TrollEye Security

Cyber News

U.S. Justice Department Charges Five in Cyber Scheme Supporting North Korea’s Nuclear Weapons Program

The U.S. Justice Department has charged five individuals, including a U.S. citizen and a Ukrainian national, for running a cyber scheme between 2020 and 2023 that infiltrated the U.S. job

Details of The Story

As reported by Bleeping Computer, the U.S. Justice Department has announced charges against five individuals for their involvement in cyber schemes that allegedly generated revenue for North Korea’s nuclear weapons program. The accused include a U.S. citizen, a Ukrainian national, and three other foreign nationals.

Between October 2020 and October 2023, the group allegedly engaged in a campaign orchestrated by the North Korean government to infiltrate U.S. job markets through fraudulent means. This effort was aimed at raising funds for North Korea’s government and its illicit nuclear activities.

Christina Marie Chapman, a U.S. citizen, and Oleksandr Didenko, a Ukrainian national, were arrested on May 15 in Litchfield Park, Arizona, and on May 7, 2024, in Poland, respectively. The DOJ is now seeking Didenko’s extradition to the United States. Both have been charged with conspiracy to defraud the United States, aggravated identity theft, and conspiracy to commit money laundering, wire fraud, identity fraud, and bank fraud.

Three other foreign nationals, identified only by their aliases Jiho Han, Haoran Xu, and Chunji Jin, face charges of conspiracy to commit money laundering.

If convicted, Chapman could face up to 97.5 years in prison, while Didenko’s maximum sentence could reach 67.5 years. Each of the other three defendants could face a maximum of 20 years in prison.

Chapman allegedly housed computers used by North Korean IT workers in her home, creating a “laptop farm” to make it appear as though the devices were in the United States. These workers were employed as remote software and application developers by multiple Fortune 500 companies, funneling millions in pay from these U.S. companies to North Korea’s nuclear program.

On the other hand, Didenko is accused of running an online platform known as UpWorkSell, which the DOJ has seized. This platform allegedly provided services that allowed North Koreans to use false identities to secure remote IT work. Didenko reportedly managed approximately 871 proxy identities and facilitated the operation of at least three U.S.-based “laptop farms,” hosting around 79 computers. Since July 2018, he is alleged to have sent or received $920,000 in payments.

The scheme compromised over 60 U.S. identities and impacted more than 300 U.S. companies, resulting in false tax liabilities for more than 35 U.S. citizens and generating at least $6.8 million for overseas IT workers.

In response, the U.S. State Department has announced a reward of up to $5 million for any information related to Chapman’s co-conspirators, the North Korean IT workers charged today, and their manager, known only as Zhonghua.

The FBI has also issued an advisory with guidance on how to spot North Korean IT worker schemes and the security risks they pose to companies that hire them. Previous advisories from the U.S. and its foreign partners have warned of such schemes and led to sanctions against multiple organizations involved in generating revenue for North Korea’s IT sector.

Share:

Live Webinar

From Discovery to
Risk Reduction

Operationalizing CTEM in Modern Security Programs

Date September 24, 2026
Time 2:00 PM Eastern

Learn how modern security teams can move beyond finding exposures and operationalize every stage of Continuous Threat Exposure Management.

01 Scope
02 Discover
03 Prioritize
04 Validate
05 Mobilize
Reserve Your Spot

Free registration · Live discussion and Q&A

This Content Is Gated