Amazon Blocks North Korean IT Workers
Analysis based on 10 articles · First reported Dec 23, 2025 · Last updated Dec 23, 2025
The event highlights significant cybersecurity risks for companies, particularly in the IT sector, as North Korea's state-sponsored cyber activities aim to steal financial assets and technology. This could lead to increased investment in cybersecurity measures across industries and potentially impact the reputation and stock prices of affected companies like Amazon (company). The illicit funding of North Korea's weapons programs through these schemes also poses broader geopolitical and economic stability concerns.
Amazon (company) has blocked over 1,800 North Korean applicants from securing remote IT jobs, revealing a widespread scheme by North Korea to send IT workers overseas to earn and launder funds. Steve Schmidt (disambiguation), Amazon (company)'s Chief Security Officer, stated that these workers use 'laptop farms' in the United States, operated remotely, and that the problem is not Amazon (company)-specific but affects the entire industry. Red flags include incorrect phone numbers and suspicious academic credentials. This activity is aimed at funding North Korea's weapons programs. The United States — United States Department of the Treasury has accused North Korea-affiliated cybercriminals of stealing over $3 billion, primarily in Tether (cryptocurrency), in the past three years. South Korea's intelligence agency also warned that North Korean operatives used LinkedIn to target South Koreans in defense firms for technology information. A woman in Arizona was sentenced for running a 'laptop farm' that helped North Korean IT workers secure jobs at over 300 US companies, generating $17 million for herself and North Korea.
Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.
Open Dashboard