials said the case demonstrates a continued commitment to identifying and prosecuting every member of organized cybercriminal networks.

Part of Broader Operation Riptide Crackdown

The prosecution forms part of Operation Riptide, an ongoing FBI initiative targeting criminal actors, infrastructure, and financial networks involved in cyber-enabled crime and fraud. According to the Department of Justice, Americans reported more than $20 billion in cybercrime-related losses last year, representing a 26% increase from the previous year. Through Operation Riptide, authorities are focusing on dismantling ransomware groups, fraud operations, and other transnational cybercriminal organizations responsible for significant financial harm. Lytvynenko faces a maximum sentence of 20 years in federal prison. He is scheduled to be sentenced on September 10, 2026. A federal judge will determine the final sentence after considering federal sentencing guidelines and other statutory factors. The investigation was led by the FBI's San Diego, Nashville, and El Paso field offices, alongside the U.S. Secret Service. Prosecutors noted that the case remains part of a broader effort to identify and prosecute additional individuals linked to the Conti ransomware conspiracy.

California Hits General Motors With Record $12.75 Million CCPA Privacy Settlement

California Privacy Settlement

California Attorney General Rob Bonta and a coalition of state and local enforcement agencies have announced a $12.75 million settlement with General Motors over allegations that the automaker illegally collected and sold drivers’ personal data without proper consent, in violation of the California Consumer Privacy Act (CCPA). The California privacy settlement marks the largest CCPA penalty in California history so far and represents the state’s first enforcement action focused on data minimization requirements under California privacy law. The case centers on allegations that General Motors shared sensitive driver information, including geolocation data and driving behavior, with data brokers Verisk Analytics and LexisNexis Risk Solutions between 2020 and 2024.

California Privacy Settlement Targets Driver Data Sales

According to the complaint, GM collected data through its OnStar connected vehicle platform, which offers emergency assistance, navigation, and crash response services. Investigators alleged that the company sold names, contact details, precise location information, and driving behavior data of hundreds of thousands of Californians to the two data brokers. Authorities said the data was intended to help create driver-risk scoring products that could be used by insurance companies when setting premiums. The investigation was conducted jointly by the California Department of Justice, the California Privacy Protection Agency (CalPrivacy), and district attorneys from San Francisco, Los Angeles, Napa, and Sonoma counties. Attorney General Rob Bonta said the settlement sends a clear message about consumer control over personal data. “General Motors sold the data of California drivers without their knowledge or consent,” Bonta said in the announcement, adding that the data could reveal sensitive details about consumers’ daily routines and movements.

CCPA Violations and Data Minimization Concerns

A major part of the case focused on alleged violations of the CCPA’s data minimization and purpose limitation requirements, which were added to California law in 2023. Under these provisions, companies are required to collect and retain only the data necessary for a disclosed purpose. Investigators alleged that GM retained driving and location data long after it was needed to operate OnStar services and later sold that retained data to third parties. Authorities also alleged that GM failed to clearly inform consumers about how their information would be used. The complaint stated that GM’s privacy policies suggested driver data would only be used to provide requested OnStar services and even claimed the company did not sell driving or location information. Investigators said the company’s practices contradicted those statements. San Francisco District Attorney Brooke Jenkins described modern vehicles as “rolling data collection machines” and said consumers deserve transparency about what information is collected and how it is shared. Los Angeles County District Attorney Nathan J. Hochman said companies handling consumer data would be held accountable under California privacy laws, regardless of their size.

Connected Vehicle Privacy Under Scrutiny

The settlement follows growing regulatory scrutiny around connected vehicle privacy and automotive data collection practices. In 2023, CalPrivacy launched investigations into connected car manufacturers and their handling of consumer information. Public attention increased further in 2024 after a report by The New York Times highlighted how automakers were sharing driving behavior data with insurance companies. The reporting indicated that some consumers outside California had experienced increased insurance premiums tied to such data-sharing practices. California investigators later determined that California drivers were likely not directly affected through insurance rate increases because state insurance laws prohibit insurers from using driving behavior data to set premiums. However, regulators maintained that the collection, retention, and sale of the data itself violated California privacy requirements.

Settlement Terms for General Motors

Under the proposed California privacy settlement, General Motors must implement several privacy-related measures over the coming years. The company will be required to:
  • Pay $12.75 million in civil penalties.
  • Stop selling driving data to consumer reporting agencies for five years.
  • Delete retained driving data within 180 days unless consumers provide express consent for limited uses.
  • Request the deletion of driver data already shared with LexisNexis and Verisk.
  • Establish and maintain a comprehensive privacy compliance program.
  • Submit privacy assessments and compliance reports to California regulators and prosecutors.
The settlement also reinforces California’s broader push to strengthen consumer control over personal information under the CCPA. CalPrivacy Executive Director Tom Kemp said California privacy laws require businesses to collect only the information they genuinely need and to be transparent about how that data is handled. Alongside the settlement announcement, regulators also highlighted the state’s Delete Request and Opt-out Platform (DROP), which allows Californians to submit requests to delete personal information held by hundreds of registered data brokers.

75,000 DDoS-for-Hire Users Reprimanded as Authorities Seize Dozens of Domains

DDoS-for-Hire, Operation PowerOFF, Europol, U.S. Department of Justice

Law enforcement agencies across Europe, the United States, and other partner nations cracked down on the commercial DDoS-for-hire ecosystem, targeting both operators and customers of services used to knock websites offline.

The coordinated effort led to the seizure of 53 domains, four arrests, 25 search warrants, and warning notices sent to more than 75,000 people suspected of using so-called “booter” or “stresser” platforms.

A Crackdown on DDoS-for-Hire

DDoS-for-hire platforms allow customers to pay relatively small fees to launch distributed denial-of-service attacks against websites, gaming services, businesses, and public infrastructure. In fact, AI-driven threat intelligence company Cyble, in a new research report released today said, DDoS was the primary mode of attack during the ongoing Iran-Israel and U.S. conflict. Cyble recorded a 140% increase in DDoS attacks targeting Israeli entities after September 2025, and at the height of the conflict, saw 40 DDoS attacks per day.

These DDoS-for-hire services often market themselves as legitimate stress-testing tools, but authorities say they are widely abused for harassment, extortion, and disruption.

The latest enforcement wave is part of the long-running international initiative known as "Operation PowerOFF," which has previously dismantled multiple booter services and disrupted related infrastructure.

Read: DDoS-for-Hire Empire Dismantled as Poland Arrests Four, U.S. Seizes Nine Domains

U.S. Authorities Seize Key Infrastructure

The U.S. Department of Justice said investigators in Alaska seized infrastructure linked to eight DDoS-for-hire domains, including services branded as Vac Stresser and Mythical Stress, both of which allegedly advertised the ability to launch tens of thousands of attacks per day. Investigators also searched backend servers tied to the platforms.

Officials did not immediately identify those behind the services, but said the action was intended to disrupt the technical backbone used to power attacks globally.

75,000 Users Contacted Directly

In one of the more unusual aspects of the operation, authorities contacted more than 75,000 suspected users directly through warning emails and letters.

Law enforcement agencies appear to be using deterrence alongside takedowns—sending a message that paying for DDoS attacks leaves a trail and may bring legal consequences.

Security experts say the tactic could be particularly effective against younger or low-level offenders who use these platforms for gaming disputes, personal retaliation, or vandalism without fully understanding the legal risks.

Investigators said they identified around three million criminal accounts connected to the wider DDoS-for-hire ecosystem. The sheer number of accounts shows how industrialized cybercrime services have become. Instead of building botnets or malware, users can simply rent attack capability on demand.

DDoS attacks overwhelm a target with traffic, often causing websites, applications, or networks to crash. While sometimes dismissed as nuisance attacks, they can disrupt hospitals, financial institutions, government portals, and emergency services.

Recent years have also seen DDoS attacks used as smokescreens to distract security teams while other intrusions unfold.

Read: Europol Issues Public Alert: ‘We Will Never Call You’ as Phone and App Scams Surge

A Persistent Cat-and-Mouse Game

Despite repeated takedowns, booter services often reappear quickly under new names, new domains, or relocated hosting providers. Researchers have found that while seizures can significantly reduce traffic in the short term, the market has proven resilient over time.

That means operations like PowerOFF may need to combine arrests, infrastructure seizures, financial disruption, and user deterrence to have lasting impact.

Two U.S. Nationals Sentenced in $5M North Korea IT Worker Scheme

North Korea IT Worker Scheme

A major North Korea IT worker scheme has led to the sentencing of two U.S. nationals who helped facilitate fraudulent remote employment operations that generated millions of dollars for the Democratic People’s Republic of Korea (DPRK), according to the U.S. Department of Justice. The case highlights how foreign actors exploited remote work systems, stolen identities, and U.S.-based infrastructure to infiltrate companies and access sensitive data.

Sentencing in North Korea IT Worker Scheme

Kejia Wang, 42, and Zhenxing Wang, 39, were sentenced for their roles in supporting the North Korea IT worker scheme, which placed overseas operatives into jobs at more than 100 U.S. companies. Kejia Wang received a sentence of 108 months in prison, while Zhenxing Wang was sentenced to 92 months. Both had pleaded guilty to multiple charges, including conspiracy to commit wire fraud and money laundering. The court also ordered three years of supervised release and financial penalties, including forfeiture of $600,000. Officials confirmed that the scheme generated more than $5 million in revenue for the DPRK, with at least $400,000 already recovered by authorities.

How the Laptop Farm Scheme Worked

At the center of the North Korea IT worker scheme were so-called “laptop farms” operated by the defendants in the United States. These setups were designed to make it appear that remote IT workers were physically located in the U.S. Using stolen identities of more than 80 Americans, the group secured remote IT roles across multiple organizations, including several Fortune 500 companies. The defendants and their associates hosted company-issued laptops at U.S. locations, enabling overseas workers to access them remotely. To facilitate this, they used hardware tools such as keyboard-video-mouse switches, allowing remote control of the devices from abroad. This setup helped bypass location checks and security controls commonly used by employers.

Use of Shell Companies and Financial Networks

The defendants also created shell companies, including Hopana Tech LLC and Independent Lab LLC, to support the North Korea IT worker scheme. These entities had no real operations but were used to present the overseas workers as legitimate U.S.-based employees. Payments from victim companies were routed through financial accounts linked to these shell companies. Authorities said millions of dollars were funneled through these accounts, with a significant portion transferred to overseas co-conspirators. In return, the facilitators in the U.S. received nearly $700,000 for their involvement.

Access to Sensitive Data and Security Risks

The North Korea IT worker scheme raised serious concerns about data security and national security. Investigators found that some of the fraudulently hired workers gained access to sensitive corporate information, including source code and restricted technical data. In one instance, an overseas co-conspirator accessed data controlled under International Traffic in Arms Regulations from a U.S.-based defense contractor. The data included sensitive information related to advanced technologies. Officials warned that such access could expose critical systems and intellectual property to foreign adversaries.

Ongoing Investigation and Wanted Suspects

Authorities continue to investigate the broader North Korea IT worker scheme, with several individuals still at large. The Federal Bureau of Investigation has identified multiple suspects believed to be involved in the operation. The U.S. Department of State has announced a reward of up to $5 million for information that helps disrupt financial networks supporting such activities. Law enforcement agencies have already taken action to dismantle parts of the operation. This includes the seizure of web domains and financial accounts linked to the scheme, along with the recovery of more than 70 laptops and remote access devices during coordinated searches. The North Korea IT worker scheme is part of a broader effort by DPRK-linked actors to generate revenue through cyber-enabled operations. Authorities say these schemes often rely on stolen identities, fake online profiles, and third-party facilitators to gain access to company systems. Public advisories from U.S. agencies have previously warned that such workers can earn significant sums, sometimes up to $300,000 annually, contributing to large-scale funding operations tied to North Korea’s strategic programs.
❌