Microsoft Suspends 3,000 Outlook and Hotmail Accounts Linked to North Korean IT Worker Scam | 2025 Crackdown
In July 2026, Microsoft suspended over 3,000 Outlook and Hotmail accounts tied to North Korea’s APT group "Jasper Sleet," who infiltrated Fortune 500 firms using fake identities and “laptop farms.” These operatives posed as remote IT freelancers to steal sensitive data and fund cyber and weapons programs. The action, coordinated with the U.S. Department of Justice, is part of a wider effort to curb global cyber espionage and protect organizations from insider threats disguised as legitimate remote workers.
Quick answer: Microsoft suspended nearly 3,000 Outlook and Hotmail accounts linked to Jasper Sleet, also called Thallium, a North Korean scheme in which operatives posed as remote IT freelancers using stolen or fake identities. Their pay allegedly funded weapons programmes. Companies should verify identities on video, run thorough background checks and watch for odd remote access, such as laptop farms.
Key takeaways
- Operatives pose as remote workers with stolen or false identities to earn salaries and access company systems.
- Verify identity on video, check references and watch for mismatched locations in remote hiring.
- Microsoft tracks the group as Jasper Sleet.
Table of Contents
- What Was the Operation About?
- How Did the Scam Work?
- Why Microsoft Took Action
- Who Is Jasper Sleet?
- What Are Laptop Farms?
- DOJ’s Global Crackdown
- What This Means for Businesses
- How to Stay Protected
- Conclusion
In July 2026, Microsoft took a major step in global cybersecurity by suspending nearly 3,000 Outlook and Hotmail accounts. These accounts were tied to a North Korean IT worker scheme called “Jasper Sleet” (also known as Thallium). The move is part of a broader international operation involving the U.S. Department of Justice (DOJ), aimed at dismantling North Korea’s hidden cyber workforce, which has been secretly supporting the country’s weapons and surveillance programs.
What Was the Operation About?
The suspended accounts were operated by North Korean nationals who posed as freelance IT professionals working remotely for large U.S. and global companies, many of them Fortune 500 corporations. By blending into the remote tech workforce, they generated millions of dollars, which were allegedly funneled back to fund North Korea’s nuclear and cyber warfare capabilities.
How Did the Scam Work?
These operatives often used stolen or fake identities, and in some cases, rented U.S.-based laptops and IP addresses to appear as American workers. These setups, sometimes referred to as “laptop farms,” were used to trick companies’ HR and IT teams.
Key Tactics Used:
-
Fake resumes and social media profiles
-
Stolen personal details of real people
-
Use of anonymizing tools and VPNs
-
U.S.-based intermediaries to access employer systems
-
Remote desktop access via hired virtual machines or "rented" devices
By gaining trust, these imposters gained access to sensitive internal data, source code, and system infrastructure from the companies they worked for.
Why Microsoft Took Action
Microsoft identified that many of the tools used in these operations relied on Outlook.com and Hotmail.com email addresses. These email accounts were used to:
-
Communicate with employers
-
Register for job portals
-
Set up fake online identities
-
Receive payments from freelance platforms
By shutting down these 3,000+ accounts, Microsoft aimed to disrupt communication channels and break the digital infrastructure that enabled the scam.
Who Is Jasper Sleet?
Jasper Sleet, also known by cybersecurity firms as Thallium, is a North Korean advanced persistent threat (APT) group. They specialize in espionage, cyberattacks, and financial theft. Over the past few years, they have:
-
Infiltrated tech companies
-
Stolen cryptocurrency
-
Distributed spyware via phishing emails
-
Targeted government and defense systems
This recent operation shows their evolution into stealthy employment fraud, allowing them to bypass sanctions by working within the global economy.
What Are Laptop Farms?
“Laptop farms” are physical locations in the U.S. or other Western countries where devices are leased or rented out to foreign workers who want to appear as local employees. These setups help:
-
Mimic local IP addresses
-
Appear on U.S. networks
-
Bypass geofencing and fraud detection
-
Make background checks appear clean
Microsoft’s findings suggest that some American-based laptop farms were unknowingly helping these operatives by leasing resources without understanding their end use.
DOJ’s Global Crackdown
This suspension was coordinated with the U.S. DOJ’s larger crackdown on North Korea’s shadow IT force. This includes:
-
Sanctions on entities aiding Jasper Sleet
-
Seizure of email accounts and domains
-
Indictments of middlemen involved in laundering payments
-
Warnings to companies that may have unknowingly hired these operatives
What This Means for Businesses
The case highlights how critical insider threats and remote work security have become. Companies must:
-
Verify employee identities thoroughly
-
Monitor login behavior and access logs
-
Use strong endpoint protection
-
Educate HR and IT teams on fraud risks
-
Audit freelance platforms and contractor vetting processes
How to Stay Protected
To defend against these types of attacks and fraud schemes, organizations and individuals should:
✅ Use Multi-Factor Authentication (MFA)
Secure logins with an extra layer of protection.
✅ Monitor Unusual Access
Track login times, IP addresses, and device types.
✅ Vet Remote Workers
Use identity verification and video interviews.
✅ Disable Unused Accounts
Remove former contractors' access immediately after contracts end.
✅ Partner With Trusted Platforms
Use platforms that enforce KYC (Know Your Customer) policies.
Conclusion
The suspension of these 3,000 Outlook and Hotmail accounts is not just about email, it represents a global cybersecurity battle. North Korean cyber operatives are using remote work culture, cloud tools, and digital freelancing to slip into organizations undetected. As companies go remote and global, the need to verify identities, monitor networks, and enforce zero-trust principles is more important than ever.
Microsoft’s action, combined with DOJ's crackdown, serves as a strong reminder: Cybersecurity isn't just about firewalls, it's about people, policies, and proactive vigilance.
Related reading
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0