Jonathan Fritz, former US Deputy Assistant Secretary of State for East Asian and Pacific Affairs and who presented the MSMT report at the United Nations in New York, said North Korean hackers are highly adaptable.

“Basically, they look for places where, you know, folks are not aware of the dangers of the scams that they are really good at [carrying out],” Fritz, who is now senior fellow for China policy at the Center for American Progress, told BIRN.

The hackers, Fritz said, use Chinese banks and, among other methods, cryptocurrency payments, which are more difficult to trace. When a country improves its defences, the hackers move on.

In Bosnia, however, Sasa Mrdovic, Professor of Computer Networks at the Faculty of Electrical Engineering of the University of Sarajevo, said that the state lacks sufficient human and institutional capacities, not to mention the legal framework, to provide the necessary protection.

Shell company

According to the MSMT report, from 2024 onwards North Korean hackers established at least two shell companies registered in the US. They exist only on paper, with no assets or employees.

One of them is Guanghe Technology Development LLC, which the report says was used by North Korean IT workers based in China to secure business contracts with an unnamed Serbian company and to receive payments through an American bank.

According to publicly available registers, Guanghe Technology Development LLC is registered in Florida, with Chengze Li listed as the authorised representative.

Among the company’s corporate documents is one from March 2026 in which the US Office of Foreign Assets Control, OFAC, informed the Florida Department of State that Guanghe Technology Development LLC had been registered by a North Korean IT worker and that all transactions and business activities conducted by the company were for the benefit of the North Korean government.

There is no information in the official registers identifying the Serbian company with which it conducted business.

The Special Prosecutor’s Office for High-Tech Crime, based in Belgrade, said in a written response to BIRN that it was unaware of North Korean IT workers’ activities involving Serbia and that no citizens had contacted the office regarding such matters.

Both Bosnia and Serbia comply with UN sanctions on North Korea, but Serbia – not wishing to anger its big-power allies Russia and China – has not aligned itself with specific European Union sanctions on Pyongyang. North Korea, for its part, does not recognise the former southern Serbian province of Kosovo as independent.

“Unfortunately, our politicians have many things that they consider more important than this, so I think they are aware of it, but it is very rarely high on the list of things they feel they must address,” Mrdovic told BIRN, adding that politicians should realise that they too are not immune.

“This really can happen to any of us,” he said. “The more exposed a person is – and our politicians, like everyone else, are exposed – the more likely they are to find themselves in such a situation.”

The woman from Bosnia agreed: “I thought I was protected, yet something like this still happened to me. I’ve learned that you can never be careful enough, that all sorts of things can happen as long as we’re using the internet.”