Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
CrowdStrike: North Korean Hackers Accounted for 47% of All State-Backed Intrusions in U.S. Tech Sector Over the Past Year

North Korea Is Running a Massive Hired-Hacker Racket Inside American Companies
CrowdStrike's annual global threat report, covering April 2025 through May 2026, found that a North Korean hacking group the company tracks as Famous Chollima was responsible for 47% of all state-backed hands-on-keyboard intrusions targeting the U.S. tech sector during that period. According to TechCrunch's reporting on the CrowdStrike findings published June 10, 2026, that figure makes North Korea the single dominant foreign cyber threat to American tech companies — not Russia, not China, not Iran. Nearly one in two documented state-sponsored attacks on U.S. tech firms trace back to Pyongyang.
How the Scheme Actually Works
Famous Chollima operatives don't brute-force their way in. They apply for jobs.
They pose as software developers, coders, and IT contractors, submitting applications to U.S., European, and Asian tech companies under fabricated identities. According to CrowdStrike via TechCrunch, the operatives use AI-generated deepfake imagery to spoof real people's faces in real time during video interviews, paired with fraudulent identity documents — stolen passports, fake driver's licenses — to present themselves as American or other foreign nationals.
They get hired. They collect a salary. That salary gets funneled back to the Kim Jong Un regime.
Meanwhile, they're stealing intellectual property, sensitive corporate data, and access credentials. When they eventually get caught, they don't just disappear — they threaten to expose whatever they stole unless the company pays a ransom. That's extortion layered on top of espionage layered on top of fraud.
The Crypto Angle Is Enormous
North Korea is heavily sanctioned by the United States, the European Union, and the United Nations over its nuclear weapons development program. That cuts it off from the Western banking system. So it built a workaround: steal crypto at industrial scale.
According to CrowdStrike as reported by TechCrunch, North Korea netted approximately $2 billion in stolen cryptocurrency during 2025 alone. Blockchain developers are specifically targeted. That money goes directly toward a nuclear weapons program that the UN has formally banned under international law. American developers and tech workers are inadvertently funding the expansion of a nuclear arsenal by accepting a coworker's pull request.
Why "Hands-on-Keyboard" Intrusions Matter
CrowdStrike specifically tracks hands-on-keyboard intrusions — meaning real human operators actively working inside a compromised system — because automated malware gets caught by conventional security tools. These don't.
Once inside, the operatives use legitimate software already present on the target's systems to move laterally and maintain persistent access. Traditional defenses largely miss this because the tools themselves aren't malicious — it's the person using them who is.
This is a sophisticated, patient operation. Professional state-sponsored actors with resources, time, and specific financial targets.
What Mainstream Coverage Is Missing
The available coverage focuses heavily on the North Korea angle without asking the harder structural questions:
Why are U.S. tech companies this easy to infiltrate through a job application? Remote work, over-reliance on video screening, and inadequate identity verification infrastructure have created a hiring pipeline that adversarial states can walk right through. AI deepfakes compound the problem.
Where is federal guidance? The FBI and CISA have both issued previous advisories on North Korean IT worker schemes — but the scale documented in CrowdStrike's report suggests those warnings have not produced adequate industry-wide defenses.
What is Congress doing? Sanctioning North Korea is already done. What's the active enforcement posture against this specific vector? That question is largely absent from mainstream coverage.
The Strongest Counterpoint — Stated Fairly
Skeptics of CrowdStrike's findings make a legitimate point: private cybersecurity firms have a financial incentive to amplify threat narratives. CrowdStrike sells threat detection and response products. The more alarming the threat landscape appears, the more its services are in demand. Critics argue that attribution in cyberspace is genuinely difficult, that nation-state labels get applied too liberally, and that 47% of "state-backed" intrusions is only as meaningful as CrowdStrike's methodology for determining what counts as state-backed in the first place.
That is a structural concern worth considering. Treat CrowdStrike as an interested source, not a neutral arbiter.
That said — the broad contours of North Korean IT worker infiltration are documented. The U.S. Department of Justice has filed charges in multiple separate cases. The FBI has issued named advisories. Multiple companies have publicly disclosed incidents. The question is scale and attribution precision, not whether this is happening.
What This Means for Regular People
If you work at a tech company, there is a meaningful probability that someone on your team — a contractor, a remote developer, a new hire — is not who they say they are.
For investors: your intellectual property is being systematically extracted and potentially held for ransom. That's a material risk.
For policymakers: sanctions alone are insufficient. North Korea has built an entire parallel revenue system specifically to circumvent them. The threat is adaptive. The policy response, as of June 11, 2026, does not appear to be.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.