Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
  • Home
  • Attack Feeds
  • Ukrainian sentenced to 5 years in prison for facilitating North Korean remote worker scheme  – CyberScoop
AttackFeed by Joe Wagner | Ukrainian sentenced to 5 years in prison for facilitating North Korean remote worker scheme  - CyberScoop

Ukrainian sentenced to 5 years in prison for facilitating North Korean remote worker scheme  – CyberScoop

Posted on February 19, 2026 By Matt Kapko
Attack Feeds

A Ukrainian national who ran multiple operations to aid the North Korean government’s expansive scheme to  hire remote IT workers at U.S. companies was sentenced to five years in prison, the Justice Department said Thursday.

Oleksandr Didenko stole U.S. citizens’ identities and created more than 2,500 fraudulent accounts on freelance IT job forums, money service transmitters, email services, and social media platforms to sell the proxy identities to North Korean workers. The 29-year-old pleaded guilty to multiple crimes related to the six-year scheme in November 2025.

Didenko ran a site, upworksell.com, to sell the stolen identities and paid co-conspirators to receive and host laptop farms in Virginia, Tennessee and California, according to court records. He managed up to 871 identities through the laptop farms and helped North Korean technical workers gain employment at 40 U.S. companies. 

Didenko funneled money from Americans and U.S. businesses into the coffers of North Korea’s hostile regime, Jeanine Pirro, U.S. attorney for the District of Columbia, said in a statement. 

“Today, North Korea is not only a threat to the homeland from afar, it is an enemy within. By using stolen and fraudulent identities, North Korean actors are infiltrating American companies, stealing information, licensing, and data that is harmful to any business,” she added. 

Officials said Didenko’s North Korean clients were paid hundreds of thousands of dollars for their work, much of which was falsely reported in the names of U.S. citizens whose identities were stolen.

“Money paid to these so-called employees goes directly to munitions programs in North Korea,” Pirro said. “This is not just a financial crime; it is a crime against national security.” 

In late 2023, following a request from one of his customers, Didenko sent a computer to a laptop farm run by Christina Chapman in Arizona, officials said. Chapman was arrested in May 2024 and sentenced to 102 months in prison for participating in the scheme.

Didenko’s site was seized following Chapman’s arrest. He was arrested by Polish police in late 2024, and later extradited to the United States. 

Didenko pleaded guilty to wire fraud conspiracy and aggravated identity theft, and agreed to forfeit more than $1.4 million as part of his sentencing. He was also ordered to pay almost $47,000 in restitution.

U.S. law enforcement has racked up some wins by seizing stolen cryptocurrency and targeting U.S.-based facilitators who provide forged or stolen identities for North Korean operatives. 

Yet, the regime’s scheme runs deep. North Korean nationals have infiltrated many top global companies, and researchers continue to uncover evidence of new tactics and techniques operatives have used to evade detection.

You can read the full indictment below.

Oleksandr-Didenko-indictment-May-2024Download

The post Ukrainian sentenced to 5 years in prison for facilitating North Korean remote worker scheme appeared first on CyberScoop.

  –

Read More  – CyberScoop 

Post navigation

❮ Previous Post: CVE-2026-20841: Arbitrary Code Execution in the Windows Notepad  – Zero Day Initiative – Blog
Next Post: MVP Development in the Age of AI: How Startups Can Build Smarter, Faster and Leaner  – Hackread – Cybersecurity News, Data Breaches, AI and More ❯

You may also like

AttackFeed by Joe Wagner | CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server Paths  - The Hacker News
Attack Feeds
CISA Flags Actively Exploited Wing FTP Vulnerability Leaking Server Paths  – The Hacker News
March 17, 2026
AttackFeed by Joe Wagner | ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ Stories  - The Hacker News
Attack Feeds
ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ Stories  – The Hacker News
May 14, 2026
AttackFeed by Joe Wagner | K2view vs Broadcom For Test Data Management  - Hackread – Cybersecurity News, Data Breaches, AI and More
Attack Feeds
K2view vs Broadcom For Test Data Management  – Hackread – Cybersecurity News, Data Breaches, AI and More
April 22, 2026
AttackFeed by Joe Wagner | How to Protect Your SaaS from Bot Attacks with SafeLine WAF  - The Hacker News
Attack Feeds
How to Protect Your SaaS from Bot Attacks with SafeLine WAF  – The Hacker News
March 2, 2026
  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.