Laptop Farm
A laptop farm is a home where a facilitator runs many corporate laptops so fraudulent overseas remote workers appear to work from inside the country.
A laptop farm is a physical location — typically a private home or apartment — where a paid facilitator keeps many corporate laptops powered on and connected to the internet on behalf of remote workers who are not who they claim to be. Each machine belongs to a different employer that believes it shipped the device to a legitimate new hire's home address. In reality, the "employee" works from another country, controlling the laptop through remote-access software, while the farm gives their sessions a plausible domestic IP address in the right time zone.
How it works
The laptop farm is the logistics layer of fake IT worker fraud, most prominently the North Korean remote-worker scheme. An operative is hired under a stolen or synthetic identity for a fully remote role; the company then ships the corporate laptop to the address on file. That address belongs to the facilitator, who signs for the device, connects it, and installs remote-desktop tooling so the operative abroad can use it as if sitting at it. Facilitators may manage dozens of machines simultaneously, handle mail and identity paperwork, and receive a cut of each salary. In 2025, the US Department of Justice sentenced an Arizona facilitator to over eight years in prison for a farm that serviced fraud against 309 companies using 68 stolen identities and generated more than $17 million for the DPRK regime.
How to defend against it
The farm is detectable precisely because it breaks the link between the person, the address and the network. Ship equipment only to a verified home address and treat last-minute shipping changes as a flag to investigate, not an admin update. Reconcile the shipping address against payroll and tax records, and check first-login geolocation and network fingerprints against the claimed residence. On the endpoint, alert when consumer remote-access tools or mouse-jiggler software appear on a newly issued machine, and restrict a new hire's initial access so a bad hire has a small blast radius. The full hiring-pipeline defense — identity verification, interview checks and onboarding controls — is covered in our guide to fake IT worker hiring fraud, and role-specific vigilance from recruiters and IT staff is part of a mature human risk management program.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo