READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Researcher Hacked Into North Korea's Hacking Operation, Found 1,640 Breached Companies in 57 Countries

Researcher Hacked Into North Korea's Hacking Operation, Found 1,640 Breached Companies in 57 Countries
Greek cybersecurity researcher Vangelis Stykas spent 22 months inside North Korean hacking infrastructure and found evidence of breaches at 1,640 companies worldwide, including Boston Children's Hospital, Coinbase, and Oppo. He's presenting the findings at Black Hat in Las Vegas, and it's a rare, detailed look at how Pyongyang's cyber army actually operates day to day.

A cybersecurity researcher broke into the systems North Korean hackers use to break into everyone else. The findings carry significant implications for companies with remote IT contractors on payroll.

Vangelis Stykas, chief technology officer at cybersecurity firm Kumio, gained access to North Korean command-and-control servers roughly 22 months ago, according to WIRED. He's presenting his findings today at the Black Hat security conference in Las Vegas.

The numbers are stark. Stykas found evidence that 1,640 companies across 57 countries have been impacted by North Korean hacking operations, WIRED reported. Of those, he says 700 to 800 organizations suffered what he calls "really damaging" intrusions.

"It's company access, it's root access to servers, it's root access to AWS," Stykas told WIRED, referring to Amazon Web Services and using "root" to mean the highest level of system permissions. "For crypto companies, it's keys, it's blockchain access. It's ridiculous access."

How He Got In

Stykas declined to detail exactly how he accessed the North Korean command-and-control servers, citing the sensitivity of that method, WIRED reported. But he described a stroke of operational irony: in some cases the hackers had apparently infected their own machines with their own malware, which gave Stykas a window into their workstations too.

"I have access to their Slack, I have access to their Discord, I have access to a lot of stuff," he told WIRED. He says he's reviewed around 5 terabytes of data pulled from those systems.

Using developer keys, source code, and other artifacts left behind, Stykas says he identified potential victims and disclosed the intrusions to the affected organizations over the course of his research, according to WIRED.

Who Got Named, and Why

At Black Hat, Stykas is publicly naming about a dozen of the impacted organizations. His stated criteria: these are largely the companies that handled the disclosure well or actually fixed the compromise, according to WIRED.

The named organizations include Boston Children's Hospital, which held a large Covid-19 database containing Americans' personal health information, according to WIRED. Also named: Japanese tech firm AEON Smart Technology, Chinese phone maker Oppo, crypto firms Coinbase and Uniswap Labs, Italy's Supreme Judicial Council, a subsidiary of Saudi Arabia's Al Rajhi Bank, and Digitaal Vlaanderen, a digital services arm of the Flemish government in Belgium.

WIRED reported that multiple companies and organizations named in its story did not respond to requests for comment about the incidents.

The Broader Implications

North Korea's hacking apparatus isn't a hobby operation. It's a state-funded pipeline that has spent years infiltrating companies through stolen corporate secrets and cryptocurrency theft, funneling the proceeds into the regime's weapons programs, according to WIRED. The US government and independent researchers have documented North Korean IT workers posing as remote contractors to gain insider access to Western companies, a tactic separate from but related to the server-level intrusions Stykas describes.

The scale here, 1,640 companies, is bigger than most individual breach disclosures that make headlines. Most companies find out they've been hit when their own systems fail or when a third party like the FBI notifies them months later. Stykas got there by going straight to the source and watching the operation run in something close to real time.

A single outside researcher, without government authority or a subpoena, apparently found and sat inside adversary infrastructure for nearly two years. If a private CTO with a laptop can pull that off, it raises the question of why national intelligence agencies with vastly larger budgets aren't producing comparably detailed public accounting of North Korean intrusions on this scale.

The technical achievement and disclosure story are significant. The harder policy question remains: if a lone researcher can map out 1,640 compromised companies using access methods he won't even disclose, what does that say about the state of basic network security at firms holding sensitive health data, banking credentials, and crypto keys?

Stykas hasn't published the full list of 1,640 companies, and it's unclear whether US or allied law enforcement agencies have independently verified his findings or opened investigations tied to specific victims. No charges, indictments, or government confirmation of Stykas's full dataset have been reported. The dozen names disclosed at Black Hat are the ones willing to be public about getting hacked. The other 1,600-plus are still unknown to their own customers.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
WiredA Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide