Cybercrime

Man Helped Individuals in China Get Jobs Involving Sensitive US Government Projects

Minh Phuong Ngoc Vong pleaded guilty to defrauding US companies of roughly $1 million in a fake IT worker scheme.

Minh Phuong Ngoc Vong pleaded guilty to defrauding US companies of roughly $1 million in a fake IT worker scheme.

A Maryland man admitted in court to obtaining remote IT work at US companies on behalf of individuals located in China.

As part of the scheme, the man, Minh Phuong Ngoc Vong, 40, of Bowie, defrauded 13 US companies that hired him as a remote software developer, by allowing others to use company-provided assets to do the IT work and receive payment for it.

To secure the jobs, Vong provided false statements about his education, experience, and training, falsely claiming that he had a Bachelor of Science degree and 16 years of experience in software development.

In January 2023, he submitted such a false resume with a Virginia-based technology company, for a web application developer role that required US citizenship. After verifying his identity and citizenship in March 2023, the company hired him.

Vong was assigned work on a contract for the Federal Aviation Administration (FAA) for an application that US government agencies used to manage sensitive information related to national defense.

The company provided Vong with a laptop and the FAA authorized the issuance of a Personal Identity Verification (PIV) card to him, to access government facilities and systems.

Advertisement. Scroll to continue reading.

After landing the job, Vong, who had no experience in software development, installed remote access software on the laptop so that a foreign national living in Shenyang, China, known as John Doe, and William James, could access the device and conceal his location.

Between March 2023 and July 2023, Doe performed software development work from his location in China, for which the Virginia-based company paid more than $28,000 in wages to Vang, who sent portions of the funds to Doe and other conspirators.

Vong admitted in court to engaging in similar schemes between 2021 and 2024 to obtain employment at 13 US companies on behalf of Doe and other overseas conspirators.

Some of these companies contracted the services to US government agencies, “which unknowingly granted Vong’s co-conspirators access to sensitive US government systems, which they accessed from China,” the Department of Justice notes.

Vong pleaded guilty to wire fraud conspiracy and faces up to 20 years in prison. He is scheduled for sentencing on August 28.

Over the past couple of years, the US government has taken steps to disrupt “laptop farm” operations that enabled individuals overseas to secure remote jobs at US companies.

Some of these laptop farms were employed in North Korean fake IT worker schemes that funneled tens of millions of dollars to the Pyongyang regime. Hundreds of companies are believed to have been affected and the US has sanctioned or charged dozens of individuals involved.

Related: North Korean Fake IT Workers Pose as Blockchain Developers on GitHub

Related: North Korean Fake IT Workers More Aggressively Extorting Enterprises

Related: Fake IT Workers Funneled Millions to North Korea, DOJ Says

Related Content

Cybercrime

Connor Riley Moucka was extradited to the United States in July 2025 after he was arrested in Canada. 

Supply Chain Security

The agency said imports of advanced robots pose cybersecurity and other national security risks.

Government

Chinese cybersecurity firms are facing action from the country’s military, but it’s not due to product or technical failures.

Cyberwarfare

Both foes and allies have targeted the Balochistan Police force in Pakistan for at least two years, according to SentinelOne.

Network Security

Cisco says the threat actor behind the LapDogs campaign has expanded its SOHO router malware toolkit with LongLeash, DogLeash, and JarLeash backdoors.

Cybercrime

Threat actors are selling investment scam templates created using the legitimate DCloud Uni-App toolkit.

Nation-State

Google’s Threat Intelligence Group has been tracking the cyberespionage group as UNC6508 since early 2025.

Government

The 13 websites purported to be affiliated with consulting companies that advertised job openings for current and former holders of security clearances

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version