The Designer Who Went to Prison – Part 1: The Empire
Fashion designer Nancy Gonzalez went to prison for smuggling exotic leather handbags. The luxury retailers who sold them? No charges filed.
Free episodes • $5/mo unlocks case files
Available on all major podcast platforms
Complete written investigation summary
Christina Marie Chapman, a 50-year-old former TikTok creator once classified as homeless in Minnesota, was sentenced to 102 months in federal prison on July 24, 2025, for operating a laptop farm that enabled North Korean IT workers to fraudulently obtain employment at more than 300 American companies. According to the superseding indictment in United States v. Christina Marie Chapman, et al. (Case No. 1:24-cr-00220, D.D.C.), the scheme generated approximately $17.1 million between October 2020 and October 2023, with proceeds funding North Korea’s Munitions Industry Department — the agency that oversees the regime’s ballistic missile program.
According to the statement of offense filed with Chapman’s guilty plea on February 11, 2025, Chapman received company-issued laptops at her Litchfield Park, Arizona residence, addressed to people who did not live there. She installed AnyDesk remote access software on each machine, allowing overseas workers to log in as though they were physically present in the United States. She affixed handwritten notes to each laptop identifying the stolen identity and the corresponding company. When FBI agents executed a search warrant on October 27, 2023, they found more than ninety laptop computers organized on shelves throughout her home.
The government sentencing memorandum describes Chapman forging signatures on I-9 employment eligibility verification forms, depositing payroll checks made out to fictitious employees, and wiring the proceeds overseas. Chapman told a co-conspirator, “I do it practically EVERYDAY!” when asked about the AnyDesk installation process. Her monthly fees from the overseas workers grew from $2,832 to over $12,464 at the scheme’s peak. Her total personal take over three years was $176,850 — roughly one percent of the $17.1 million the operation generated.
The 57-page superseding indictment identifies 309 U.S. companies defrauded through Chapman’s operation. Fortune magazine identified Nike as one victim, reporting approximately $75,000 paid to a North Korean worker using a stolen identity. The indictment describes additional victims by category: a top-five national television network, a Silicon Valley technology company, an aerospace and defense manufacturer, an iconic American car maker, and a high-end retail chain — all Fortune 500 companies. According to the indictment, one North Korean worker operating under the alias “David S.” earned $564,220 from a Silicon Valley company, while another using the name “Frank C.” earned $952,109 from a Detroit automaker.
The statement of offense describes three separate attempts by North Korean IT workers to infiltrate United States government agencies. A worker using the alias “Sion W.” obtained a contractor position at DHS Immigration and Customs Enforcement but failed when ICE required fingerprint verification. Another worker, “Royd L.,” infiltrated the DHS Federal Protective Service, listing Chapman’s address on paperwork and Chapman as his “spouse,” before quitting when fingerprints were requested. Most alarmingly, a worker identified as “Dong C.” was contracted to the General Services Administration, listed Chapman as his spouse, and virtually attended a GSA staff meeting where he introduced himself but was unable to communicate further. Court documents state he attended several additional meetings without speaking before being terminated on October 2, 2023.
The government sentencing memorandum, read aloud during the July 24, 2025 sentencing hearing, quotes Chapman’s own messages acknowledging the criminal nature of her activities. On June 28, 2022, Chapman wrote: “What happens when my bank account gets flagged by the federal government for processing too many large payments and sending them overseas? I get in trouble and go to prison.” On August 2, 2023, she messaged a group chat with the overseas workers: “I can go to FEDERAL PRISON for falsifying federal documents.” Despite these acknowledgments, Chapman continued the scheme for an additional fifteen months after her first documented admission of illegality.
Chapman also tracked federal monitoring of money transfer services, writing that “the feds here are now tracking every penny” on certain services while noting that they had not yet begun monitoring a third. The prosecution described this as countersurveillance conducted from her kitchen table.
Sixty-eight Americans had their identities stolen to facilitate the scheme. Victim impact statements filed with the court describe Cody Willsey, whose identity was stolen during the birth of his newborn child. The stress created postpartum anxiety for his wife and robbed the family of bonding time with their baby. Another unnamed victim was denied unemployment benefits because a North Korean worker was using their Social Security number — the government system showed them as employed when they were not. Chapman herself had been an identity theft victim, writing in her letter to Judge Randolph Moss: “I dealt with identity theft myself and it took me 17 years to recover from the damage it caused me.”
