On Wednesday, September 16, 2026, the Multilateral Sanctions Monitoring Team (MSMT), a multinational body that tracks compliance with UN sanctions on North Korea, released its third report. It covers the DPRK's overseas labour program. As The Record reported on September 18, the report says that as of July, Pakistan, Vietnam, Laos and Argentina had taken meaningful steps in response to allegations in the team's earlier October 2025 study of North Korean IT-worker schemes.
The Pakistan detail deserves attention because it shows what proportionate enforcement looks like in a country better known for blunt tools.
What Pakistan actually did
According to The Record, Pakistani authorities opened a legal case against Syeda Aliya Batool Zaidi, an alleged forger who supplied North Korean IT workers with fraudulent identification documents. The Federal Investigation Agency is also investigating two other people, named as Syed Sohail Mehdi and Syed Kazim, accused of helping North Koreans do IT work inside the country. These are allegations and investigations, not convictions.
The method matters. Officials went after identifiable people who supplied forged documents and local facilitation. They did not throttle the network or restrict the tools that ordinary users depend on.
The strongest case for tougher network controls
The security case for broad controls is real. The scheme is large. The MSMT's joint statement estimates that between 35,600 and 101,280 North Korean labourers are deployed abroad. It says they generated between US $450 million and $800 million in 2025 for a state that funds nuclear weapons and ballistic missile programs. A July 31, 2026 joint alert from the US, Japan, South Korea and other governments warns that workers increasingly use AI, proxies, VPNs and "laptop farms" to hide who and where they are. A regulator looking at that list could reasonably conclude that VPNs are part of the problem and should be restricted.
Pakistan's own history shows why that instinct has been tempting. In 2020 the Pakistan Telecommunication Authority (PTA) told users to register VPNs with their ISPs by June 30. The Digital Rights Foundation documented that registration required a CNIC national ID number, a stated purpose and the IP address in use, with only 22 days' notice.
Why the blunt version fails on the evidence
First, the mismatch is one of kind. The same July alert that flags VPN use lists the remedies that address the actual fraud. It calls for stronger identity verification by platforms, video interviews and photo-ID checks by hiring firms, domestic legal consequences for contracting with these workers, and enforcement of UN Security Council Resolution 2397. None of that requires banning a privacy tool. It requires checking who you are hiring and prosecuting the forgers. The Pakistani case, which targets identity fraud at its source, follows that logic.
Second, a VPN ban or registration regime would not stop a state-backed operation. A team with forged documents, proxies and laptop farms in multiple countries can also route around a domestic registry. The people who bear the cost are Pakistani freelancers, journalists and businesses. The Digital Rights Foundation warned that a registry of VPN users, shared with ISPs and then with government, undermines the privacy the tool exists to provide. It also noted that vague terms such as "illegal traffic" could be turned against dissent.
Third, Pakistan's economy is already paying for network-level disruption. Access Now counts at least 77 documented shutdowns in Pakistan since 2016. It also reports that a firewall-style Web Management System has slowed the internet since August 2024. It cites the Pakistan Software Houses Association estimate that the IT industry loses over one million dollars per hour to frequent shutdowns. A country that wants to grow an IT export sector cannot credibly police fraud by degrading the connectivity that sector runs on.
What the report does and does not show
The report does not say Pakistan's cases involved VPN restrictions, and this article does not claim they did. It also does not say the three-person investigation has ended the problem. The MSMT says workers operate in about 17 countries, chiefly China and Russia, and the report urges the UN Security Council to reestablish its Panel of Experts, which Russia's April 2024 veto ended. Pakistan's actions are a small piece of a much larger picture.
The narrower lesson still holds. Where a government has evidence about specific forgers and facilitators, it can use existing criminal and identity-fraud law against them. That is faster to defend, easier to audit, and far less costly to legitimate users than blanket controls.
A proportionate path
Pakistan should keep this approach and formalize it. That means resourcing the FIA's cybercrime work, publishing outcomes of these cases so the public can judge them, and sharing identity-fraud indicators with platforms and foreign partners. It also means dropping the recurring proposals to register or ban VPNs and to shut down networks as a security measure. The MSMT report gives Pakistan credit for the first approach. The record of the second approach is a decade of documented shutdowns with real economic cost.