How the Arizona laptop farm worked: North Korean IT workers hired at 309 US companies
For 3 years, a house in suburban Arizona quietly served as the "office" for remote workers at 309 US companies, and the people actually doing the work were North Korean IT workers using stolen American identities.[1] This case file covers how the laptop farm worked, how it was caught, what it cost, and the one control that would have stopped it.
What happened
From October 2020 to October 2023, Christina Marie Chapman of Litchfield Park, Arizona, helped overseas IT workers get and keep remote jobs at American companies by pretending to be US residents.[1] The workers were really in places such as China and Russia, according to prosecutors, and used the stolen or borrowed identities of 68 Americans.[1][3]
The employers included Fortune 500 companies: a top-five television network, a Silicon Valley technology company, an aerospace manufacturer, an American car maker, a luxury retailer and a media and entertainment company. In total, 309 US businesses and 2 foreign ones hired workers through the scheme.[1]
When a company shipped a new hire's laptop, it went to Chapman's house. She kept the machines running there so the workers could log in from abroad, and she shipped 49 laptops overseas, including several to a Chinese city on the border with North Korea.[1] Prosecutors said the scheme generated more than $17.1 million for the workers and for North Korea.[1]
How it worked
Remote hiring removes the moments where an employer would normally notice something is off. Nobody walks into an office, nobody shows a passport at the front desk, and the only physical link to the worker is a shipping address for a company laptop.
The scheme filled each of those gaps. The workers applied using identities that belonged to real Americans, sometimes through staffing agencies.[3] Prosecutors said Chapman helped submit false identity documents to the Department of Homeland Security more than 100 times, the kind of check employers run to confirm someone can legally work in the US.[1] Company laptops arrived at her home, where she set them up so the workers could connect to them remotely. To the employer's network, the worker appeared to be sitting in Arizona.[1][2]
Paychecks followed the same route. Chapman received payroll checks and direct deposits, forged signatures on some checks, and moved the money overseas through her own bank accounts.[1][2] Because wages were reported to the IRS and Social Security in the stolen names, dozens of real Americans ended up with false tax liabilities for jobs they never held.[1][3] Prosecutors said the workers also tried, largely without success, to get jobs at 2 US government agencies.[1]
How it was caught
In October 2023, federal agents searched Chapman's home and found more than 90 laptops. Some carried notes identifying which company and which stolen identity went with each machine.[1][2] She was arrested in May 2024.[2]
On February 11, 2025, she pleaded guilty to conspiracy to commit wire fraud, aggravated identity theft and conspiracy to launder monetary instruments.[1][3] On July 24, 2025, she was sentenced to 102 months in prison, followed by 3 years of supervised release, and ordered to forfeit $284,555.92 and pay a judgment of $176,850.[1][2] A Ukrainian man charged as a co-conspirator was arrested in Poland and faces extradition; he has not been convicted in the US.[2][3]
In January 2025, the FBI warned that North Korean IT workers had moved beyond collecting salaries to stealing company source code and extorting employers with it, and that some used face-swapping technology during video interviews.[4]
The missing control
The missing control: verifying that a new hire is who they say they are and is where they say they are, at hiring and again during onboarding.
Each employer checked paperwork, but the paperwork was the part the scheme had already faked. What the fraud could not easily fake was a live person matching the identity in person or on camera, a laptop that lived with that person, and pay going to an account that matched the name. The FBI's own guidance to employers is to verify identity during interviewing, onboarding and throughout employment, finish hiring in person when possible, and watch for sudden changes to a new hire's shipping address or payment details.[4] Any one of those checks could have exposed a new hire whose laptop sat in a stranger's living room.
What to do in your business
- Meet remote hires on camera, and check their ID live. Ask them to hold their photo ID up during a video call and compare it with the face and name on their application.
- Ship equipment only to a verified address. Send the first laptop to the address on the ID, and treat a last-minute request to ship it somewhere else as a red flag.
- Match the paycheck to the person. Confirm that the bank account for direct deposit is in the new hire's own name, and review any change to it before the next payroll run.
- Ask staffing firms how they verify people. If an agency supplies contractors, get its identity-check process in writing, as the FBI recommends auditing third-party hiring.[4]
- Look for duplicates. Watch for the same phone number, email pattern or nearly identical resume showing up under different names in your applicant pile.[4]
Check your business for this control
The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.
- Guide: Employee offboarding checklist: how to cut off a former employee's access the same day
- Guide: How to verify callers before password resets, and protect your phone number from SIM swaps
- Guide: Which two-step login actually stops phishing, and how a small office rolls it out
- How the SEC's X account was hacked: a fake ID, a SIM swap and no MFA
- How the Colonial Pipeline hack happened: one unused VPN account and no MFA
- How the 2020 Twitter hack happened: a fake help desk call and an admin tool
- How the Mirai botnet knocked Twitter and Netflix offline with factory passwords
- How the Ronin bridge was hacked: a fake job offer and $600 million
- How Uber got hacked in 2022: a stolen password and one tired tap
- Every identity and access control
- All case files
Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.
- US Department of Justice: Arizona woman sentenced for $17M information technology worker fraud scheme that generated revenue for North Korea
- The Record: Arizona woman sentenced for running North Korean laptop farm
- The Record: Arizona woman pleads guilty to running North Korean laptop farm
- FBI IC3: North Korean IT workers conducting data extortion (Alert I-012325-PSA)