Judge Randolph Daniel Moss sentenced Christina Marie Chapman to 102 months — eight and a half years — in federal prison on July 24, 2025, in Courtroom Eight of the E. Barrett Prettyman Courthouse in Washington, D.C. The court also ordered forfeiture of $284,000 and restitution of $176,850, the exact amount Chapman had personally earned from the scheme. According to the sentencing transcript, Chapman’s allocution consisted of only six sentences. When she heard the name of victim Cody Willsey, she said: “I really hate myself because of that.” She was immediately remanded to custody.
Chapman’s defense sentencing memorandum described a childhood of severe abuse, including physical violence from her brother and sexual abuse by multiple individuals. Her defense argued that Chapman’s involvement began from a place of desperation — she was homeless and caring for a terminally ill mother. Her mother died of renal cancer in April 2023, but the scheme continued for six more months until the FBI raid.
Christina Marie Chapman is currently serving her 102-month sentence in the federal prison system. In her letter to Judge Moss, she expressed interest in working in substance abuse recovery upon release. Her co-defendant Oleksandr Didenko, a Ukrainian national who operated the website upworksell.com to sell stolen American identities, was sentenced to five years in prison in February 2026. The three North Korean co-defendants — Jiho Han, Haoran Xu, and Chunji Jin — remain at large, with a $5 million reward offered for information leading to their capture. At the press conference following Chapman’s sentencing, U.S. Attorney Jeanine Ferris Pirro stated: “The call is coming from inside the house.”
The Department of Justice reported that in June 2025, federal agents raided twenty-nine laptop farms across sixteen states. The United Nations estimates North Korea has deployed approximately 4,000 IT workers worldwide, generating between $250 million and $1 billion annually. CrowdStrike documented a 220% increase in infiltrations over twelve months, and Google’s cybersecurity division Mandiant found that nearly every Fortune 500 CISO surveyed admitted to unknowingly hiring at least one North Korean IT worker.
Verifiable case records used in this investigation
Superseding Indictment — United States v. Christina Marie Chapman, et al.
Government Sentencing Memorandum — United States v. Christina Marie Chapman
Sentencing Hearing Transcript — United States v. Christina Marie Chapman
[0:05] Who do I say I am? That's a real question. [0:11] Typed into a chat window by a woman sitting in her living room in suburban Arizona, she's about to join a Microsoft Teams call with an IT technician at one of the five largest television networks in America. The IT tech thought he was setting up a laptop for a new software engineer named Daniel. There was no Daniel. There was no software engineer. There was a North Korean operative connecting remotely through a laptop that sat on a shelf in this woman's home. One of 90, each labeled with a post-it note bearing a stolen American name. And every paycheck that flowed through those machines was funding North Korea's nuclear weapons program. [1:12] This woman's name is Christina Marie Chapman, and before she ran this operation, she was homeless, living in a travel trailer in Minnesota without running water, documenting her poverty on TikTok for tens of thousands of followers. After the FBI found those 90 laptops, she ended up homeless again in a shelter in Phoenix and then in a federal courtroom where she spoke exactly six sentences before a judge sent her to prison for eight and a half years. Who do I say I am? It's the question that haunts this entire case because Christina Chapman spent her whole life trying to answer it. [2:11] You're listening to True Crime Cases You Haven't Heard, and I'm Steve Rode. If this is your first time here, hit follow, hit subscribe. You can subscribe at truecrimeunheard.com if you want to get behind-the-scenes case files. Nobody in true crime has covered this case, really. The cybersecurity press told it as a tech story, and the business press told it as a corporate threat story. But I'm going to tell it as what it really is. A story about identity. About a woman who had her stolen and spent 17 years recovering. And then stole 68 more. I want you to notice something as you listen. I want you to pay attention to when your sympathy for Christina Chapman starts to crack. Because it will. And where it cracks and what that feels like, that's the real story. [3:23] Hey, welcome back. I'm Steve Rode. I spent 30 years as an investigative writer tracking financial criminals. From Ponzi schemers to corporate fraudsters, I feel like I've seen them all. I also served in emergency services as a police dispatcher, surveillance photographer, and chief pilot for public safety operations. In 30 years of investigating fraud, I've learned something most people don't want to hear. The people who make the worst decisions, they're not usually evil. They're desperate. They're tired. They're one phone call away from losing everything. And someone shows up with an opportunity that looks like salvation. [4:13] And they jump at it. They just don't ask enough questions. That's how christina chapman's story starts but that's not how it ends because at some point and you'll hear exactly when the desperation stopped being the reason and started being the excuse according to her defense sentencing memorandum christina chapman was born in Busan, South Korea. Her dad was a United States Marine, and what