Two Americans were jailed over a $5m scheme. The Justice Department says they helped place North Korean IT workers inside US firms.

How prosecutors say the operation ran

The Justice Department says the scheme put remote IT contractors on U.S. payrolls by making their log-ins and locations look domestic. Prosecutors say the operation ran from 2021 to 2024, during which operators built and ran 'laptop farms' — banks of U.S.-based machines North Korean workers logged into so they looked like local employees.

Federal filings identify two New Jersey residents, Kejia Wang and Zhenxing Wang, as central facilitators. Prosecutors say Kejia Wang ran laptop farms made up of hundreds of machines, and Zhenxing Wang kept some of the devices at his home. The two men are accused of helping co-conspirators steal the identities of more than 80 Americans and obtain work at over 100 US corporations, including some Fortune 500 firms.

According to the Justice Department, the ruse not only generated payroll payments but also gave the North Korean workers access to corporate systems. That access, prosecutors say, was sometimes used to take trade secrets and source code.

In one example cited by the Department, export-controlled data was stolen from a California-based artificial intelligence company.

Money trail and corporate fronts

According to prosecutors, the conspirators hid salary payments behind a web of shell companies and bank accounts. The Justice Department's announcement states that shell entities were created with accounts tied to the fake IT workers so that salaries could be paid and then routed overseas.

The Department calculated that the operation put roughly $5m into the hands of North Korean actors. It also says the American facilitators — including the two men now sentenced — received nearly $700,000 for their work running the domestic infrastructure and processing payments.

The Justice Department has published a reward offer too. Officials said they would pay up to $5m for information that helps counter these schemes, and specifically for details on nine individuals who allegedly worked with Kejia Wang and Zhenxing Wang.

Sentencing and official response

On Wednesday the Department of Justice announced the prison terms. Kejia Wang was sentenced to seven and a half years; Zhenxing Wang received nine years.

Both men were convicted after prosecutors linked them to the laptop farms and the financial structures that hid the true origins of the payroll funds.

John A. Eisenberg, assistant attorney general for National Security, framed the case as more than payroll fraud. "The ruse placed North Korean IT workers on the payrolls of unwitting U.S. Companies and in U.S. Computer systems, thereby harming our national security," he said in the Department's announcement.

The charges prosecuted by the Department included allegations that stolen identities were used to win employment and that payments were later transferred overseas. The Department said the scheme reached dozens of companies and that the defendants and co-conspirators exploited legitimate hiring processes to conceal the true locations and affiliations of remote workers.

Scale and corporate exposure

Prosecutors listed more than 100 corporate victims, a tally that includes large employers across sectors.

The Justice Department's filing doesn't name all of the affected firms, but it notes that some were Fortune 500 companies. This Department said more than 80 stolen identities were used to obtain positions at those firms.

Having real payroll records and working credentials meant companies unknowingly let remote actors into their systems, creating a serious exposure. Firms were, according to prosecutors, unwitting intermediaries. They paid wages to accounts controlled by shell companies, then granted network access and, in several instances, sensitive intellectual property was taken.

One theft cited by prosecutors involved export-controlled material taken from a California-based AI firm. The Justice Department didn't name that company in its announcement, but highlighted the incident to show the kinds of data at risk when foreign actors obtain inside access through falsified employment records.

Legal mechanics and the role of facilitators

Prosecutors described a division of labour inside the conspiracy. Some co-conspirators focused on recruiting and vetting candidates. Others created or managed the technical infrastructure — the laptop farms — that made remote log-ins appear local. A separate group set up shell companies and routed payments through US accounts to obscure the true recipients.

According to the Department, Kejia Wang handled large-scale laptop operations while Zhenxing Wang provided physical hosting. Both men also helped establish the financial conduits that channelled millions out of the United States. In return, the Justice Department said, the US facilitators received payments approaching $700,000 among several named participants.

The Department's investigation spanned multiple years and aimed to tie the domestic enablers to the broader international scheme. Those links formed the basis for charges that range from identity theft and fraud to violations tied to national security concerns.

What firms and investigators face now

Targeted companies are now facing internal inquiries and may have to answer regulators, given the allegations of stolen data and falsified employment. The Justice Department's emphasis on stolen export-controlled information suggests potential civil or regulatory follow-ups where data protection, export compliance and contracting practices are in question.

Investigators may also seek to map the payments trail and the network of shell companies named in the indictment. The Department's reward offer for information on nine alleged collaborators shows that prosecutors view the conspiracy as broader than the two men now sentenced.

For corporate security teams, the case highlights a vulnerability in remote hiring: a candidate can look domestic on paper while being run through overseas channels. This Justice Department framed those vulnerabilities as a national-security threat when the access obtained includes sensitive technologies and export-controlled material.

Prosecutors' broader message

The Justice Department presented the sentence hearings as a warning to would-be facilitators and to foreign actors who would exploit US labour and financial systems. By publicising both the jail terms and the reward offer, officials signalled an appetite to pursue remaining operatives and to recover information that could stop similar networks.

That approach pairs criminal punishment with an intelligence-gathering incentive. The Department's $5m reward offer is meant to elicit tips about alleged collaborators and to build cases against individuals who remain at large. Prosecutors said those efforts are part of wider work to disrupt schemes that feed foreign regimes through fraud.

Related Articles

John A. Eisenberg, assistant attorney general for National Security, said the ruse placed North Korean IT workers in US computer systems and harmed national security.

This article was created with AI assistance.