discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide

A security researcher, Vangelis Stykas, gained access to North Korean systems and found evidence of 1,640 companies across 57 countries being impacted by the country's hacking operations. Among these, around 700 to 800 organizations had 'really damaging' intrusions.

By Vangelis Stykas·Aug 5·wired.com·5 min read

Intelligence analysis by Llama

A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide
Image: wired.com

A security researcher, Vangelis Stykas, accessed North Korean systems and found evidence of 1,640 companies across 57 countries being impacted by the country's hacking operations. The researcher identified potential victims by analyzing developer keys, source code, and more, and disclosed the incidents to those impacted.

Why it matters

The findings highlight the effectiveness and far-reaching targeting of individual employees and contractors by North Korean hackers, which has resulted in significant breaches of corporate secrets and cryptocurrency theft.

Imagine you're a software developer, and you get a job offer that seems too good to be true. You download a program to test your coding skills, but it secretly installs malware on your machine. This is how North Korean hackers have been breaching companies worldwide, gaining access to sensitive data and cryptocurrency wallets. A security researcher, Vangelis Stykas, has been tracking these hackers and found evidence of 1,640 companies across 57 countries being impacted.

Analysis

A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide

For years, North Korea's stealthy hackers and scam IT workers have infiltrated companies, stealing corporate secrets and plundering billions in cryptocurrency to help fund the totalitarian regime and its weapons programs. Now, a security researcher who has spent almost two years inside the systems belonging to a group of those North Korean hackers is raising the alarm on just how effective and far reaching the targeting of individual employees and contractors has been in breaching organizations across the globe.

Since Greece-based cybersecurity researcher Vangelis Stykas gained access to North Korean systems 22 months ago, he says, he has found evidence that 1,640 companies across 57 countries have been impacted by the country's hacking operations. Among these, Stykas will detail at the Black Hat security conference in Las Vegas today, around 700 to 800 of the impacted organizations have had 'really damaging' intrusions.

"It's company access, it's root access to servers, it's root access to AWS," the researcher tells WIRED, referring to Amazon Web Services and the term 'root' to mean the highest level of permissions in a computer system. "For crypto companies, it's keys, it's blockchain access—it's ridiculous access."

Stykas, the CTO at cybersecurity firm Kumio, says he accessed multiple command-and-control servers used by the hackers, though he asked WIRED not to reveal the details of how he gained that access due to the sensitivity of that information. In some cases, he notes, the hackers appeared to have infected themselves with their own malware—which, as a result, gave him access to the hackers' workstations, too.

"I have access to their Slack, I have access to their Discord, I have access to a lot of stuff," Stykas says, adding he has seen around 5 terabytes of data in total. As he probed those systems over months, Stykas identified potential victims—by analyzing developer keys, source code, and more—and says he has disclosed the incidents to those impacted.

As part of his talk at Black Hat, Stykas is publicly naming around a dozen of the impacted companies—these are, he says, largely the ones that handled the disclosures well and/or fixed possible compromises. The researcher says these include the Boston Children's Hospital (which held a vast Covid-19 database of Americans' personal health data), the large Japanese tech firm AEON Smart Technology, Chinese phone manufacturer Oppo, cryptocurrency firms Coinbase and Uniswap Labs, Italy's Supreme Judicial Council, a subsidiary of Saudi Arabian bank Al Rajhi Bank, and Digitaal Vlaanderen, part of the Flemish Government in Belgium.

Multiple companies and organizations named in this article did not respond to WIRED's request for comment about the incidents. Japan's Computer Emergency Response Team says it confirmed the security researcher's findings and worked with AEON Smart Technology on 'remediation.' "We can confirm that we were notified of this incident on March 3, 2026 by the Centre for Cybersecurity Belgium (CCB), following the researcher's disclosure," a spokesperson for the Flemish government says. "As part of that response, the affected workstation was isolated and the potentially exposed credentials and access were revoked and rotated. Based on our investigation, the incident has been contained and remediated."

