A 29-year-old Ukrainian man has been sentenced to five years in prison in the U.S. for his role in facilitating fraud by North Korean IT workers. In November 2025, Oleksandr “Alexander” Didenko pleaded guilty to conspiracy to commit wire fraud, stealing the identities of American citizens and selling them to IT workers. His goal was to help North Koreans get jobs at 40 American companies in order to receive regular salaries, which were then channeled to the regime to support North Korea’s weapons programs.

The Ukrainian was arrested by Polish authorities in late 2024 and later extradited to the U.S.
Didenko was also ordered to serve 12 months of supervised release and pay $46,547.28 in restitution. Last year, Didenko also agreed to forfeit more than $1.4 million, including about $181,438 in U.S. dollars and cryptocurrencies seized from him and his accomplices.
See also: North Koreans pose as IT professionals on LinkedIn to infiltrate companies
How the IT scam in which the Ukrainian participated worked
The defendant allegedly operated a website called Upworksell.com to help overseas IT workers buy or rent stolen or borrowed identities since early 2021. The IT workers used these identities to apply for jobs on freelance job platforms based in California and Pennsylvania.
The website was seized by authorities on May 16, 2024.
In addition, Didenko paid individuals in the U.S. to pick up and host laptops at their residences in Virginia, Tennessee, and California. The idea was to give the impression that the workers were in the country, when in fact they were connecting remotely from countries like China.

As part of the criminal scheme, Didenko managed up to 871 proxy identities and facilitated the operation of at least three U.S.-based laptop farms . One of the computers was sent to a laptop farm operated by Christina Marie Chapman in Arizona. Chapman was arrested in May 2024 and sentenced to 102 months in prison in July 2025 for her participation in the scheme.
See also: North Korean hackers target developers through malicious VS Code projects
In addition, he allowed his North Korean clients to access the U.S. financial system through Money Service Transmitters (rather than opening a bank account within the U.S.). These money transfer services were used to transfer income from work to foreign bank accounts. Authorities said Didenko’s clients were paid hundreds of thousands of dollars for their work.
“Defendant Didenko’s scheme funneled money from Americans and American businesses into the coffers of North Korea, a hostile regime,” said U.S. Attorney Jeanine Ferris Pirro. “Today, North Korea is not only a threat to the homeland from afar, it is an enemy within.”
“Using stolen and fake identities, North Koreans infiltrate American companies, stealing information, licenses, and data that are harmful to any business. But more than that, the money paid to these so-called employees goes directly to North Korea's munitions programs.“.
See also: Amazon: Blocked 1,800 job applications from North Korean agents

Despite ongoing law enforcement actions, the North Korean IT worker continues to evolve with new tactics and techniques to evade detection.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
According to a report from the Security Alliance (SEAL) firm, IT workers have begun applying for remote jobs using the real LinkedIn accounts of the people they are impersonating, in an effort to make their fraudulent applications appear authentic.
