Seoul: For twenty years European governments filed Pyongyang under proliferation. The instruments matched that reading, and they were mostly about physical things: dual-use export licences, shipping registries, port inspections, a list of names attached to a missile programme. The North Korean revenue model has since moved somewhere the paperwork does not reach. A meaningful share of the money financing that programme now arrives as ordinary salary payments, and some of it leaves European bank accounts.
The mechanism is unglamorous. North Korean software engineers, working through stolen or rented identities, apply for remote contracts at firms that never meet them. They pass technical interviews because they are competent. They invoice through intermediaries in third countries, and the wage lands in Pyongyang minus a broker’s cut. The United States has documented the pattern in detail, describing how these workers systematically evade UN sanctions while embedded inside legitimate payrolls.
Two developments in 2026 changed the scale of the problem. First, the same units graduated from earning wages to stealing outright, taking more than two billion dollars in cryptocurrency during 2025 alone. Second, the recruitment posture inverted. Operatives stopped merely applying for jobs and began posing as recruiters, running fake hiring processes at Web3 and artificial intelligence companies to harvest credentials, source code and virtual private network access from real applicants. The job interview became the attack surface.
Washington has responded with speed that Brussels structurally cannot match. Treasury designated a fresh tranche of facilitators in March 2026 and has since targeted the bankers who launder the proceeds. The European Union maintains one of its oldest autonomous restrictive measures regimes against the country, but that regime largely mirrors United Nations designations, and the Union adds names slowly because it adds them by consensus. Enforcement then falls to twenty-seven national authorities with uneven capacity and no shared view of who is actually being paid.
This produces a specific European vulnerability, and it is not primarily a diplomatic one. A mid-sized engineering firm in Bavaria or a fintech in Vilnius is not screening its contractor roster against a sanctions list. It is checking whether the code compiles. Where an American company faces an aggressive regulator and a plaintiffs’ bar, its European counterpart faces neither, so the incentive to verify identity remains weak. The Union has built serious machinery for tracing crypto transfers and for anti-money-laundering supervision, yet almost none of it looks at employment relationships.
The policy question follows from that gap. Sanctions designed for cargo cannot police contracts. Closing the exposure would mean treating remote hiring as a compliance surface, obliging identity verification for contractors paid from the Union into high-risk jurisdictions, and giving national authorities a route to warn firms quickly rather than annually. None of that requires new listings, which is convenient, because new listings are the one thing the Union finds hardest to agree.
Pyongyang has read the asymmetry correctly. It cannot ship much through a sanctioned port, so it ships labour through a laptop instead. Europe kept watching the harbour.