A spokesperson for Boston Children's Hospital says that the incident 'involved a former independent contractor's personal device' and not the hospital's systems. "Upon notification, our cybersecurity and IT teams immediately investigated, disabled any remaining active access credentials within hours, and found no evidence of unauthorized access to Boston Children's systems," the spokesperson says, adding that the 'data at issue' was already publicly available.

Meanwhile, a Coinbase spokesperson says they investigated a contractor, who they found was in the United States, and 'uncovered no evidence that he was either located in North Korea nor affiliated with the DPRK government' before it was reported by the researcher, using DPRK to refer to the Democratic People's Republic of Korea. "However, our security controls identified potential risks in their technology setup, suggesting they may have outsourced their work to a third party, and we terminated the contractor within 30 days of onboarding, prior to receiving a tip from Vangelis Stykas," the spokesperson says. They add that 'no sensitive information was compromised and no customer data was exposed.'

In fact, while many of those companies held highly sensitive data that the hackers could have theoretically accessed—aside from the Boston Children's Hospital's store of health data, another US company held vast access to Americans' criminal records, Stykas says—the hackers largely maintained a tight focus on gaining access to cryptocurrency wallets and ignored other systems.

In the cases of almost all of the hundreds of hacked firms—as well as the larger thousand-plus group of organizations where the North Korean intruders gained at least a foothold—the hackers used a simple and well-documented tactic of luring software developers with fake job offers promising temptingly high salaries. Once the target took the bait, the engineer would be asked to download a program as a test of their coding abilities, which would silently install malware on their machine. North Korean hacker groups have used that fake interview hacking technique in a broader campaign known as Contagious Interview since as early as 2022, according to Microsoft.

For many of the impacted organizations, Stykas says, seemingly compromised external contractors, who often held developer keys or had system access to multiple systems, vastly increased the potential blast radius of a successful attack.

Key points

  • North Korean hackers have breached 1,640 companies across 57 countries.
  • The hackers used a tactic of luring software developers with fake job offers to gain access to sensitive data and cryptocurrency wallets.
  • A security researcher, Vangelis Stykas, has been tracking these hackers and found evidence of the breaches.
  • The researcher has disclosed the incidents to those impacted and publicly named around a dozen of the impacted companies.
The Upside

The findings by Vangelis Stykas highlight the effectiveness of security researchers in tracking and exposing North Korean hacking operations. If this development plays out positively, it could lead to increased cooperation between governments and private companies to combat these threats.

The Downside

The scale of the breaches and the ease with which North Korean hackers have gained access to sensitive data and cryptocurrency wallets raise concerns about the potential for further attacks. If this development plays out negatively, it could lead to a significant increase in cybercrime and a loss of trust in online systems.

Originally reported at

wired.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritynorth-koreahackingcybersecuritycryptocurrencybreaches

Author

Vangelis Stykas

Intelligence analysis by

Llama

Published

Aug 5, 2026

Source

wired.com

Share

Topics

securitynorth-koreahackingcybersecuritycryptocurrencybreaches

Related

More from this desk

Aug 5·bleepingcomputer.com

Ransom Cartel ransomware creator sentenced to 16 years in prison

Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for his role in ransomware attacks against at least 18 companies worldwide.

Aug 5·bleepingcomputer.com

Canadian pleads guilty to Snowflake cloud data-theft attacks

A Canadian man pleaded guilty to stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims. The data was accessed through Snowflake's storage service without multi-factor authentication.

Aug 5·wired.com

DHS Wants Protesters’ Signal Group Chats

The Department of Homeland Security is seeking neighborhood “rapid response” Signal group chats as it defends itself in a lawsuit accusing it of violating protesters’ First Amendment rights.

Aug 5·bleepingcomputer.com

Hackers run khunt post-exploitation toolkit from Oracle database

Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate network. The attack was discovered by Huntress on July 27, 2026, after its security platform detected credential t…