Cybersecurity

Security pro hacks North Korean hackers, finds 1,640 firms breached

2 min read

Security pro hacks North Korean hackers, finds 1,640 firms breached
Photo: Markus Spiske · Unsplash
0 0
XWhatsAppTelegramLinkedIn

A cybersecurity researcher gained access to North Korean hackers' systems and uncovered that they had breached 1,640 companies across 57 countries. Vangelis Stykas, CTO at Kumio, will present his findings at the Black Hat security conference in Las Vegas on August 5, 2026. He estimates that 700 to 800 of the impacted organizations suffered severe intrusions, including root access to servers and cryptocurrency keys. Stykas accessed multiple command-and-control servers and, in some cases, the hackers' own workstations, giving him access to their Slack, Discord, and around 5 terabytes of data. He identified victims by analyzing developer keys and source code, and disclosed the incidents to those affected. At Black Hat, he is publicly naming about a dozen companies that handled disclosures well, including Boston Children's Hospital, AEON Smart Technology, Oppo, Coinbase, Uniswap Labs, Italy's Supreme Judicial Council, a subsidiary of Al Rajhi Bank, and Digitaal Vlaanderen. Japan's CERT confirmed the findings and worked with AEON on remediation. The Flemish government was notified on March 3, 2026, and isolated the affected workstation. Boston Children's Hospital said the incident involved a former contractor's personal device and found no unauthorized access to its systems. Coinbase investigated a contractor, found no North Korea link, but terminated them within 30 days of onboarding due to security risks. The hackers used fake job interviews to lure software developers into installing malware, a tactic known as Contagious Interview since 2022. Compromised contractors often had access to multiple companies, increasing the attack's blast radius. North Korea's cyber operations are fluid, with several hundred skilled operators and thousands of IT workers earning money for the regime, according to a Dtex report. Threat researcher Marcus Hutchins warns that while the hackers focused on crypto theft, persistent access could be exploited by espionage teams. Stykas says hundreds of companies never responded to his warnings, and new victims are added daily, making this his full-time job.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.