Oleksandr Didenko: Convicted Fraudster Behind a North Korean IT Worker Laptop Farm Scheme
Oleksandr Didenko, a 29-year-old Ukrainian national from Kyiv, Ukraine, is a federally convicted fraudster who operated a multi-year scheme to sell stolen U.S. citizen identities to North Korean IT workers. His operation allowed North Korean operatives to infiltrate at least 40 American companies, earn hundreds of thousands of dollars in fraudulent wages, and funnel those earnings back to the North Korean regime. This blacklist entry is based on the original exposure published at Hucksters.net and verified through official U.S. Department of Justice court records.
Who Is Oleksandr Didenko?
Oleksandr Didenko, also referenced in some records as Alexander Didenko, was born and raised in Kyiv, Ukraine. From 2021 through May 2024, Didenko ran a coordinated fraud infrastructure targeting U.S. businesses, U.S. citizens, and federal agencies including the IRS, DHS, and Social Security Administration. He operated as the central broker connecting stolen American identities with overseas North Korean IT workers seeking remote employment at U.S. firms.
Polish authorities arrested Didenko in 2024. He was extradited to the United States on December 31, 2024. On November 10, 2025, Didenko pleaded guilty in U.S. District Court for the District of Columbia to wire fraud conspiracy and aggravated identity theft before Judge Randolph D. Moss. On February 19, 2026, he was sentenced to 60 months (5 years) in federal prison.
How the Upworksell.com Fraud Scheme Worked
Oleksandr Didenko operated a website called Upworksell.com, which was seized by the U.S. Department of Justice on May 16, 2024. The site openly advertised stolen U.S. citizen identities, stolen credit card information, and SIM card rentals to overseas clients, with North Korean IT workers among his primary customers. These stolen credentials allowed foreign operatives to impersonate American workers on freelance and remote employment platforms based in California and Pennsylvania.
Didenko managed as many as 871 proxy identities at the height of his operation. North Korean clients used these stolen identities to apply for and secure high-paying remote IT positions at U.S. companies across sectors including technology, defense, and finance. The fraudulent workers earned salaries that were then transferred to foreign accounts through money service transmitters, deliberately bypassing U.S. banking systems to avoid detection.
Laptop Farms Across Multiple U.S. States
A core component of Oleksandr Didenko’s fraud network was the establishment of at least three U.S.-based laptop farms. These were physical locations, typically private residences, where multiple laptops were set up and remotely accessed by North Korean IT workers operating from overseas, primarily in China and Russia. The laptop farms gave North Korean workers American IP addresses, making their remote access appear legitimate to employers.
Didenko facilitated laptop farm operations across California, Tennessee, Virginia, and Arizona. He paid U.S. residents in those states to host the equipment and maintain the connections. One of Didenko’s associated laptop farm operators, Christina Marie Chapman of Arizona, was separately prosecuted and sentenced to 102 months in federal prison in July 2025 for her role in managing a laptop farm that serviced 309 companies and generated $17.1 million in fraudulent revenue.
National Security Implications
The fraud scheme run by Oleksandr Didenko was not a simple financial crime. U.S. Attorney Jeanine Ferris Pirro described the operation as directly funneling money from American employers to a hostile foreign regime. The salaries generated through stolen American identities supported North Korea’s weapons and military programs, including its nuclear development efforts.
FBI officials emphasized that this type of scheme poses a direct threat to U.S. economic and national security. North Korean IT workers placed inside U.S. companies through stolen identities gain internal network access. In documented cases involving other firms, those workers used that access to install malware, conduct corporate espionage, and exfiltrate sensitive data. The cybersecurity firm KnowBe4 publicly disclosed a near-miss incident involving a North Korean IT worker hired through exactly this type of fraudulent identity scheme.
Criminal Charges, Conviction, and Penalties
Oleksandr Didenko was convicted on the following federal charges:
- Wire fraud conspiracy
- Aggravated identity theft
His sentence and financial penalties include:
- 60 months (5 years) in U.S. federal prison
- 12 months of supervised release following imprisonment
- Forfeiture of over $1.4 million in criminal proceeds, including $181,438 in USD and cryptocurrency
- $46,547.28 in restitution paid to victims
The sentencing took place on February 19, 2026, before Judge Randolph D. Moss in Washington, D.C. The case was prosecuted by the U.S. Attorney’s Office for the District of Columbia.
Known Details and Identifiers
The following identifying information for Oleksandr Didenko is on record through federal court documents and law enforcement disclosures:
- Full Name: Oleksandr Didenko
- Alias: Alexander Didenko
- Age at Sentencing: 29
- Nationality: Ukrainian
- City of Origin: Kyiv, Ukraine
- Fraudulent Website: Upworksell.com (seized May 16, 2024)
- Scheme Active: 2021 to May 2024
- Arrested: Poland, 2024
- Extradited to U.S.: December 31, 2024
- Guilty Plea: November 10, 2025
- Sentenced: February 19, 2026
Why Oleksandr Didenko Belongs on the Blacklist
Oleksandr Didenko knowingly built and operated a commercial fraud infrastructure designed to deceive U.S. employers, steal the identities of hundreds of American citizens, and enrich a foreign government designated as a state sponsor of terrorism. His website functioned as a marketplace for identity theft, and his laptop farm network gave North Korean operatives the cover they needed to infiltrate American companies undetected for years.
This was not a crime of opportunity. Didenko ran a deliberate, sustained, and profitable criminal enterprise for at least three years before law enforcement shut it down. The victims include the 40 companies defrauded, the hundreds of U.S. citizens whose identities were sold without their knowledge, and the broader American public whose national security was put at risk.
Businesses are urged to review CISA’s guidance on North Korean cyber threats and consult the official DOJ press release on the Didenko sentencing for full details on this case. Additional background on the broader North Korean IT worker threat is available from the FBI’s North Korean IT worker resource page.
Oleksandr Didenko is listed as a confirmed fraudster on Hucksters.net. This blacklist entry serves as a permanent public record warning businesses, recruiters, and individuals to avoid any individual or entity connected to Oleksandr Didenko’s activities.



