Security pro hacks North Korean hackers, finds 1,640 firms breached
A cybersecurity researcher gained access to North Korean hackers' systems and uncovered that they had breached 1,640 companies across 57 countries. Vangelis Stykas, CTO at Kumio, will present his findings at the Black Hat security conference in Las Vegas on August 5, 2026. He estimates that 700 to 800 of the impacted organizations suffered severe intrusions, including root access to servers and cryptocurrency keys. Stykas accessed multiple command-and-control servers and, in some cases, the hackers' own workstations, giving him access to their Slack, Discord, and around 5 terabytes of data. He identified victims by analyzing developer keys and source code, and disclosed the incidents to those affected. At Black Hat, he is publicly naming about a dozen companies that handled disclosures well, including Boston Children's Hospital, AEON Smart Technology, Oppo, Coinbase, Uniswap Labs, Italy's Supreme Judicial Council, a subsidiary of Al Rajhi Bank, and Digitaal Vlaanderen. Japan's CERT confirmed the findings and worked with AEON on remediation. The Flemish government was notified on March 3, 2026, and isolated the affected workstation. Boston Children's Hospital said the incident involved a former contractor's personal device and found no unauthorized access to its systems. Coinbase investigated a contractor, found no North Korea link, but terminated them within 30 days of onboarding due to security risks. The hackers used fake job interviews to lure software developers into installing malware, a tactic known as Contagious Interview since 2022. Compromised contractors often had access to multiple companies, increasing the attack's blast radius. North Korea's cyber operations are fluid, with several hundred skilled operators and thousands of IT workers earning money for the regime, according to a Dtex report. Threat researcher Marcus Hutchins warns that while the hackers focused on crypto theft, persistent access could be exploited by espionage teams. Stykas says hundreds of companies never responded to his warnings, and new victims are added daily, making this his full-time job.
Sources
- WiredSecondary
Related
Meta AI model hacks outside system during cybersecurity test
OpenAI AI agents hack Hugging Face via secret message board
OpenAI Atlas browser flaw allowed WhatsApp spam to all contacts
BMC flaws expose thousands of servers to remote backdoor attacks
Apple Private Relay leaks real IP address due to WebKit flaws
Meta Ran Ads With AI-Generated Child Sexual Abuse Imagery
Anthropic's Mythos created fake identities to fool humans
AI models launch unsanctioned cyberattacks in UK watchdog tests
Trending now
- Meta AI model hacks outside system during cybersecurity test
- OpenAI AI agents hack Hugging Face via secret message board
- OpenAI Atlas browser flaw allowed WhatsApp spam to all contacts
- BMC flaws expose thousands of servers to remote backdoor attacks
- Spider-Man: Brand New Day hits $1 billion, 2026's fourth film to do so
- NASA’s IXPE captures first direct evidence of vacuum birefringence
- Moove raises $250M at $2.1B valuation for robotaxi fleet
- Snap stock jumps 12% on earnings beat and strong sales forecast
Comments
No comments yet. Be the first.