Security Researcher Infiltrates North Korean Hackers, Exposes 1,640 Breached Firms

Original: A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide

Why This Matters

Findings reveal the unprecedented global reach of state-sponsored North Korean cyber intrusions across critical sectors.

Greece-based researcher Vangelis Stykas gained access to North Korean hackers' command-and-control servers 22 months ago, uncovering intrusions across 1,640 companies in 57 countries. He presented findings at Black Hat 2026, naming victims including Coinbase, Boston Children's Hospital, and Oppo.

Cybersecurity researcher Vangelis Stykas, CTO of firm Kumio, has spent nearly two years inside systems belonging to North Korean state-linked hacking groups. Since gaining access to their command-and-control servers 22 months ago, he identified evidence that 1,640 organizations across 57 countries were impacted. Of these, approximately 700 to 800 suffered what Stykas describes as 'really damaging' intrusions, including root-level access to servers, AWS environments, and cryptocurrency keys and blockchain access. Stykas told WIRED he observed around 5 terabytes of data in total and, in some cases, the hackers had accidentally infected their own workstations with malware, granting him access to their Slack and Discord communications as well. He presented his findings at the Black Hat security conference in Las Vegas on August 5, 2026, publicly naming roughly a dozen affected organizations that he says handled disclosures responsibly. Named victims include Boston Children's Hospital, AEON Smart Technology, Oppo, Coinbase, Uniswap Labs, Italy's Supreme Judicial Council, a subsidiary of Al Rajhi Bank, and Digitaal Vlaanderen of the Flemish Government in Belgium. Japan's CERT confirmed Stykas's findings and assisted AEON Smart Technology with remediation. The research underscores the scale of North Korea's global cyber operations, which analysts say fund the regime's weapons programs through cryptocurrency theft and corporate espionage.

Source

wired.com — Read original →