EDISON, N.J. — In suburban office suites and residential homes across New Jersey, row after row of high-end corporate laptops remained continuously powered on, illuminated by the faint glow of status LEDs. To human resource directors and IT security teams at over 100 American corporations, these devices appeared to be operating seamlessly from local U.S. addresses.
In reality, the physical keyboards were untouched. The actual inputs were being routed in real-time from state-sponsored North Korean software engineers operating overseas, part of a massive, multi-year cyber-fraud conspiracy designed to funnel million-dollar payrolls straight into Pyongyang's nuclear weapons budget.
In a major victory for the Justice Department's DPRK RevGen: Domestic Enabler Initiative, federal judges sentenced 42-year-old Kejia Wang of Edison, New Jersey, to 108 months (9 years) in prison and 39-year-old Zhenxing Wang of New Brunswick, New Jersey, to 92 months in prison, according to an official U.S. Department of Justice announcement. Both defendants pleaded guilty in U.S. District Court to conspiracy charges including wire fraud, money laundering, and identity theft.
The Case Profile | The Wang Network Ledger
Operating between 2021 and late 2024, the co-conspirators built one of the largest domestic proxy infrastructure networks ever dismantled by federal law enforcement.
Federal Prosecution Matrix
| Key Defendants | Kejia Wang (108 months prison) & Zhenxing Wang (92 months prison) |
| Base of Operations | Edison and New Brunswick, New Jersey (with 8 sub-farms across 3 states) |
| Illicit Revenue Generated | Over $5,000,000 funneled to the North Korean regime |
| Compromised Identities | Stolen personal details of at least 80 U.S. citizens |
| Defrauded Entities | 100+ U.S. corporations, including major Fortune 500 tech & defense contractors |
| Seized Infrastructure | 70+ laptops, KVM adapters, 17 domain names, and 29 financial accounts |
Inside the Operation | From Identity Theft to ITAR Data Exfiltration
The scheme relied on a highly disciplined operational funnel designed to pass every standard corporate vetting protocol during remote onboarding.
The New Jersey Facilitation Pipeline
Identity Harvesting and Synthetic Hiring
Using stolen personally identifiable information from over 80 U.S. citizens, overseas North Korean operatives applied for full-time remote engineering roles at Fortune 500 media networks, financial institutions, and defense firms.
The Multi-State Laptop Farm Network
When victim companies shipped official hardware to their new "American" hires, the devices were delivered directly to locations managed by Kejia and Zhenxing Wang.
Wang Network | Operational Breakdown
| Physical Infrastructure | Federal agents executed coordinated search warrants across eight separate physical locations in three states, recovering over 70 company-issued laptops. |
| KVM Hardware Integration | The laptops were connected to specialized Hardware-over-IP KVM (Keyboard, Video, Mouse) switches, allowing remote control from overseas. |
| Remote Desktop Proxy | By installing unauthorized remote-desktop software, the defendants allowed overseas operatives in China and Russia to control the machines as if they were sitting in New Jersey. |
Corporate Extortion and ITAR Violations
Beyond collecting six-figure salaries, the infiltration posed grave national security risks. Federal prosecutors revealed that between January and April 2024, an overseas North Korean operative remotely accessed a defense contractor's system without authorization, exfiltrating technical data subject to International Traffic in Arms Regulations (ITAR).
In other instances across the national network, when companies discovered the deception and terminated the workers, the North Korean actors attempted to extort the firms by threatening to publish stolen source code on the internet.
The Financial Laundering Pipeline
The Wang network managed an extensive financial apparatus to wash the proceeds. Corporate payroll direct deposits were routed into domestic bank accounts opened under stolen identities, quickly converted into cryptocurrency, and transferred to offshore wallets controlled by the Democratic People's Republic of Korea.
As part of the final court orders, Judge Nathaniel M. Gorton ordered the defendants to serve three years of supervised release and forfeit $600,000 in direct fees paid to them for operating the proxy hubs.
"By operating so-called 'laptop farms,' these defendants enabled overseas actors to infiltrate U.S. businesses, access sensitive data, and undermine our economic and national security."
As federal agencies continue to issue joint alerts with international partners, the prison sentences signal a zero-tolerance stance for domestic facilitators aiding foreign cyber-infiltration.
This case is the fourth chapter in the North Korea IT infiltration story. The Wall Street Journal investigation revealed the $800 million global scale. The Christina Marie Chapman sentencing showed the Arizona laptop farm. The Hopana Tech case exposed the residential proxy technique. The Wang network reveals the multi-state, multi-defendant organizational structure, with eight physical farms across three states coordinated by two defendants working in concert, and introduces the ITAR data exfiltration dimension that elevates the threat from economic fraud to national security breach.