A company’s next remote IT hire could be sending sensitive data to a foreign government, and federal investigators say it is already happening. 

The FBI disclosed in July 2026 that it identified a North Korean operative performing remote contract work inside an unnamed U.S. federal agency.

Todd Hemmen, deputy assistant director of the FBI’s Cyber Capabilities Branch, revealed the case at a July 28, 2026, conference in Washington, D.C.

He told the panel he was still trying to understand how the agency’s hiring process allowed the operative through.

That case is not isolated, and fresh breach data from the first half of 2026 suggests the threat is growing faster than most employers realize.

How North Korean operatives are landing remote U.S. jobs

North Korea deploys skilled IT workers who use stolen identities, forged documents, and AI-generated deepfakes to land remote technology jobs across the United States.

On July 31, 2026, agencies from 11 countries issued a joint advisory warning that these operatives use false identities to earn income through remote work.

The workers then funnel their salaries to agencies inside North Korea that fund the country’s nuclear weapons and ballistic missile programs. Once embedded inside a company, some operatives go further by exfiltrating proprietary data, stealing cryptocurrency, or extorting their employers, the joint advisory stated.

Eight people have been sentenced in the United States this year for their roles in facilitating the schemes, the FBI noted.

“We’re seeing AI use across that entire spectrum of the DPRK remote worker, from application to employment,” Hemmen said.

Insider breach incidents surge to seven times last year’s total

The Identity Theft Resource Center (ITRC), a nonprofit that tracks publicly reported data compromises, counted 21 malicious insider events during the first six months of 2026.

That figure represents a sevenfold increase over the three such incidents recorded in all of 2025, a pace the organization had never previously documented. 

Part of the spike stems from disgruntled employees who stole information on their way out following tech-sector layoffs, James Lee, the ITRC’s president, told CNBC.

Related: A $72 billion forecast just raised the stakes for the AI trade

The center’s report described the North Korean hiring operation as “arguably the most significant structural driver” behind the surge in malicious insider attacks.

“We’ve never seen more than three data breaches in a given year related to a malicious insider, and you get 21 in six months,” Lee said.

Overall, the ITRC counted 1,803 data compromises in the first half of the year, up from 1,732 during the same period in 2025.

Those incidents generated more than 471 million victim notices by midyear, already surpassing the 297.5 million issued in all of 2025, the report showed.

AI-enabled breaches cost companies $1 million more per incident

An IBM study of 602 organizations found that one in four malicious breaches between March 2025 and February 2026 involved AI-enabled tactics, a 56% increase.

Those AI-driven incidents cost companies an average of $6 million each, about $1 million above the $4.99 million global breach average, the study showed.

Adam Meyers, head of counter adversary operations at CrowdStrike, warned in the firm’s 2026 Threat Hunting Report that the line between attacker tools and business tools has effectively disappeared.

“AI is now embedded in modern adversary operations. It is changing how attacks are planned, executed, and scaled while expanding the attack surface organizations must defend,” Meyers said.

More AI:

Cybersecurity firm CrowdStrike, which tracks the North Korean operation under the name FAMOUS CHOLLIMA, has documented its rapid expansion into U.S. corporate networks. 

The group accounted for 47% of all state-sponsored interactive intrusions against the technology sector between April 2025 and March 2026, CrowdStrike reported.

The operatives apply for remote developer and IT specialist roles using AI-generated resumes, fabricated portfolio websites, and cover letters produced by large language models. 

During video interviews, they deploy real-time deepfake technology to impersonate the stolen identity they used on their application, the firm found.

What remote hiring fraud means for your personal data

When an operative gains access to a company’s internal systems through a fraudulent hire, the data at risk often extends beyond the employer.

Customer records, Social Security numbers, financial account details, and health information can all sit on systems that a single remote IT workstation can reach, the ITRC found

Publicly traded companies made up just 10.3% of all compromises but generated 83.4% of all victim notices during that period. That concentration means a single insider breach at a large company can expose millions of consumers who have no direct relationship with the compromised firm.

The center has recommended that consumers freeze their credit files with all three major bureaus and switch from passwords to passkeys, the ITRC H1 2026 report noted. 

Those two steps remain the most effective measures an individual can take to reduce exposure when breach notices arrive, Lee explained.

Malicious insider incidents surged sevenfold in 2026.

Witthaya Prasongsin / Getty Images

What the federal agency case reveals about private-sector hiring gaps

Lee’s data indicates that insider threats have shifted from a rare event to a growing breach category, fueled in part by a state-backed operation deploying artificial intelligence.

Hemmen’s disclosure that a federal agency’s own process failed makes the risk concrete for every organization, regardless of size or sector.

If a government entity with formal vetting procedures could not catch a fraudulent hire, the gap in most private-sector processes may be even wider.

The FBI case leaves an open question for employers: whether remote-hire verification can extend beyond the offer stage and into onboarding, given that identity spoofing now runs through the full application cycle.

Related: Jobs Surprise: AI Cuts vs. Hiring