Amazon has prevented more than 1,800 North Korean workers from securing remote positions at the company as Pyongyang deploys IT specialists overseas to generate and launder funds, French news agency AFP reported on December 23.
According to newly released details, Chief Security Officer Stephen Schmidt stated on LinkedIn that North Korean workers have been attempting to secure remote IT positions with companies worldwide, particularly in the US. The firm recorded a nearly one-third increase in applications from North Koreans over the past year.
The workers typically employ "laptop farms", computers located in the United States operated remotely from outside the country. Schmidt identified tell-tale signs including incorrectly formatted telephone numbers and fraudulent academic credentials.
Schmidt warned the problem extends beyond Amazon and "is likely happening at scale across the industry".
A woman in Arizona received more than eight years in prison in July for operating a laptop farm that helped North Korean IT workers secure remote positions at more than 300 US companies. The operation generated more than $17mn in revenue for her and North Korea, according to officials.
Hong Min, an analyst at the Korea Institute for National Unification, stated that North Korea actively trains cyber personnel and infiltrates key locations worldwide. He suggested the operation targeting Amazon was likely motivated by economic objectives with a high probability of aiming to steal financial assets given the company's business nature.
Seoul's intelligence agency warned last year that North Korean operatives used LinkedIn to pose as recruiters and approach South Koreans working at defence firms to obtain technology information.
North Korea's cyber-warfare programme dates to at least the mid-1990s and has expanded into a 6,000-strong cyber unit known as Bureau 121 operating from several countries, according to a 2020 US military report.
Washington announced sanctions in November on eight individuals accused of being state-sponsored hackers conducting illicit operations to fund the regime's nuclear weapons programme through theft and money laundering.
The US Department of the Treasury has accused North Korea-affiliated cybercriminals of stealing more than $3bn over the past three years, primarily in cryptocurrency.