followed was a childhood of instability. A dozen schools, constant relocations. Her defense attorneys described social isolation and an inability to form lasting friendships or a sense of belonging. [5:11] The defense filing goes further. Her brother, the document states, repeatedly beat and choked her, held a shotgun to her chest, and once left her so visibly bruised that her school intervened. Her father forced Marie Chapman to apologize to her abuser. And the memo also describes sexual abuse during her childhood by multiple people. It's terrible. [5:42] And I'll be direct. These are claims in a defense filing offered as mitigation, but they do matter because in her own letter to the judge, and I'm quoting, Chapman wrote that she had an addictive personality, low self-esteem, codependency issues, and prone to be easily manipulated by others. And she wrote, I have almost a panic attack-like reaction when I have to say no to someone's request. I've seen that before in other people, especially in the third years of helping people with financial problems who were desperate. That's a pattern I've seen repeated time and time again. But court filings show her one stable relationship was with her mother. And in 2018, her mother was diagnosed with renal cancer. Chapman enrolled in a coding boot camp. She was trying to build something, to become someone. Published reporting describes her as homeless in Minnesota, living in a travel trailer without running water, heat, or even a working bathroom. She posted about it on TikTok. [7:02] Then in March 2020, according to the sentencing transcript, Chapman told the FBI that someone messaged her on LinkedIn, and she was asked to be the U.S. face of their company. You can see how that would seem like a great opportunity in her situation. The defense sentencing memo describes what Chapman understood, and I'm quoting. For the first time in her life, she was financially stable and able to provide for her mother's needs. [7:38] The Wall Street Journal's Bob McMillan later described the pattern. The North Koreans, if they have a superpower, it's identifying people who will do almost anything in a task-rabbit-type style for them. Christina Chapman said, Yes! [8:03] But here's where the record goes quiet. The conspiracy starts in October of 2020 Chapman is still in that travel trailer In Brook Park, Minnesota No running water, no heat No bathroom, And we don't know And the court documents don't tell us How she got from there To a four-bedroom house in Litchfield Park, Arizona, What the indictment does show is this By November 2021, Chapman was charging monthly fees to the overseas IT workers, $2,800 a month to start. By the following summer, over $12,000 a month, she called it rent for hosting their laptops, setting up remote access, handling paperwork. And the prosecution said it plainly at sentencing. She had enough money to rent a nice house And the defense finally put it differently, of course For the first time in her life, she was financially stable By January 2023, she was in that house The scheme was both the job and the paycheck But the gap between the travel trailer and the front door. [9:26] That's part of the story no one's explained to me yet not the prosecution, not the defense, and not Chapman herself. [9:41] According to the statement of offense, the document Chapman signed when she pled guilty, well, here's what she built. Company laptops arrived at her home that she was living in, addressed to people who didn't live there. She set each one up, installed remote access software called AnyDesk, and let overseas workers log in as if they were sitting in Arizona. She taped a handwritten note to each machine with the company name, the identity, and she forged signatures on payroll checks and deposited them, and then wired the money overseas. When a co-conspirator asked if she knew how to install any desk, her response, as documented in a government sentencing memorandum, was, I do it practically every day. [10:40] She charged rent, and the indictment shows her monthly fees grew from $2,800 to over $12,000 a month at the peak. Her total personal take over three years? $176,800 and roughly 1% of the $17.1 million the scheme generated. The other 99% went overseas in support of North Korea. it, according to the government's filing. [11:15] But we should talk about the people on the other end of those any desk connections because, they're not who you think they are the fbi's own 2022 advisory describes, many north korean i.t workers in these schemes as facing conditions the bureau called human trafficking, Long hours, constant surveillance, separation from family And Fortune magazine reported that some had committed suicide because of the working conditions. [11:53] A 23-year-old cybersecurity researcher named Aidan Ranney infiltrated one of these operations He communicated with the workers for months And according to journalist Sasha Ingber's published account, at Christmas, one of the North Korean workers sent Rani a penguin gif with this message. I wish you had a nice rest with your family. Family is the best. Yeah, family is the best from someone who may never see theirs again. After months of communicating with them, Rani told Ingber, And I'm quoting, it was kind of heartbreaking to know that that's their life. So remember that. On one end of this operation was a desperate American woman caring for her dying mother. And on the other end were desperate North Korean men who dream about families they can't see. And the only people who actually benefited were the ones neither of them will ever meet. The regime officials running the Munitions Industry Department. That's the agency that oversees North Korea's ballistic missile program. [13:15] The superseding indictment lays out the scale. Chapman's operation touched 309 U.S. companies. 