Tallinn: Estonian software firms hire remote contractors the way most of Europe now does, through a marketplace, a video call and a bank transfer. That routine has quietly become a sanctions problem, and European governments spent the summer conceding as much.
The European External Action Service issued a spokesperson statement on 31 July describing North Korean cyber operations as causing significant financial harm to the Union, its member states and their partners, and as helping Pyongyang fund unlawful nuclear and ballistic missile programmes. The EEAS framing matters because it treats fraudulent employment, not only intrusion, as the revenue channel.
The scheme works through impersonation rather than hacking. Operatives present themselves as freelance developers from other countries, pass technical interviews, deliver real work and route wages back through intermediaries and cryptocurrency. Clients receive functioning code. They also, without knowing it, pay a sanctioned state.
A Multilateral Sanctions Monitoring Team report published in January set out how far the practice has spread. Eleven participating states, including France, Germany and Italy, documented violations and evasions carried out through cyber and information technology worker activity. European participation in that reporting effort answers a criticism heard for years in Seoul and Tokyo, that the Union talked about the Korean peninsula while leaving enforcement to Washington.
Enforcement remains the weak point. The Union maintains a dedicated North Korea sanctions regime and a separate horizontal cyber sanctions regime, and it has listed individuals and entities under both. Listings punish identified actors. They do not stop a recruiter in Riga from onboarding a contractor whose passport scan looks convincing and whose GitHub history was assembled for the purpose.
That gap points at private due diligence, and here European regulation cuts oddly against itself. Firms operate under strict rules on processing identity documents and on hiring discrimination, and compliance officers report genuine uncertainty about how aggressively they may verify a remote worker’s location without breaching data protection or employment law. Guidance that reconciles the two obligations would help more than another listing round.
Payment infrastructure offers the sharper lever. Wages in these arrangements pass through payroll intermediaries, employer of record platforms and crypto exchanges, and every one of those categories already sits inside European anti money laundering supervision. Supervisors could require platforms to flag the specific patterns that recur in known cases, including mismatched residency, repeated bank changes and payment consolidation across nominally unrelated contractors.
Sceptics raise two fair objections. Excessive verification would push legitimate freelancers from developing economies out of the European market, which is a real cost and not a hypothetical one. And attribution is difficult, so any flagging regime will generate false positives that damage individual reputations with no appeal mechanism. Both arguments argue for proportionate, auditable rules rather than for inaction.
There is also a diplomatic calculation. Brussels has almost no leverage in Pyongyang and no realistic prospect of talks, so its North Korea policy consists largely of sanctions maintenance and coordination with partners. Making that policy bite where the money actually flows, through European employers and European payment rails, is one of the few instruments the Union genuinely controls.
Council will revisit the North Korea listings in the autumn cycle. The useful test will not be how many names are added. It will be whether the Commission publishes practical guidance that a fifty person software company in Tallinn or Porto can actually follow before it signs its next contract.





