< Back to all clusters
[TECHNOLOGY] · United States, North Korea · 3 sources

started · updated

FBI investigates North Korean IT worker found within U.S. federal agency

The FBI has confirmed it is investigating a case in which a North Korean remote information technology worker successfully obtained employment at a U.S. federal agency. Todd Hemmen, deputy assistant director of the FBI’s Cyber Division, disclosed that the bureau identified the worker within the past week. While the specific agency has not been named, officials believe the worker likely gained access through contract IT support rather than a direct federal position, a recurring vulnerability in government vetting processes.

Simultaneously, the Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch a Microsoft Windows vulnerability being exploited by North Korean hackers. The bug, identified as CVE-2026-68820, affects Winsock and is being used in North Korean campaigns such as ‘Operation Dream Job.’ In these operations, hackers impersonate recruiters for major firms like Lockheed Martin to target individuals in the defense and aerospace industries. CISA has set an August 25 deadline for agencies to apply the necessary patches and restart affected devices.

Entities

CISA · FBI · Lazarus Group · Microsoft · North Korea