Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsStudyTraining
ProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Study
Training
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

1310+ Articles
157+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. New Jersey Men Sentenced to Combined 17 Years for Running
New Jersey Men Sentenced to Combined 17 Years for Running
NEWS

New Jersey Men Sentenced to Combined 17 Years for Running

Two New Jersey men received prison sentences of nine and nearly eight years respectively for operating IT laptop farms that funneled over $5 million to...

Dylan H.

News Desk

April 18, 2026
3 min read

Two New Jersey residents have received lengthy federal prison sentences for their roles in one of the most operationally sophisticated North Korean IT worker fraud schemes prosecuted to date. The Department of Justice announced that Kejia Wang, 42, was sentenced to nine years in federal prison, while Zhenxing Wang, 39, received a sentence of nearly eight years — a combined 17-year sentence reflecting the scale and national security implications of the operation.

The Scheme

The pair ran what prosecutors described as a laptop farm — a physical location stocked with US-registered laptops that North Korean nationals could remotely access to pose as legitimate American IT workers. By routing their connections through US-based hardware, the North Korean workers could bypass geolocation checks and appear as domestic employees to US companies hiring for remote IT and software development roles.

According to the DOJ, the scheme generated more than $5 million in fraudulent income that was ultimately funneled back to the government of North Korea, which uses IT worker revenue to fund its weapons programs and evade international sanctions.

How the Operation Worked

  1. Recruitment — North Korean nationals (operating from North Korea, China, or other third countries) applied for remote IT contractor and software development positions at US companies under false identities
  2. Identity fraud — the defendants provided stolen or fabricated US identities, including Social Security Numbers and fabricated work histories, to make the applications appear legitimate
  3. Laptop farm infrastructure — laptops registered to US addresses were set up and maintained by the defendants; North Korean workers connected remotely, appearing to employers as US-based employees
  4. Payroll interception — wages paid by US employers were collected by the defendants and forwarded, minus a cut, to DPRK-controlled accounts through layered financial transfers

Broader Context

The sentencing follows a years-long FBI and DOJ enforcement campaign targeting DPRK IT worker networks. In 2023, the US government issued a joint advisory with allies warning that thousands of North Korean nationals were embedded as remote workers at technology companies globally. The FBI has estimated these operations collectively generate hundreds of millions of dollars annually for Pyongyang.

Prior prosecutions have named facilitators in the US, Europe, and Asia. The Wang case is notable for the severity of the sentences — reflecting prosecutors' intent to deter others from operating domestic infrastructure in support of sanctions evasion schemes.

Indicators and Detection Guidance

Organizations hiring remote IT workers should watch for:

  • Unusual login patterns — workers logging in via VPN, KVM-over-IP, or remote desktop from unexpected IP ranges
  • Multiple identities on shared hardware — MAC address or device fingerprint inconsistencies
  • Reluctance to appear on video — North Korean workers frequently avoid live video calls or use AI-generated faces
  • Requests to redirect paychecks — rapid changes to payment accounts shortly after onboarding
  • Inconsistencies in credentials — certifications or work history that cannot be independently verified

CISA and the FBI maintain guidance on detecting and reporting suspected North Korean IT worker fraud.

References

  • The Record — NJ Men Sentenced for North Korean Laptop Farms
  • DOJ Press Release
  • FBI / CISA Advisory on DPRK IT Workers

Related Reading

  • American Duo Sentenced for Hosting Laptop Farms for North
  • Iran Deploys
  • TA446 Deploys DarkSword iOS Exploit Kit in Targeted
#APT#North Korea#Nation-State#DOJ#Cybercrime#Insider Threat

Related Articles

American Duo Sentenced for Hosting Laptop Farms for North

Two U.S. men have been sentenced for operating laptop farms that helped North Korean IT workers fraudulently obtain employment at nearly 70 American...

4 min read

Iran Deploys 'Pseudo-Ransomware,' Revives Pay2Key Operations

Iranian APT groups are increasingly blurring the lines between state-sponsored cyber espionage and financially motivated cybercrime, deploying destructive...

6 min read

China-Aligned Groups Ramp Up Attacks: Operation Dragon Weave Hits Czech Republic and Taiwan

Security researchers at Seqrite Labs have uncovered Operation Dragon Weave, a new China-aligned cyber espionage campaign targeting government, research, academic, and financial organizations in the Czech Republic and Taiwan using the AdaptixC2 post-exploitation framework.

6 min read
Back to all News