READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

State-Backed Hacking From North Korea, China and Russia Rose 7.5% in First Half of 2026

State-Backed Hacking From North Korea, China and Russia Rose 7.5% in First Half of 2026
A new report from South Korean cybersecurity firm S2W counted 158 state-sponsored cyberattacks tied to North Korea, China and Russia in the first six months of 2026, up from 147 the prior half. North Korea remains the most prolific attacker by far, hitting South Korea nearly twice as often as the U.S., while China's drop in raw incident count reflects stealthier tactics, not less activity.

State-Backed Hacking From North Korea, China and Russia Rose 7.5% in First Half of 2026

North Korea, China and Russia ran 158 documented state-sponsored cyberattacks in the first half of 2026, up 7.5% from 147 in the second half of 2025, according to a threat intelligence report from South Korean cybersecurity firm S2W published August 12 and summarized by The Korea Times on August 16.

The increase wasn't steady. S2W's TALON threat intelligence team found the spike was concentrated almost entirely in the first quarter, driven by a burst of activity from Pyongyang and Moscow.

North Korea Still Leads, By a Mile

North Korea accounted for 99 of the 158 incidents, a 13.8% jump from 87 in the prior six-month period, according to S2W. That's more than triple China's count and nearly four times Russia's.

South Korea took the brunt of it, absorbing 19 North Korean attacks. The United States came in second with 8, according to both The Korea Times and Financial News (fnnews.com), meaning Seoul was targeted more than twice as often as Washington.

The tactics have gotten sharper. S2W documented North Korean groups using generative AI and deepfake technology to run fake job-recruitment schemes aimed at cryptocurrency firms, IT companies and software developers, along with malware hidden inside code repositories and npm packages.

Tech Times reported that South Korean firm Genians Security Center found something more specific in August 2026: Kimsuky, one of North Korea's most active espionage units, built a self-hosted large language model lab inside its own attack servers, using open-source AI tools to process stolen classified documents and diplomatic correspondence. If accurate, that's North Korean hackers running their own private AI system to sort through what they steal, not just using AI as a lure.

China's Numbers Fell. That's Not Good News

China-linked incidents dropped 17.5%, from 40 to 33, according to S2W. On its face that looks like a retreat. Tech Times argues the opposite is true, calling China's decline a situation where fewer incidents reflect "a backdoor that conventional firewalls and network scanners physically cannot detect" rather than reduced threat activity.

The mechanism is BPFDoor, a backdoor malware that Chinese-linked groups have used alongside legitimate cloud APIs, VPNs and tunneling tools to maintain long-term, quiet access to networks. Beijing-linked groups kept their sustained focus on telecommunications while expanding into Southeast Asia and the Middle East, according to Financial News. Southeast Asia logged 8 cases and the Middle East 4, the most of any regions hit by Chinese-linked actors.

Fewer flagged incidents doesn't mean less spying. It can mean better camouflage. Methodological limitations exist for anyone trying to measure this threat with incident counts alone.

Russia's Surge Went Beyond Ukraine

Russian-backed cyberattacks jumped 30%, the largest percentage increase of the three, rising from 20 to 26 incidents according to S2W. Ukraine remained the top target with 10 attacks, but Kremlin-linked groups expanded into Poland, Romania and other Eastern European nations, per Financial News.

Russian operators blended traditional espionage with attacks aimed at destroying systems and disrupting services, targeting energy grids, government networks and military systems, according to The Korea Times.

The Bigger Picture, and Where the Coverage Gaps Are

None of these three reports on the S2W data mention China, Russia, North Korea or Iran coordinating with each other. That's a separate claim, made in a new book from the Foundation for Defense of Democracies, "Axis of Aggressors," covered by Fox News. Retired Rear Adm. Mark Montgomery, one of the book's authors, told Fox News Digital the four governments aren't a formal alliance with unified command, but their military, economic and technological support for one another creates what he calls a "simultaneity problem" for U.S. defense planners, who might face multiple crises at once instead of one at a time. The book's researchers counted 616 instances of security cooperation among the four nations between January 2019 and December 2025.

That's a distinct dataset covering physical and military cooperation, not the cyberattack tallies from S2W. Conflating the two would be sloppy. But they point in the same direction: adversarial state activity against the U.S. and its allies, across multiple domains, isn't slowing down.

Skeptics of threat-inflation narratives have a fair point. Incident counts from any single cybersecurity vendor reflect what that vendor's sensors and clients happen to see, not a complete census of global attacks. S2W is a South Korean firm with obvious visibility into Korean-language and Korea-focused threats, which may explain why North Korea's numbers dwarf China's and Russia's in this particular dataset. A different vendor with different client coverage could produce a different ranking.

Still, no source in this reporting disputes the core trend: North Korea is the most prolific state-backed hacking operation tracked in the first half of 2026, and it's leaning harder on AI and deepfakes to do it. What happens with China's undercounted, camouflaged activity over the next six months is the open question enterprise security teams and U.S. policymakers don't yet have an answer to.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

right
Breitbartbreitbart.com
right
Fox NewsChina, Russia, Iran and North Korea form 'axis of aggressors' that could overwhelm US, book warns
unknown
koreatimes.co.krState-sponsored cyberattacks from N. Korea, China, Russia rise 7.5% in 1st half of 2026
unknown
en.fnnewsNorth Korea’s cyberattacks targeting South Korea top the list, more than double those against the United States
unknown
Tech TimesNorth Korea, Russia, China Cyberattacks Rose 7.5%; BPFDoor Backdoor Defeats Firewall Detection
unknown
chinapulsesponsored cyberattacks from N. Korea, China, Russia rise 7.5% in 1st half of 2026 - ChinaPulse.com