68 Americans had their identities stolen. Fortune magazine identified Nike as one of the victims. Approximately $75,000 paid to a North Korean worker under a stolen name. The indictment describes the companies in categories. A top-five TV network, a Silicon Valley tech giant, an aerospace and defense manufacturer, an American carmaker, and a high-end retail chain, all Fortune 500 companies. Those numbers are staggering, but they're not the part that made me put the documents down and stare at the wall. The statement of offense describes three separate occasions when North Korean IT workers attempted to infiltrate United States government agencies. One worker using a stolen identity got a contractor position at the Department of Homeland Security, Immigration and Customs Enforcement, ICE, listed Chapman's home address on the paperwork, but failed when ICE required fingerprints. [14:34] Another got a position at the Federal Protective Services, listed Chapman's address, quit when they asked for fingerprints, claiming, ah, death in the family. And then there was Dong C. The court filing shows that Dong C. Was contracted to the General Services Administration. He listed Chapman as his spouse. And then he virtually attended a GSA staff meeting. Right? Picture this. A screen full of government employees on a routine video call. And in one of those little boxes, a North Korean operative, using a stolen American name, connected through a laptop in an Arizona suburb. And he introduced himself. And that was it. The court documents say he was unable to communicate besides introducing himself. He attended several more meetings without speaking, just there, and the GSA terminated him on October 2, 2023. A North Korean agent on a United States government video call, silent, and the only reason he got there was because of a post-it note on a laptop in Litchfield Park, Arizona. [15:55] Are you still sympathizing with Christina Chapman? Well, hold that thought. [16:06] November 2022. The statement of offense describes what happened next. An overseas worker using the screen name AT obtained a software engineering job at a major television network using the stolen identity Daniel B. The company shipped a laptop to Chapman's home. And then the company scheduled a Teams meeting for IT setup. The court filing captures this exchange. AT wrote, we're going to have a laptop setup meeting in 20 minutes. Can you join Teams meetings and follow what the IT guy says? Because it will require to restart the laptop multiple times, and I cannot handle that. Chapman says, who do I say I am? AT says, you don't have to say, I'll be joining there too. Chapman, it's going to have my name on it, right? AT, yeah, you just mute and listen. And then Chapman typed, I just typed in the name Daniel. If they ask why you're using two devices, just say the microphone on your laptop doesn't work right. She added, most IT people are fine with that explanation. [17:35] She's sitting in her Arizona home. A real IT technician at a real television network is on the other end. And Chapman has typed Daniel into the name field. Becoming someone who doesn't exist in a meeting for a job being done by someone in another country. Using another person's stolen social security number. Who do I say I am? whoever they needed her to be. North Korean operatives infiltrated the TV network and attempted access to ICE and the GSA all through one woman's suburban home. And the story gets darker from here. If you haven't subscribed, go to truecrimeunheard.com and subscribe or hit follow. [18:28] Or subscribe on the platform you're listening on. Let's keep going. [18:36] This is where your sympathy should start to fracture, because whatever you've been telling yourself about Christina Chapman, that she was naive, that she didn't understand, that she was just a desperate woman trying to help her mother, the court documents destroy that narrative. And in her own words. The government sentencing memo quotes Chapman messaging a co-conspirator on June 28, 2022, and says, What happens when my bank account gets flagged by these federal government people for processing too many large payments and sending them overseas? I get in trouble and go to prison? I get in trouble and go to prison? [19:24] On August 2nd, 2023, she sent this to a group chat with the overseas workers. Quote, In the future, I hope you guys can find other people to do your physical I-9s. These are federal documents. I will send them for you, but have someone else do the paperwork. I can go to federal prison for falsifying federal documents. Unquote. She capitalized the words federal prison. And she kept going for three more months. She tracked which money transfer services the feds were monitoring. She wrote, quote, The feds here are now tracking every penny on two services. And then added, they aren't doing that on the third yet. The indictment shows her operation had grown so large, she hired two assistants to help manage the laptops. A February 2022 invoice she sent to her handler listed 15 stolen identities working at 17 different companies on a single page. This wasn't a side hustle anymore. This wasn't an opportunity. This was an enterprise. [20:46] I need to step out of the story for a second because this pattern, the essential disposable facilitator, It's one I've seen my entire career, Chapman earned $176,000 over three years That's $58,000 a year For a scheme that generated $17 million, The government's own sentencing memo Called her role one that Would not be successful without a willing U.S.