my timesThe Korea Times
  1. Opinion
  2. Editorial

ED Lessons from US laptop farm crackdown

Listen
  • Published Jul 2, 2025 2:55 pm KST
  • Updated Jul 2, 2025 4:38 pm KST

US case has implications regarding SKT data leak in South Korea

Four North Korean nationals, Kim Kwang-Jin, Kang Tae-bok, Jong Pong-ju and Chang Nam-il, who have been charged in a five-count wire fraud and money laundering indictment, are seen on an FBI wanted poster released Monday. Reuters-Yonhap

Four North Korean nationals, Kim Kwang-Jin, Kang Tae-bok, Jong Pong-ju and Chang Nam-il, who have been charged in a five-count wire fraud and money laundering indictment, are seen on an FBI wanted poster released Monday. Reuters-Yonhap

U.S. law enforcement has launched a nationwide crackdown on so-called “laptop farms” — where individuals in the U.S. helped North Korean IT workers secure remote jobs at U.S. companies, funneling earnings back to the regime.

On Monday (local time), the FBI announced that several U.S.-based operatives were found to be managing laptop farms, logging into company-issued devices from over 100 organizations. These actions enabled foreign tech workers, including North Koreans, to impersonate U.S.-based employees. The FBI searched 16 states, seizing stashes of laptops used in the scheme.

According to the U.S. Department of Justice, some of these North Korean workers stole sensitive military technology and defrauded a Georgia-based tech company of approximately $740,000. The scheme allowed North Korea to bypass international sanctions and potentially channel illicit earnings into the alleged development of nuclear weapons.

The case has serious implications for South Korea. Sharing a border with the North, Seoul faces direct security threats from Pyongyang’s continued evasion of sanctions to fund its nuclear and missile development.

Even more troubling is the increasing sophistication of North Korea’s digital operations. The FBI revealed that the schemes relied heavily on stolen and fake identities to gain remote employment at more than 100 U.S. firms.

This tactic is especially alarming for South Korea, where identity theft has already become a serious issue. The country’s largest telecom operator, SK Telecom, recently revealed that hackers infiltrated its home subscriber server as early as June 2022. The breach, which went undetected until April this year, has potentially exposed the personal data of nearly 25 million subscribers.

A joint investigation is now underway, involving the National Police Agency, the National Intelligence Service (NIS) and other relevant bodies. On Monday, an official from the Seoul Metropolitan Police Agency, speaking on condition of anonymity, said local investigators are cooperating with law enforcement in five countries, including the U.S., though he declined to name the others.

Experts suggest the hackers behind the SKT breach were not financially motivated, noting the absence of any ransom demands. Attention is now focused on how the stolen identities could be — or may already have been — exploited.

Cybersecurity experts warned that there’s a significant amount of damage hackers can do once they have people’s identities, and in the hands of a regime like North Korea, that information can become a tool for global disruption.

Telecommunications are considered critical national infrastructure, as their networks support essential services such as user communication and information exchange. When data is stolen, it can be weaponized by state-sponsored actors — even in peacetime — to disrupt these vital systems, fueling chaos, social unrest and even political instability. Weaponized data can also be used to interfere in a nation’s political processes.

As demonstrated by North Korean tech workers fraudulently securing U.S.-based jobs, stolen identities can be exploited to generate illicit revenue in third countries, such as through virtual asset theft, or to gain access to sensitive military technologies.

While U.S. tech firms were the immediate victims in the recent laptop farming case, the implications extend to South Korea as well. The incident serves as a stark reminder of the far-reaching risks associated with stolen identities — risks that can go well beyond financial loss.

South Korea is one of the most frequently targeted nations for cyberattacks. According to the NIS, public sector entities alone experienced an average of 1.62 million cyberattacks per day in 2023, marking a 36 percent increase from the previous year. These attacks are typically carried out by state-sponsored operatives or transnational hacking groups.

Despite this alarming trend, South Korea remains largely underprepared for cyber threats. Public awareness of cybersecurity is relatively low, and cyberattacks are not taken seriously by many. If this complacency persists, South Korea risks becoming increasingly vulnerable to cybercrimes with potentially devastating national security consequences.

A dual-pronged response is urgently needed. First, the government must intensify public education on cybersecurity and the real-world dangers posed by cybercrime. Second, it should consider establishing a dedicated committee or state-run agency to assess state-sponsored cyberattacks on critical infrastructure and develop strategic countermeasures.