OFAC Sanctions DPRK IT-Worker Scheme Facilitator: What Accounting Firms and CFOs Must Act On Now
On 8 July 2025, the US Department of the Treasury's Office of Foreign Assets Control (OFAC) designated Song Kum Hyok, a North Korea-based cyber actor affiliated with the Andariel hacking unit, for his central role in running an illicit IT-worker scheme designed to generate hard-currency revenue for the Kim regime. The same action designated one additional individual and four entities tied to a Russia-based network that contracted North Korean workers directly into technology and crypto companies worldwide. For accounting firms, auditors, and CFOs who manage digital asset payroll or contractor relationships, this action is not just geopolitical news: it carries direct compliance obligations under US sanctions law.
What OFAC Actually Designated and Why It Matters
The Song Kum Hyok Designation
Song Kum Hyok is described by OFAC as a facilitator operating under the Reconnaissance General Bureau (RGB), the North Korean intelligence body that has previously been linked to the Lazarus Group, Bluenoroff, and the Technical Reconnaissance Bureau. His specific role was to recruit DPRK nationals, equip them with falsified identities built from real US citizens' personal data, and place them in remote positions at companies that had no idea they were hiring North Korean operatives. Workers operated physically from China and Russia while presenting themselves as US-based freelancers or employees.
Deputy Secretary of the Treasury Michael Faulkender stated that the action underscores the importance of vigilance against DPRK efforts to clandestinely fund its weapons of mass destruction and ballistic missile programmes through digital asset theft, impersonation of Americans, and malicious cyber operations. That framing is significant: Treasury is treating crypto-enabled contractor fraud as a sanctions-evasion mechanism at the same level as direct hacking.
The Broader Network: Russia-Based Entities
The five additional designations cover entities based in Russia that entered into long-term agreements with North Korean trading firms, effectively serving as a legitimate-looking intermediary layer between DPRK worker pools and Western employers. This structure allowed the scheme to survive routine due-diligence checks: the contracting party on paper was a Russian entity, not a DPRK national. Firms that rely solely on entity-level name screening without probing the beneficial ownership and worker-identity layer are precisely the kind of target this structure was designed to exploit.
How the Payment and Laundering Chain Worked
Stablecoin Salaries and Wallet Fragmentation
Workers in the scheme were typically paid in USDC or USDT, the two dominant stablecoins used for cross-border payroll. Once received, funds moved through a layered laundering sequence: initial receipt at self-hosted or exchange-hosted wallets, fragmentation across multiple addresses to obscure the transaction trail, and eventual consolidation before transfer to senior DPRK operatives. OFAC and the Department of Justice have previously sanctioned two of those senior recipients: Kim Sang Man and Sim Hyon Sop.
Investigators found that over-the-counter brokers, including one sanctioned by OFAC in late 2024, were used to convert aggregated crypto holdings into fiat currency. Russian and UAE-based infrastructure, IP addresses, and forged documentation formed the operational backbone of the scheme's concealment layer.
The DOJ Forfeiture Action of June 2025
A parallel action from the Department of Justice, filed on 5 June 2025 in the District of Columbia, sought forfeiture of more than USD 7.7 million in cryptocurrency, NFTs, and other digital assets tied to the same laundering network. DOJ investigators identified workers using fabricated personas, and traced proceeds routed through centralised exchanges and self-hosted wallets before they reached DPRK-controlled addresses. Seized assets included USDC, ETH, and high-value NFTs, illustrating that the scheme was not limited to simple token payments: it extended into the broader digital asset ecosystem.
Scale: North Korea's Crypto Threat in H1 2025
USD 1.6 Billion Attributed to DPRK Actors
The IT-worker scheme sits within a much larger picture. In the first half of 2025, threat actors stole more than USD 2.1 billion across 75 hacks and exploits tracked across the crypto ecosystem. North Korea-linked actors are attributed with approximately USD 1.6 billion of that total, representing close to 70% of all crypto theft in the period. The bulk of that figure is attributable to the USD 1.5 billion Bybit hack, but the IT-worker channel represents a structurally different risk: it generates revenue through deception rather than technical exploitation, making it harder for traditional exchange-side security controls to catch.
The shift is deliberate. As blockchain analytics and law enforcement capabilities improve at detecting and freezing hack proceeds, DPRK has diversified into income streams that blend into ordinary commercial activity: remote employment, freelance development contracts, and Web3 project work. The fact that payments are in USDC or USDT, the same instruments used by thousands of legitimate remote teams, is not an accident.
Accounting and AML Implications for Firms and CFOs
Sanctions Exposure on Stablecoin Payroll
Under the International Emergency Economic Powers Act and the relevant OFAC regulations, US persons and entities are prohibited from transacting with designated individuals or entities, and that prohibition extends to indirect transactions. A firm that paid a DPRK-linked worker in USDC without knowing the worker's true identity does not automatically avoid liability: OFAC's strict-liability framework means that good faith alone is not a complete defence, though it is a factor considered in penalty determinations.
For any firm running stablecoin-denominated payroll or contractor payments, the practical implication is that wallet-address screening against the OFAC Specially Designated Nationals (SDN) list must happen before each payment, not just at onboarding. Addresses tied to designated parties can appear in the payment chain even if the direct counterparty appears clean, so firms that use a single onboarding screen and then automate recurring transfers are carrying residual sanctions risk.
KYC and Vendor Due Diligence Gaps
The scheme exploited a specific gap: the identity verification process was applied to fabricated personas rather than real individuals. Standard KYC for remote contractors in the crypto space often relies on document submission and liveness checks, but the DPRK network used stolen US personal data that passed those checks. For accounting firms advising crypto-native clients or for CFOs managing Web3 teams, the lesson is that document authenticity is not the same as identity authenticity.