-based facilitator like the defendant, She was the linchpin and she got 1%. Every fraud operation I've ever investigated has someone like this. The person who makes it all work, who stays up late solving problems, who takes the daily risks, and who gets the smallest cut. The masterminds? Well, in this case, agents of the North Korean Munitions Industry Department. They kept the other 99%, and when it falls apart, Hell, the facilitator is the one in the courtroom, Chapman was essential Chapman was cheap And Chapman was expendable. [22:07] Chapman's mother passed away from renal cancer in April 2023 That's according to the defense sentencing memo The person she had been doing all this for was gone, And the scheme continued for six more months, The defense filing tries to explain Even after she realized that the job was not legitimate she continued out of fear of losing the ability to care for her terminally ill mother who passed away in April 2023. [22:46] But the mother died in April and the FBI didn't come until October. What was the fear of losing the ability to care for? I've thought about this a lot. In 30 years of investigating people who cross lines, I've learned the hardest moments aren't the first ones when they decide to do it. It's the moment, the reason they told themselves, poof, evaporates. And they keep going anyway. Chapman's mother was her reason, her only stable relationship, her justification. And when the reason died, she didn't stop, she escalated. The government sentencing memorandum describes what happened in October 2023, six months after her mother's funeral. Chapman was directing a co-conspirator on how to commit in-person bank fraud when he suggested sending someone to impersonate the identity theft victim at a bank branch. Chapman's response, according to the statement of offense, was, We need someone who looks like Andy. [24:07] We need someone who looks like Andy? Six months after burying her mother, the reason was gone, but the operation had become her identity. The laptop farm wasn't something she did anymore. It was now who she was. [24:28] Here's the detail that haunts this case, and it's the one I keep coming back to. In her letter to the judge, Chapman wrote, I dealt with identity theft myself, and it took me 17 years to recover from that damage, and it caused me terrible pain. Knowing that I had a part in that, causing that kind of stress and suffering for others, makes me feel deeply ashamed. 17 years. She spent 17 years fighting to reclaim her own identity. She knew personally and viscerally in her bones what it feels like to have someone steal your social security number. To have the IRS say you owe taxes on wages you never earned To apply for a job and be told someone else is already working under your name. [25:26] And she did that to 68 people. The government sentencing memo describes one victim who was denied unemployment benefits because a North Korean worker was using their social security number. The system said they were employed. They weren't. Another victim, Cody Wilsey, had his identity stolen during the birth of his newborn child. Victim impact statements filed with the court describe the stress creating postpartum anxiety for his wife. They said it robbed them of bonding time with their new baby. Chapman spent 17 years recovering from identity theft, and then she stole 68 identities, not as an abstract crime, but as the exact thing that had been done to her. Who do I say I am? She was an identity theft victim, and she was an identity thief. The same person at the same time. Police, open up! [26:50] October 27th, 2023, Litchfield Park, Arizona. It was a clear sky day. Mid-60s, climbing to the low 80s, a perfectly ordinary desert morning. FBI agents executed a search warrant at Chapman's residence. The government sentencing memo describes what they found. More than 90 laptop computers, each labeled with a post-it note, a company name, Stolen Identity, and all organized on shelves. And when she realized the FBI was there, she grabbed her phone and deleted her conversations with the overseas workers. The filing states she admitted this four days later. [27:38] Then came the mirror image of her rise. Published reporting shows that by December 2023, her savings were gone. She tried selling coloring books on Amazon. She opened an Etsy shop. By August 2024, she was in a homeless shelter in Phoenix. Homeless in Pine City, Minnesota. TikTok star with tens of thousands of followers. And a four-bedroom house because of that. and now homeless again in Phoenix and then a federal courtroom. [28:14] July 24th, 2025, Washington, D.C., one of those humid, oppressive, low 90s days. 2.02 p.m., courtroom 8. The sentencing transcript shows the prosecution reading Chapman's own message aloud for separate admissions from July 2022 through August 2023, in which she acknowledged in her own words that she was committing federal crimes and continued for 15 more months. The prosecution noted that a simple Google search would have shown her that Dandong, the Chinese city where she shipped 35 packages over eight months, sits directly on the North Korean border. Connected by what's known as the Friendship Bridge. She shipped American company laptops to a city connected to North Korea by a bridge called Friendship. And the plea