Full Breakdown
U.S. Citizens Plead Guilty in North Korean IT Fraud Scheme
11/16/2025, 11:12:54 PM
Overview of the Fraudulent Scheme
The U.S. Department of Justice (DoJ) announced that five individuals, including four U.S. citizens and one Ukrainian national, have pleaded guilty to participating in a scheme that allowed North Korean workers to illegally secure remote information technology (IT) jobs with American companies. This operation, which ran from September 2019 to November 2022, involved the use of stolen identities and fraudulent employment practices, generating over $2.2 million in revenue for the North Korean regime, primarily to fund its weapons programs.
Key Figures Involved
The defendants include:
- Audricus Phagnasay (24), Jason Salazar (30), and Alexander Paul Travis (34), who pleaded guilty to wire fraud conspiracy for facilitating North Korean IT workers' employment by allowing them to use their identities and hosting company-issued laptops at their homes.
- Oleksandr Didenko (28), who pleaded guilty to wire fraud conspiracy and aggravated identity theft for stealing U.S. identities and selling them to North Korean operatives. He managed up to 871 proxy identities and operated laptop farms.
- Erick Ntekereze Prince (30), who also pleaded guilty to wire fraud conspiracy for running a company that supplied "certified" IT workers to U.S. firms and hosted laptops at his residence in Florida.
Mechanisms of the Scheme
The defendants facilitated North Korean IT workers by helping them pass employer vetting procedures and providing them with the necessary technology to create the illusion of working remotely from within the U.S. Travis, an active-duty member of the U.S. Army, received over $51,000 for his role, while Phagnasay and Salazar earned $3,450 and $4,500, respectively. Didenko's operations included a website designed to assist overseas IT workers in acquiring stolen identities.
Impact on U.S. Companies
The fraudulent activities affected at least 136 U.S. companies, with the DoJ reporting that the scheme generated approximately $1.28 million in salaries, most of which was funneled back to North Korea. The operation also compromised the identities of more than 18 U.S. individuals.
Official Statements & Responses
Assistant Attorney General for National Security John Eisenberg stated, “These actions demonstrate the department’s comprehensive approach to disrupting North Korean efforts to finance their weapons program on the backs of Americans.” The DoJ has also initiated civil complaints to forfeit over $15 million in cryptocurrency linked to North Korean cyber operations.
Criticism & Opposition
While the DoJ's actions have been praised as a necessary step in combating North Korean cybercrime, some critics argue that the focus on individual facilitators may overlook the broader systemic issues that allow such schemes to thrive, particularly in the context of the remote work boom accelerated by the COVID-19 pandemic.
What's Next
The U.S. government continues to pursue legal actions against individuals involved in similar schemes, with recent efforts including the seizure of hundreds of laptops and the filing of lawsuits to recover stolen virtual currencies. Additionally, international cooperation with allies in Asia, such as Japan and South Korea, is ongoing to combat North Korean cyber tactics.
Verbatim Quotes
- “These actions demonstrate the department’s comprehensive approach to disrupting North Korean efforts to finance their weapons program on the backs of Americans,” — John Eisenberg, Assistant Attorney General for National Security
- “In total, these defendants' fraudulent employment schemes impacted more than 136 U.S. victim companies, generated more than $2.2 million in revenue for the [Democratic People's Republic of Korea] regime, and compromised the identities of more than 18 U.S. persons,” — U.S. Department of Justice