Firms should consider layered verification: cross-referencing submitted identity documents against employer identification records, using video-call protocols with randomised prompt questions, and requiring tax-identification numbers that can be validated against IRS records for US-presented contractors. Where contractors are paid through intermediary entities (as with the Russia-based network in this case), due diligence should extend to the beneficial ownership of that intermediary, not stop at its registered address.
Crypto Accounting Software and Transaction Monitoring
Robust crypto accounting software should be doing more than recording journal entries for stablecoin payroll. The audit trail embedded in the software, including wallet addresses, transaction hashes, and counterparty metadata, becomes the primary evidentiary record if a regulator or law enforcement agency later questions whether a payment reached a sanctioned party. Firms that use digital asset accounting software without exporting transaction-level data to an AML monitoring layer are creating a blind spot that this type of scheme is specifically designed to exploit.
Connecting crypto bookkeeping software outputs to sanctions-screening APIs, and retaining those screening records, is quickly becoming a baseline expectation rather than a best practice. The DOJ's ability to trace the IT-worker proceeds through centralised exchanges and self-hosted wallets in this case was partly possible because of on-chain data; firms that keep clean, timestamped records of their own stablecoin payroll flows are in a far stronger position to demonstrate compliance. For additional context on how enforcement agencies are approaching crypto-related financial crime more broadly, the BDO Worldwatch 2026 white-collar crime trends analysis covers the wider investigative patterns accounting firms need to understand.
Internal Controls: What to Review Now
The designation is an immediate trigger for several internal control reviews. First, any firm that has hired remote contractors in Web3, blockchain infrastructure, software development, or crypto finance roles in the past three years should cross-reference contractor identity records against the updated OFAC SDN list, including the newly added names from this action. Second, wallet addresses used to receive contractor payment confirmations or to send stablecoin payroll should be run through a current OFAC address-screening check, since the SDN list now includes specific crypto addresses associated with the network. Third, any payments routed through Russian or UAE intermediary entities warrant a fresh beneficial-ownership review in light of the Russia-based network structure disclosed by OFAC.
Accounting teams should document each of these steps with dated records. If a subsequent inquiry arises, the ability to show that a proactive screen was conducted promptly after a designation is material evidence of a compliance culture and will be considered in any OFAC penalty analysis. The pattern of escalating enforcement is clear: as covered in our analysis of the US Treasury sanctions on Iranian firms accepting Bitcoin for Hormuz passage, OFAC is consistently treating crypto payments as within the full scope of its enforcement remit.
What Comes Next
Treasury's statement frames this action as part of a continuing campaign rather than a one-off designation. The reference to building out networks of facilitators signals that OFAC intends to move up the chain from individual workers to the infrastructure layer: the brokers, intermediary companies, and platform operators that make the payment flows possible. Firms in the stablecoin payment, crypto payroll, and on-chain HR space should expect further designations and potentially new guidance on due-diligence standards for digital asset contractor payments.
The intersection of AML obligations and crypto accounting is tightening. Accounting firms and CFOs that treat digital asset transactions as outside the scope of their existing financial-crime controls are misreading the regulatory direction. OFAC, DOJ, and FBI have demonstrated in this case that they can and will trace stablecoin flows from employer wallets to DPRK-controlled addresses, and that the companies in between carry liability exposure regardless of intent.
Source: TRM Labs
Frequently Asked Questions
Who did OFAC designate on 8 July 2025?
OFAC designated Song Kum Hyok, a DPRK-based cyber actor affiliated with the Andariel unit under the Reconnaissance General Bureau, along with one additional individual and four Russia-based entities linked to a North Korean IT-worker network. The designations add these parties to the OFAC Specially Designated Nationals list, making it illegal for US persons to transact with them.
How were stablecoins used in this scheme?
Remote workers placed through the scheme were paid in USDC and USDT by unsuspecting US employers. Those funds were then moved through self-hosted wallets and centralised exchanges, fragmented to obscure their origin, and eventually consolidated for transfer to senior DPRK operatives. OTC brokers, including one previously sanctioned by OFAC, were used to convert the proceeds into fiat currency.
Does a firm face sanctions liability if it unknowingly paid a DPRK-linked worker?
OFAC's sanctions regime applies a strict-liability standard: a violation can occur even without knowledge that a designated party was involved. However, OFAC considers factors including good faith, the strength of a firm's compliance programme, and how quickly a firm self-discloses and remediates when calculating penalties. Having documented, up-to-date screening records is the most important mitigant available.
What specific contractor due-diligence steps should firms take now?
Firms should cross-reference all current and recent remote contractor identity records against the updated OFAC SDN list, screen wallet addresses used in stablecoin payroll against OFAC's published crypto-address lists, review the beneficial ownership of any Russian or UAE intermediary entities used in contracting arrangements, and retain dated records of each step. For new hires, layered identity verification that goes beyond document submission, such as IRS tax-ID validation for US-presented contractors, is advisable.
Is this enforcement action limited to US firms?
Primary jurisdiction rests with the US under OFAC and DOJ authority, but the DPRK IT-worker scheme operated globally. Non-US firms that have US dollar or stablecoin exposure, bank with US correspondent institutions, or employ US persons in compliance roles can face secondary risk. Additionally, many other jurisdictions maintain parallel autonomous sanctions regimes against North Korea, so non-US firms should check their own national SDN equivalents alongside the OFAC list.