agreement states that without the deal, her sentencing guidelines called for 210 to 262 months. That's 17 and a half to nearly 22 years. [29:39] The judge asked if she wished to address the court. According to the sentencing transcript, Christina Marie Chapman spoke six sentences. Six sentences after three years, after $17.1 million, after 68 stolen identities and 309 defrauded companies, after shipping laptops to a North Korean border, after forging federal documents, after directing bank fraud and after deleting evidence. Six sentences. One of them came after she heard the name Cody Wilson, the man whose identity was stolen during the birth of his child. And she said, I really hate myself because of that. [30:34] Before the sentencing, Chapman had written a letter to the judge, and in it she described trying to escape the people she worked for. She wrote, I've been trying to get away from the guys that I was working for for a while, and I wasn't really sure how to do it. I was tired of feeling pushed into a corner by them. And about the FBI raid, the thing that ended everything, she wrote this, While this wasn't the ideal way to get away from them It did indeed get me away from them And I'm thankful, She was thankful the FBI arrested her And she was thankful because she couldn't find Any other way out. [31:25] The judge sentenced Christina Marie Chapman To 102 months in federal prison, eight and a half years. Forfeiture of $284,000, a judgment of $176,850, the exact amount that she'd earned, every single penny. The sentencing transcript confirms she was immediately taken into custody. No self-surrender, no time to prepare. Deputies escorted her from the courtroom. She walked into courtroom 8 as Christina Chapman And she walked out as a federal prisoner One more identity She didn't choose. [32:20] Christina Chapman's laptop farm was not unique. It was one of many. The Department of Justice reported that in June 2025, federal agents raided 29 laptop farms across 16 states. The United Nations estimates North Korea had deployed roughly 4,000 IT workers worldwide. Fortune magazine reports they generated between $250 million and $1 billion in annual revenue. CrowdStrike documented a 220% increase in infiltrations over 12 months. And Mandiant, Google's cybersecurity division, found that nearly every Fortune 500 chief information security officer who was asked, admitted, they'd unknowingly hired at least one North Korean IT worker. [33:25] At one company, a California defense contractor, court documents from a related DOJ enforcement action describe a North Korean worker accessing data regulated under the International Traffic and Arms Regulations. ITAR, controlled information, military technology specifications in the hands of an agent of a regime building nuclear weapons. [33:54] That's not identity theft anymore. That's espionage. And look, don't fool yourself. It's still happening. It's happening right now as you listen to. [34:09] Thousands of North Korean workers remain embedded in American companies right now. Using stolen names, earning salaries, funding weapons, connected through laptop farms run by Americans who said yes to a message they should have ignored. Christina Chapman is serving her sentence in a federal prison. She told the judge she wants to work in substance abuse recovery when she gets out. She mentioned writing books, and in her letter to the judge, she mentioned wanting to start an underwear company. [34:51] Her co-defendant, a Ukrainian who ran a website called UpworkSell.com, that sold American identities, was sentenced to five years in February 2026. Three North Korean co-defendants remain at large. The $5 million reward stands waiting to be paid. If this happened to these Fortune 500 companies, it can happen or is happening at your company right now. Who are your remote workers? I started this episode with one question. Chapman typed into a chat window, Who do I say I am? [35:40] I don't think she ever really found that answer. Not as a child dragged between 12 schools, not as a homeless woman in Minnesota in a travel trailer, not as a TikTok star earning money with tens of thousands of followers, not as a facilitator of one of the largest North Korean IT worker fraud schemes the DOJ has ever charged. At the end, standing in a federal courtroom, reduced to six sentences. She still didn't know who she was. The 68 Americans whose identities she stole are still fighting to reclaim theirs. The North Korean workers who sent penguin gifts at Christmas are still sitting in rooms somewhere, monitored, separated from their families, and working under names that aren't theirs. And somewhere right now in a quiet suburb, maybe yours, a laptop is sitting on a shelf with a post-it note on it, and someone is saying yes to a message they should have never answered. Who do I say I am? [37:04] The question is still open Until next week I want you to Stay safe Stay curious Stay subscribed And most importantly I want you to stay awesome Yeah Bye.
Christina Marie Chapman is a 50-year-old woman from Pine City, Minnesota, who was sentenced to 102 months in federal prison on July 24, 2025, for operating a laptop farm that enabled North Korean IT workers to fraudulently obtain employment at more than 300 American companies. According to court documents in Case No. 1:24-cr-00220 (D.D.C.), Chapman received company-issued laptops at her Arizona home, installed remote access software, and allowed overseas workers to log in under stolen American identities. The scheme generated $17.1 million between 2020 and 2023.
