{"id":110428,"date":"2026-08-06T00:33:06","date_gmt":"2026-08-06T00:33:06","guid":{"rendered":"https:\/\/www.europesays.com\/korea\/110428\/"},"modified":"2026-08-06T00:33:06","modified_gmt":"2026-08-06T00:33:06","slug":"a-security-pro-hacked-north-korean-hackers-he-found-theyd-breached-hundreds-of-networks-worldwide","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/korea\/110428\/","title":{"rendered":"A Security Pro Hacked North Korean Hackers. He Found They\u2019d Breached Hundreds of Networks Worldwide"},"content":{"rendered":"<p>For years, <a href=\"https:\/\/www.wired.com\/story\/p4x-north-korea-internet-hacker-identity-reveal\/\" class=\"text link\" rel=\"nofollow noopener\" target=\"_blank\">North Korea\u2019s<\/a> stealthy hackers and scam <a href=\"https:\/\/www.wired.com\/story\/north-korean-it-worker-scams-exposed\/\" class=\"text link\" rel=\"nofollow noopener\" target=\"_blank\">IT workers<\/a> have infiltrated companies, stealing corporate secrets and plundering <a href=\"https:\/\/www.wired.com\/story\/tradertraitor-north-korea-crypto-theft\/\" class=\"text link\" rel=\"nofollow noopener\" target=\"_blank\">billions in cryptocurrency<\/a> to help fund the totalitarian regime and its weapons programs. Now, a security researcher who has spent almost two years inside the systems belonging to a group of those North Korean hackers is raising the alarm on just how effective and far reaching the targeting of individual employees and contractors has been in breaching organizations across the globe.<\/p>\n<p class=\"paywall\">Since Greece-based cybersecurity researcher Vangelis Stykas gained access to North Korean systems 22 months ago, he says, he has found evidence that 1,640 companies across 57 countries have been impacted by the country\u2019s hacking operations. Among these, Stykas will detail at the <a href=\"https:\/\/www.wired.com\/tag\/black-hat\/\" class=\"text link\" rel=\"nofollow noopener\" target=\"_blank\">Black Hat<\/a> security conference in Las Vegas today, around 700 to 800 of the impacted organizations have had \u201creally damaging\u201d intrusions.<\/p>\n<p class=\"paywall\">\u201cIt\u2019s company access, it\u2019s root access to servers, it\u2019s root access to AWS,\u201d the researcher tells WIRED, referring to Amazon Web Services and the term \u201croot\u201d to mean the highest level of permissions in a computer system. \u201cFor crypto companies, it\u2019s keys, it\u2019s blockchain access\u2014it\u2019s ridiculous access.\u201d<\/p>\n<p class=\"paywall\">Stykas, the CTO at cybersecurity firm Kumio, says he accessed multiple command-and-control servers used by the hackers, though he asked WIRED not to reveal the details of how he gained that access due to the sensitivity of that information. In some cases, he notes, the hackers appeared to have infected themselves with their own malware\u2014which, as a result, gave him access to the hackers\u2019 workstations, too. \u201cI have access to their Slack, I have access to their Discord, I have access to a lot of stuff,\u201d Stykas says, adding he has seen around 5 terabytes of data in total.<\/p>\n<p class=\"paywall\">As he probed those systems over months, Stykas identified potential victims\u2014by analyzing developer keys, source code, and more\u2014and says he has disclosed the incidents to those impacted. As part of his talk at Black Hat, Stykas is publicly naming around a dozen of the impacted companies\u2014these are, he says, largely the ones that handled the disclosures well and\/or fixed possible compromises. The researcher says these include the Boston Children\u2019s Hospital (which held a vast Covid-19 database of Americans\u2019 personal health data), the large Japanese tech firm AEON Smart Technology, Chinese phone manufacturer Oppo, cryptocurrency firms Coinbase and Uniswap Labs, Italy\u2019s Supreme Judicial Council, a subsidiary of Saudi Arabian bank Al Rajhi Bank, and Digitaal Vlaanderen, part of the Flemish Government in Belgium.<\/p>\n<p class=\"paywall\">Multiple companies and organizations named in this article did not respond to WIRED\u2019s request for comment about the incidents. Japan\u2019s Computer Emergency Response Team says it confirmed the security researcher\u2019s findings and worked with AEON Smart Technology on \u201cremediation.\u201d<\/p>\n<p class=\"paywall\">\u201cWe can confirm that we were notified of this incident on March 3, 2026 by the Centre for Cybersecurity Belgium (CCB), following the researcher\u2019s disclosure,\u201d a spokesperson for the Flemish government says. \u201cAs part of that response, the affected workstation was isolated and the potentially exposed credentials and access were revoked and rotated. Based on our investigation, the incident has been contained and remediated.\u201d<\/p>\n<p class=\"paywall\">A spokesperson for Boston Children\u2019s Hospital says that the incident \u201cinvolved a former independent contractor&#8217;s personal device\u201d and not the hospital\u2019s systems. \u201cUpon notification, our cybersecurity and IT teams immediately investigated, disabled any remaining active access credentials within hours, and found no evidence of unauthorized access to Boston Children&#8217;s systems,\u201d the spokesperson says, adding that the \u201cdata at issue\u201d was already publicly available.<\/p>\n<p class=\"paywall\">Meanwhile, a Coinbase spokesperson says they <a data-offer-url=\"https:\/\/www.coinbase.com\/en-gb\/blog\/consumer-protection-tuesday-how-coinbase-detects-and-disrupts-sophisticated-hiring-threats\" class=\"external-link text link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.coinbase.com\/en-gb\/blog\/consumer-protection-tuesday-how-coinbase-detects-and-disrupts-sophisticated-hiring-threats&quot;}\" href=\"https:\/\/www.coinbase.com\/en-gb\/blog\/consumer-protection-tuesday-how-coinbase-detects-and-disrupts-sophisticated-hiring-threats\" rel=\"nofollow noopener\" target=\"_blank\">investigated a contractor<\/a>, who they found was in the United States, and \u201cuncovered no evidence that he was either located in North Korea nor affiliated with the DPRK government\u201d before it was reported by the researcher, using DPRK to refer to the Democratic People\u2019s Republic of Korea. \u201cHowever, our security controls identified potential risks in their technology setup, suggesting they may have outsourced their work to a third party, and we terminated the contractor within 30 days of onboarding, prior to receiving a tip from Vangelis Stykas,\u201d the spokesperson says. They add that \u201cno sensitive information was compromised and no customer data was exposed.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"For years, North Korea\u2019s stealthy hackers and scam IT workers have infiltrated companies, stealing corporate secrets and plundering&hellip;\n","protected":false},"author":2,"featured_media":110429,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[56677,1147,56678,1105,56676,31,3110,34,5055],"class_list":["post-110428","post","type-post","status-publish","format-standard","has-post-thumbnail","category-north-korea","tag-black-hat","tag-cybersecurity","tag-defcon","tag-hacking","tag-hacks","tag-korea","tag-malware","tag-north-korea","tag-security"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/posts\/110428","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/comments?post=110428"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/posts\/110428\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/media\/110429"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/media?parent=110428"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/categories?post=110428"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/korea\/wp-json\/wp\/v2\/tags?post=110428"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}