← All terms

Laptop Farm

A laptop farm is a home where a facilitator runs many corporate laptops so fraudulent overseas remote workers appear to work from inside the country.

A laptop farm is a physical location — typically a private home or apartment — where a paid facilitator keeps many corporate laptops powered on and connected to the internet on behalf of remote workers who are not who they claim to be. Each machine belongs to a different employer that believes it shipped the device to a legitimate new hire's home address. In reality, the "employee" works from another country, controlling the laptop through remote-access software, while the farm gives their sessions a plausible domestic IP address in the right time zone.

How it works

The laptop farm is the logistics layer of fake IT worker fraud, most prominently the North Korean remote-worker scheme. An operative is hired under a stolen or synthetic identity for a fully remote role; the company then ships the corporate laptop to the address on file. That address belongs to the facilitator, who signs for the device, connects it, and installs remote-desktop tooling so the operative abroad can use it as if sitting at it. Facilitators may manage dozens of machines simultaneously, handle mail and identity paperwork, and receive a cut of each salary. In 2025, the US Department of Justice sentenced an Arizona facilitator to over eight years in prison for a farm that serviced fraud against 309 companies using 68 stolen identities and generated more than $17 million for the DPRK regime.

How to defend against it

The farm is detectable precisely because it breaks the link between the person, the address and the network. Ship equipment only to a verified home address and treat last-minute shipping changes as a flag to investigate, not an admin update. Reconcile the shipping address against payroll and tax records, and check first-login geolocation and network fingerprints against the claimed residence. On the endpoint, alert when consumer remote-access tools or mouse-jiggler software appear on a newly issued machine, and restrict a new hire's initial access so a bad hire has a small blast radius. The full hiring-pipeline defense — identity verification, interview checks and onboarding controls — is covered in our guide to fake IT worker hiring fraud, and role-specific vigilance from recruiters and IT staff is part of a mature human risk management program.

Full guide
Read the deep dive on this attack →

Related terms

Insider ThreatAn insider threat is the risk that employees, contractors, or partners with legitimate access cause harm — maliciously, negligently, or after being compromised.Employment ScamAn employment scam uses a fake job offer, recruiter or new-boss message to steal money, personal data or credentials from job seekers and newly hired employees.DeepfakeA deepfake is AI-generated synthetic media — audio, video, or images — used in social engineering to impersonate trusted individuals convincingly.Synthetic Identity FraudSynthetic identity fraud combines real and fabricated personal data into a new, fake identity used to open accounts, pass checks, or get hired.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo