The inside view of North Korea’s hacking machine: 1,640 companies breached in 57 countries

North Korea’s state hackers made a beginner’s mistake that handed a security researcher a two-year window into their operations: they infected their own computers with their own malware.

Vangelis Stykas, a Greek security researcher and the chief technology officer at Kumio, presented his findings in Las Vegas at Black Hat, the annual security conference. He said he spent roughly 22 months inside command-and-control servers run by North Korean hacking groups, and that the way in was the groups’ own sloppy operations. In several cases the attackers had accidentally contaminated their own workstations with their own tools, which gave Stykas a view straight into their Slack and Discord conversations and the rest of their day-to-day setup. He did not say how he first penetrated their systems.

What he found inside, first reported by Wired, is one of the largest corporate breach campaigns ever documented. Stykas said he identified intrusions at 1,640 companies spread over 57 countries, and that between 700 and 800 of those organizations suffered compromises that included root access to servers, entry into AWS environments, and, at cryptocurrency firms, direct possession of blockchain keys and wallets. In total he pulled roughly five terabytes of their material.

The attack method is nearly identical across the cases. The hackers pose as recruiters, dangle well-paid software development jobs at experienced engineers, and send coding tests that quietly install malware on the candidate’s machine. The Contagious Interview pattern has been on record since around 2022 and has been tracked by Microsoft as part of the wider North Korean cyber operation. Heise reports that the groups previously leaned on compromised credentials, but since the end of 2024 have shifted primarily to this form of social engineering.

Your support allows us to spend more time verifying facts and less time chasing page views.

Keep quality journalism alive

The reach of the campaign runs through contractors. Stykas said he saw individual contractors who held credentials or system access for as many as 30 companies at once, so a single compromised developer could open the door to dozens of organizations. Among the victims he publicly identified are Oppo, Boston Children’s Hospital, Japan’s AEON Smart Technology, Italy’s Supreme Judicial Council, Belgium’s Digitaal Vlaanderen, Coinbase, and Uniswap Labs.

The responses varied. Boston Children’s Hospital traced the incident to a personal laptop once used by a former contractor rather than to its own network, and said it found no sign of unauthorized access. Coinbase said a contractor was let go within weeks of onboarding after security tools raised flags, though it found no evidence the person sat in North Korea or belonged to the regime. The Flemish government confirmed it was notified in March 2025, isolated the affected systems, and rotated credentials. Many other organizations, Stykas said, brushed off his alerts entirely, and hundreds never answered at all. New victims were being added daily.

The money trail explains the focus. Heise, citing Chainalysis data, reports that North Korea stole $2.02 billion in cryptocurrency during 2025, up 51 percent year over year, and roughly $6.75 billion since 2017. In the first four months of 2026, North Korean operations accounted for 76 percent of global cryptocurrency hack losses. The stolen funds demonstrably flow into the country’s nuclear and missile programs, which is precisely why the hacking continues despite international sanctions.

The persistent access is the part that worries security researchers. Marcus Hutchins, the researcher who stopped the WannaCry outbreak, warned that the footholds established for crypto theft could be repurposed for espionage at any time. The campaign also runs in parallel with North Korea’s deployment of thousands of remote IT workers who take salaried roles under stolen identities and send their earnings home; five helpers in the United States recently pleaded guilty to supporting that network in cases that affected more than 136 companies.

Sources: A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide (Wired, Aug 5, 2026); North Korean hackers: Security researcher uncovers worldwide attacks (heise online, Aug 6, 2026); Researcher Finds 1,640 Companies Breached by North Korean Hackers (Omega Technology Solutions Group, Aug 5, 2026)

Scroll to Top