• 4 min read
North Korean hackers reached 1,640 companies, researcher says
A researcher says North Korean hackers reached 1,640 companies in 57 countries through fake developer jobs, exposing cloud and crypto access.

Image: Wired
A North Korean hacking operation reached 1,640 companies in 57 countries, according to Greek cybersecurity researcher Vangelis Stykas, who says he spent 22 months inside systems used by the attackers. He estimates that roughly 700 to 800 organizations suffered “really damaging” intrusions.
Stykas, CTO of cybersecurity firm Kumio, is presenting the findings at the Black Hat security conference in Las Vegas. His investigation points to a campaign that combines fake software-engineering job offers, malware and compromised contractors to gain access to corporate systems—particularly cryptocurrency infrastructure.
Inside the attackers' infrastructure
Stykas says he accessed several command-and-control servers used by the hackers, although he did not disclose how. In some cases, the attackers apparently infected their own machines with malware, allowing him to reach their workstations as well.
“It’s company access, it’s root access to servers, it’s root access to AWS. For crypto companies, it’s keys, it’s blockchain access—it’s ridiculous access.”
He says he could access the group’s Slack and Discord accounts and reviewed about 5 terabytes of data. By examining developer keys, source code and other information, he identified potential victims and notified the affected organizations.

Recommended reading
BMC flaws leave thousands of servers open to backdoors
Stykas plans to name roughly a dozen companies at Black Hat. He says they were selected largely because they handled the disclosures responsibly or addressed possible compromises. The organizations include Boston Children’s Hospital, AEON Smart Technology, Oppo, Coinbase, Uniswap Labs, Italy’s Supreme Judicial Council, a subsidiary of Saudi Arabian bank Al Rajhi Bank, and Digitaal Vlaanderen, part of the Flemish government.
Fake job offers created a wide blast radius
The attackers generally targeted software developers with fake job offers promising high salaries. Candidates were then asked to download a coding-test application that silently installed malware. Microsoft has tracked this technique, known as Contagious Interview, since at least 2022.
The danger was amplified when contractors had access to multiple employers. Stykas says he found several contractors who could reach as many as 30 companies, potentially turning one compromised workstation into a route into dozens of organizations.
The hackers often obtained access to highly sensitive systems, including cloud environments and developer credentials. Yet Stykas says they mostly focused on cryptocurrency wallets and did not appear to explore other systems, even when they could theoretically reach health or criminal-record data.
That narrow focus does not eliminate the risk. Marcus Hutchins, a threat-intelligence researcher at Expel, says another North Korean espionage team could potentially exploit the persistent access left behind by a cryptocurrency-focused group.
“It seems like the teams tend to stick to their task of getting crypto wallets. But there’s obviously the risk that if they’re maintaining persistent access to a corporation, one of the espionage teams could then piggyback off that access.”
Organizations dispute or contain some findings
Several companies named in the investigation did not respond to Wired’s requests for comment. Others said their reviews found more limited exposure than the researcher’s access might suggest.
Japan’s Computer Emergency Response Team confirmed Stykas’s findings and worked with AEON Smart Technology on remediation. A Flemish government spokesperson said an affected workstation was isolated and exposed credentials were revoked and rotated after the government was notified on March 3, 2026. The government said the incident had been contained and remediated.
Boston Children’s Hospital said the incident involved a former independent contractor’s personal device, not hospital systems. The hospital said it disabled remaining credentials within hours, found no unauthorized access to its systems and determined that the data at issue was already publicly available.
Coinbase said it investigated a contractor based in the United States and found no evidence that he was in North Korea or affiliated with the North Korean government. The company said its controls identified risks suggesting the contractor may have outsourced the work, and that Coinbase terminated him within 30 days of onboarding, before receiving Stykas’s report. Coinbase said no sensitive information or customer data was compromised.
The undisclosed victims may matter most
The investigation does not establish that every one of the 1,640 organizations suffered the same level of compromise. Stykas’s total includes companies where the attackers gained at least a foothold, while the estimate of 700 to 800 refers to intrusions he considers seriously damaging. The researcher also has not named most of the organizations he says were affected, and hundreds reportedly never responded to his warnings.
The campaign’s effectiveness comes less from an exotic exploit than from placing malware on trusted developers' machines and abusing legitimate access. That approach can expose cloud accounts, source code, cryptographic keys and multiple downstream employers at once.
“They’re here, they’re hacking us nonstop. At the end of the day, everyone’s getting hacked. How you treat you being hacked is what separates a good company from a bad company. And we have seen a lot of bad companies.”
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via Wired