A North Korea laptop farm is an operation where a U.S.-based facilitator receives corporate laptops at their home address, installs remote access software like AnyDesk, and allows North Korean IT workers to log in remotely under stolen American identities. The workers appear to be located in the United States while actually operating from overseas. Chapman's farm in Litchfield Park, Arizona contained more than 90 laptops, each labeled with Post-it notes bearing stolen names and company identifiers.
Christina Marie Chapman was sentenced to 102 months — eight and a half years — in federal prison by Judge Randolph Daniel Moss on July 24, 2025. She was also ordered to forfeit $284,000 and pay restitution of $176,850. Without the plea agreement, her sentencing guidelines called for 210 to 262 months (17.5 to nearly 22 years). She was immediately remanded to custody after sentencing.
According to the 57-page superseding indictment, 309 U.S. companies were defrauded through Chapman's operation. Fortune magazine identified Nike as one victim, with approximately $75,000 paid to a North Korean worker. Other victims described in the indictment include a top-five television network, a Silicon Valley tech giant, an aerospace and defense manufacturer, an iconic American car maker, and a high-end retail chain — all Fortune 500 companies.
Yes. According to the statement of offense, North Korean IT workers attempted to infiltrate three U.S. government agencies through Chapman's operation. One worker obtained a position at DHS Immigration and Customs Enforcement but failed at fingerprint verification. Another infiltrated the DHS Federal Protective Service before quitting when fingerprints were requested. A third worker, identified as 'Dong C.,' attended a General Services Administration staff meeting via video call but was unable to communicate beyond introducing himself.
FBI agents executed a search warrant at Christina Chapman's residence in Litchfield Park, Arizona on October 27, 2023. They discovered more than 90 laptop computers organized on shelves, each labeled with handwritten Post-it notes bearing stolen identities and company names. Chapman admitted four days later that she had deleted messages with the overseas workers from her phone when she realized the FBI was present.
This episode is built from 402 pages of federal court documents including a 57-page superseding indictment, the statement of offense, the government sentencing memorandum, the defense sentencing memorandum, Chapman's personal letter to Judge Moss, government exhibits presented at sentencing, the 55-page sentencing transcript, the judgment, and the order of restitution — all filed in United States v. Christina Marie Chapman, et al. (1:24-cr-00220, D.D.C.).
The scheme generated approximately $17.1 million in total between October 2020 and October 2023. Chapman's personal share was $176,850 — roughly one percent of the total. Her monthly fees from the overseas workers grew from $2,832 to over $12,464 at the peak. The remaining 99% of proceeds went overseas in support of North Korea's Munitions Industry Department, according to the government's sentencing memorandum.
Sixty-eight Americans had their identities stolen to facilitate the scheme. Victim Cody Willsey had his identity stolen during the birth of his newborn child, creating postpartum anxiety for his wife and robbing the family of bonding time. Another unnamed victim was denied unemployment benefits because a North Korean worker was using their Social Security number. Chapman herself had previously been an identity theft victim, writing that it took her 17 years to recover.
According to the government sentencing memorandum, proceeds from laptop farm schemes like Chapman's fund North Korea's Munitions Industry Department — the agency that oversees the regime's ballistic missile program. The United Nations estimates North Korea has deployed approximately 4,000 IT workers worldwide, generating between $250 million and $1 billion annually. A related DOJ enforcement action described a North Korean worker accessing ITAR-controlled military technology specifications at a California defense contractor.
Chapman's case stands out because she was simultaneously a victim and perpetrator of identity theft. She spent 17 years recovering from having her own identity stolen, then stole 68 American identities for North Korean operatives. She was also homeless before the scheme began and was homeless again after the FBI raid — living in a shelter in Phoenix by August 2024. Despite knowing the scheme was illegal, she continued for months after her mother died, removing her stated motivation for participating.
Co-defendant Oleksandr Didenko, a Ukrainian national who operated upworksell.com — a website that sold stolen American identities — was sentenced to five years in prison in February 2026. The three North Korean co-defendants named in the indictment — Jiho Han, Haoran Xu, and Chunji Jin — remain at large. The U.S. government has offered a $5 million reward for information leading to their capture.
