BigTech CompaniesCybersecurityNewswireTechnology

Security Pro Hacks North Korean Hackers, Finds Hundreds of Networks Breached

▼ Summary

– Researcher Vangelis Stykas gained access to North Korean hackers’ systems and found evidence of 1,640 impacted companies across 57 countries, with 700–800 suffering “really damaging” intrusions.
– Stykas accessed command-and-control servers and hackers’ workstations, obtaining around 5 terabytes of data, including access to their Slack and Discord channels.
– Named victims include Boston Children’s Hospital, Japanese firm AEON Smart Technology, Oppo, Coinbase, Uniswap Labs, Italy’s Supreme Judicial Council, a Saudi bank subsidiary, and Digitaal Vlaanderen.
– Boston Children’s Hospital says the incident involved a former contractor’s personal device, not its systems, with no evidence of unauthorized access to hospital networks.
– Coinbase states it terminated a contractor within 30 days of onboarding after finding potential third-party outsourcing risks, prior to Stykas’s tip, with no sensitive information compromised.

For nearly two decades, North Korea’s digital operatives have quietly burrowed into global corporations, siphoning off trade secrets and billions in cryptocurrency to bankroll the regime’s weapons ambitions. Now, a security expert who spent close to two years embedded inside the very infrastructure used by one faction of those state-sponsored hackers is sounding the alarm on how deeply these actors have penetrated businesses worldwide, often through the compromise of individual employees and remote contractors.

Vangelis Stykas, a cybersecurity researcher based in Greece, first gained entry into North Korean-operated systems roughly 22 months ago. Since that initial breakthrough, he has uncovered evidence suggesting that 1,640 companies across 57 countries have been touched by Pyongyang’s hacking apparatus. Speaking ahead of his presentation at the Black Hat security conference in Las Vegas today, Stykas says that between 700 and 800 of those organizations experienced intrusions he characterizes as “really damaging.”

The level of access obtained by the attackers is staggering, according to Stykas. “It’s company access, it’s root access to servers, it’s root access to AWS,” he explains, referencing Amazon Web Services and the highest tier of system permissions. “For crypto companies, it’s keys, it’s blockchain access, it’s ridiculous access.”

Stykas, who serves as CTO at the firm Kumio, declined to specify how he breached the hackers’ command-and-control servers, citing the sensitive nature of that method. In a curious twist, he notes that some of the North Korean operators appeared to have infected themselves with their own malware, inadvertently handing him visibility into their personal workstations. “I have access to their Slack, I have access to their Discord, I have access to a lot of stuff,” he says, adding that he has reviewed roughly 5 terabytes of harvested data.

Over the course of his extended probe, Stykas identified potential victims by sifting through developer keys, source code, and other digital artifacts. He says he has already notified the affected parties about the breaches. During his Black Hat talk, he is publicly naming roughly a dozen organizations, choosing those that responded well to the disclosures or moved quickly to fix vulnerabilities. Among those named are Boston Children’s Hospital, which maintained a massive database of Americans’ personal health data during the Covid-19 pandemic, Japan’s AEON Smart Technology, Chinese smartphone maker Oppo, cryptocurrency platforms Coinbase and Uniswap Labs, Italy’s Supreme Judicial Council, a subsidiary of Saudi Arabia’s Al Rajhi Bank, and Digitaal Vlaanderen, a branch of the Flemish Government in Belgium.

Several of the organizations listed in this report did not respond to requests for comment. Japan’s Computer Emergency Response Team, however, confirmed Stykas’ findings and said it collaborated with AEON Smart Technology on remediation efforts.

A spokesperson for the Flemish government acknowledged the incident, stating, “We can confirm that we were notified of this incident on March 3, 2026 by the Centre for Cybersecurity Belgium (CCB), following the researcher’s disclosure. As part of that response, the affected workstation was isolated and the potentially exposed credentials and access were revoked and rotated. Based on our investigation, the incident has been contained and remediated.”

Boston Children’s Hospital offered a different account, saying the event “involved a former independent contractor’s personal device” rather than hospital infrastructure. “Upon notification, our cybersecurity and IT teams immediately investigated, disabled any remaining active access credentials within hours, and found no evidence of unauthorized access to Boston Children’s systems,” the spokesperson said, adding that the “data at issue” was already publicly available.

Coinbase also pushed back on the characterization of the incident. A spokesperson said the company investigated a contractor who was based in the United States and found “no evidence that he was either located in North Korea nor affiliated with the DPRK government” prior to the researcher’s report. Still, the company’s own security checks flagged potential risks in the contractor’s technology setup, suggesting possible outsourcing to a third party. “We terminated the contractor within 30 days of onboarding, prior to receiving a tip from Vangelis Stykas,” the spokesperson said, stressing that “no sensitive information was compromised and no customer data was exposed.”

(Source: Wired)

Topics

north korean hacking 98% cybersecurity research 95% corporate data breaches 93% cryptocurrency theft 91% insider threats 89% security disclosure 87% cloud security 85% malware infections 83% critical infrastructure 81% incident response 79%