In a case with serious implications for U.S. cybersecurity and national defense, Christina Marie Chapman, 50, of Arizona, was sentenced to 102 months in prison for her role in a network that helped North Korean information technology (IT) workers gain access to 309 U.S. companies.

Chapman pleaded guilty to identity theft, wire fraud, conspiracy to commit money laundering and conspiracy to commit
See also: North Korean hackers distribute 67 malicious npm packages
Digital penetration via “laptop farm”
From 2020 to 2023, Chapman had a “laptop farm” in her home, where she hosted the computers of remote North Korean workers. Through this structure, the computers appeared to be within the United States, masking the actual location of the North Korean programmers.
The programmers managed to work remotely for high-profile companies , from aerospace and defense industries to television networks and Silicon Valley companies . During that time, they extracted more than $17 million from the companies, some of which went to Pyongyang — funding North Korea’s nuclear program , according to the FBI .
Chapman also managed payroll, using her own bank accounts, and allegedly sent 49 laptops and other devices to addresses in China, near the border with North Korea.
See also: Treasury imposes sanctions on North Korea
The digital front: From freelancing to espionage
Authorities also uncovered the existence of an illegal job-hunting platform called UpWorkSell , run by Ukrainian Oleksandr Didenko . The platform served as a front for the remote recruitment of North Korean IT workers, providing them with fake profiles, identities, and IP addresses to apply for jobs at American companies through mainstream platforms like Upwork or Freelancer.
Didenko and at least three other accomplices, known only by pseudonyms (Jiho Han, Haoran Xu, Chunji Jin), are also charged with money laundering. The Justice Department seized the website and is investigating the network's expansion to other countries.
Sanctions and US strategic response
In conjunction with the court ruling, the Office of Foreign Assets Control (OFAC) announced financial sanctions on North Korean front companies and three individuals associated with the network. The United States had previously issued international warnings, sounding the alarm over Pyongyang’s strategy of using skilled IT workers for financial gain and to support state programs.
See also: North Korean hackers use new macOS malware NimDoor

The FBI has updated its guidance to businesses, encouraging them to rigorously verify the identities and IP addresses of remote employees, particularly in the technology and defense industries.
Why this case is a warning to the global tech community
The Chapman case highlights an emerging threat model , where freelancing, remote work, and the decentralization of tech employment are creating new vulnerabilities for businesses. As remote work continues to become a core practice in the tech industry, the need for multi-faceted mechanisms and security verification increases .
Digital infrastructure is no longer at risk only from ransomware or phishing attacks, but also from strategic internal infiltration, with state support and geopolitical motives.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: www.bleepingcomputer.com