The Department of Justice reported that in June 2025, federal agents raided 29 laptop farms across 16 states. The United Nations estimates North Korea has deployed approximately 4,000 IT workers worldwide. CrowdStrike documented a 220% increase in North Korean infiltrations over 12 months. Google's cybersecurity division Mandiant found that nearly every Fortune 500 CISO surveyed admitted to unknowingly hiring at least one North Korean IT worker.
Chronological sequence of key events
Chapman is born in Busan, South Korea. Her father is a United States Marine. According to her defense sentencing memorandum, her childhood included severe abuse, 12+ school changes, and social isolation.
Chapman's mother, described as her only stable relationship, is diagnosed with renal cancer. Chapman enrolls in a coding bootcamp.
Chapman lives in a travel trailer in Brook Park, Minnesota without running water, heat, or a working bathroom. She documents her struggles on TikTok for tens of thousands of followers.
An unknown co-conspirator contacts Chapman through LinkedIn and asks her to 'be the U.S. face' of their company, according to the sentencing transcript.
The laptop farm conspiracy officially commences according to the statement of offense. Chapman begins receiving corporate laptops and installing remote access software.
Chapman starts charging overseas IT workers $2,832 per month in 'rent' for hosting their laptops and managing their employment paperwork.
An online background check service account is opened; over 1,700 identity queries follow, according to the statement of offense.
Chapman tells a co-conspirator 'I do it practically EVERYDAY!' regarding AnyDesk installation. She also forges I-9 employment eligibility forms, telling a worker: 'I did my best to copy your signature.'
Federal agencies publish a public advisory warning about North Korean IT workers fraudulently obtaining remote employment at U.S. companies.
Chapman writes: 'What happens when my bank account gets flagged by the federal government for processing too many large payments and sending them overseas? I get in trouble and go to prison.'
Chapman's monthly charges to the overseas IT workers reach their peak of $12,464 per month, according to the indictment.
Chapman types 'Daniel' into the name field for a Microsoft Teams setup call with a top-five television network's IT department. She asks her handler: 'Who do I say I am?'
Chapman ships 35 packages over eight months to Dandong, a Chinese city directly on the North Korean border, connected by the Friendship Bridge.
Chapman's mother passes away from renal cancer. The person she described as her sole motivation for participating in the scheme is gone. The scheme continues for six more months.
A worker using the alias 'Royd L.' obtains a position at the DHS Federal Protective Service, lists Chapman's address, and quits before fingerprint verification, claiming 'a death in the family.'
A worker using the alias 'Sion W.' obtains a contractor position at DHS Immigration and Customs Enforcement but fails at the fingerprint requirement.
Chapman messages co-conspirators: 'I can go to FEDERAL PRISON for falsifying federal documents.' She continues the scheme for three more months.
'Dong C.' virtually attends a General Services Administration staff meeting, lists Chapman as his spouse, but is unable to communicate beyond introducing himself. He attends several more meetings without speaking.
Chapman tells a co-conspirator 'We need someone who looks like Andy,' directing physical impersonation of an identity theft victim at a bank branch.
FBI agents execute a search warrant at Chapman's residence and discover more than 90 labeled laptop computers organized on shelves. Chapman grabs her phone and deletes messages with overseas workers.
Four days after the raid, Chapman admits to FBI agents that she deleted her communications with the overseas workers when she learned of the search warrant.
Chapman's savings are gone. She attempts to sell coloring books on Amazon and opens an Etsy shop, according to published reporting.
Christina Marie Chapman is arrested at her residence in Litchfield Park, Arizona.
The superseding indictment is unsealed, revealing the full scope of the conspiracy. The Department of Justice announces a $5 million reward for the three North Korean co-defendants.
Chapman enters a homeless shelter in Phoenix, Arizona — homeless for the second time, mirroring her situation before the scheme began.
Christina Chapman pleads guilty in the U.S. District Court for the District of Columbia. She signs the statement of offense and plea agreement.
Judge Randolph Daniel Moss sentences Chapman to 102 months in federal prison. Her allocution consists of six sentences. She says 'I really hate myself because of that' after hearing victim Cody Willsey's name. She is immediately remanded to custody.
The court enters an order of restitution for $176,850 — the exact amount Chapman personally earned from the scheme.
Oleksandr Didenko, the Ukrainian co-defendant who operated upworksell.com to sell stolen American identities, is sentenced to five years in federal prison.
All information verified against official court records and primary documentation
Every fact cited in this investigation is sourced from official court documents, FBI records, or verified news archives. No speculation or unverified claims.
For Researchers: All court documents available to email subscribers. Citations follow Bluebook legal citation format where applicable.