Researcher uncovers North Korean hack campaign compromising 1,640 firms worldwide
Cybersecurity expert Vangelis Stykas revealed that North Korean hackers have infiltrated 1,640 companies in 57 countries, using fake job offers to gain deep system access.
For almost two years, Vangelis Stykas infiltrated the networks used by North Korean cyber groups, discovering that their operations have affected 1,640 entities across 57 nations. The intrusions often involved contractors lured by bogus high-salary interview offers, which installed malware granting the attackers root access to servers, cloud services and cryptocurrency wallets. Stykas gained entry to the hackers' own workstations, Slack and Discord channels, reviewing around 5 terabytes of material.
He will disclose details at the Black Hat conference, naming about a dozen organizations—such as Boston Children’s Hospital, AEON Smart Technology, Oppo, Coinbase, Uniswap Labs, Italy’s Supreme Judicial Council, an Al Rajhi Bank subsidiary, and Digitaal Vlaanderen—that have either mitigated the breach or cooperated with authorities. Responses varied: the Flemish government confirmed containment, Boston Children’s Hospital said the incident involved a former contractor’s device, and Coinbase reported no evidence of DPRK affiliation. Experts warn that while the current focus is crypto theft, persistent access could enable future espionage.
Why it matters
The breach shows how state-backed hackers can exploit global supply chains, threatening corporate data and crypto assets.
In this story