North Korea Hacks Australia: Firms Targeted & ID Farms Exposed

Australian companies are being infiltrated by a sophisticated network of North Korean operatives posing as remote IT workers, a covert operation aimed at generating funds for Kim Jong-un’s weapons programs and potentially enabling espionage or sabotage, security agencies have warned.

North Korean Infiltration of Australian Firms

The operation, uncovered by Five Eyes security agencies and Australian cyber firm DTEX, involves an army of undercover operatives applying for IT jobs at companies across the country. The scheme nets North Korea an estimated $800 million annually, according to the United Nations.

The deception came to light during a sting operation in which investigators posed as recruiters for an Australian AI and cyber company. One operative, claiming to be an American named Aaron Pierson, struggled to provide basic details about his supposed life in New York and California during a Zoom interview.

“Aaron” was unable to name specific boroughs of New York City, and displayed a lack of knowledge about US professional sports, instead stating a preference for playing soccer. He also appeared visibly different from the profile picture used on his applications.

The earlier version of “Pierson” was a Black American detected during efforts to track the operation. The operative on the Zoom call was Asian and no longer appeared actively seeking employment.

Operation Details and Tactics

ASIO director-general Mike Burgess revealed the scale of the threat, stating that thousands of North Korean agents are actively targeting Australian firms. He warned that the vulnerability could be exploited for espionage, foreign interference, or sabotage.

Law enforcement sources confirmed that major banks, including NAB, have been infiltrated. The Australian Federal Police’s cyber threat teams are assessing intelligence suggesting North Korean agents are already operating within Australia, including a Melbourne University alumnus suspected of acting as an intermediary.

Mohan Koo, founder of cybersecurity company DTEX, said dozens of Australian firms are already compromised, and the situation could worsen. He pointed to the United States, where companies have unwittingly hired North Korean agents as remote IT workers for a decade.

The FBI has warned that the operation is becoming “increasingly malicious” and has urged US companies to strengthen their defenses. Burgess and Koo are now issuing the same urgent plea to Australian businesses.

The operation relies on a lack of robust security checks during online recruitment. North Korean operatives often use stolen identities and falsified documents, such as a photoshopped water bill used to create false Australian identities, as discovered by DTEX investigators.

Case Studies and Warnings

A recent case in the United States involved Christina Chapman, an Arizona woman who was jailed for 8½ years for hosting a “laptop farm” for North Korean remote workers. She received and operated computers sent to operatives after they were hired online under false pretenses.

US Attorney Jeanine Pirro emphasized that even large companies like Nike have been vulnerable to this type of deception. She warned that Australia is a fertile ground for these operations due to a lack of suspicion and ease of identity theft.

DTEX investigators have uncovered evidence of North Korean operatives using multiple online profiles and coordinating their efforts. One operative was photographed with other regime members visible in the background of a selfie, revealing a likely military facility as his workplace.

Burgess expressed frustration that some Australian companies are not taking the threat seriously. He emphasized the potential for disruption, ransom, or sabotage if operatives gain access to critical systems.

The North Korean operation is bolstered by technical support from China and the increasing use of artificial intelligence to create convincing online personas and bypass security measures.

When confronted with inconsistencies, the operative posing as “Aaron Pierson” abruptly ended the Zoom call, demonstrating the lengths to which these agents will go to conceal their true identities.

Worth a look


Discover more from Archyworldys

Subscribe to get the latest posts sent to your email.