A cybersecurity researcher has revealed that he maintained access to North Korean hacking infrastructure for nearly two years, uncovering evidence of intrusions into 1,640 organizations across 57 countries. Vangelis Stykas, CTO at Kumio, stated that between 700 and 800 of these intrusions were "really damaging," involving root access to servers, AWS environments, and critical cryptocurrency keys.
Stykas gained access to multiple command-and-control servers used by the North Korean hackers, and in some instances, the attackers inadvertently infected their own workstations, granting him access to their internal communications like Slack and Discord. Over 22 months, he collected approximately 5 terabytes of data, which he used to identify potential victims and disclose the incidents.
Among the organizations publicly named by Stykas at the Black Hat security conference are Boston Children’s Hospital, Japanese tech firm AEON Smart Technology, Chinese phone manufacturer Oppo, cryptocurrency firms Coinbase and Uniswap Labs, Italy’s Supreme Judicial Council, a subsidiary of Saudi Arabian bank Al Rajhi Bank, and Digitaal Vlaanderen, a part of the Flemish Government in Belgium.
Responses from named organizations varied. Japan’s Computer Emergency Response Team confirmed Stykas’s findings and collaborated with AEON Smart Technology on remediation. Digitaal Vlaanderen confirmed a notification on March 3, 2026, leading to the isolation of an affected workstation and revocation of credentials, with the incident deemed contained. Boston Children’s Hospital stated the incident involved a former independent contractor’s personal device, not hospital systems, and that no unauthorized access to their systems was found, with the data at issue already public. Coinbase investigated a contractor and found no evidence of North Korean affiliation, but terminated the contractor due to potential outsourcing risks before Stykas’s tip, confirming no sensitive information or customer data was compromised.
The primary method of attack involved luring software developers with fake job offers and high salaries. Once a target accepted, they were prompted to download a program as a coding test, which secretly installed malware on their machine. This tactic, known as "Contagious Interview," has been documented by Microsoft as early as 2022. Stykas observed that compromised external contractors, who often held developer keys and system access to multiple companies, significantly expanded the potential impact of these attacks, with some contractors having access to up to 30 organizations.
While many compromised firms held highly sensitive data, including health records and criminal records, the North Korean hackers largely focused on acquiring cryptocurrency wallets, often overlooking other systems. However, experts warn that persistent access to corporate networks, even if initially used for crypto theft, could be leveraged by espionage teams for broader intelligence gathering.
North Korea's cyber operations are extensive and adaptable, supporting economic and military development, revenue generation, espionage, and sanctions evasion. The country is believed to employ several hundred skilled cyber operators, alongside thousands of "IT workers" who secure fraudulent remote employment to funnel earnings to the regime. Both groups are reportedly given annual earnings quotas. The scale of these campaigns, with victim lists often numbering in the thousands, is consistent with the broad scope of North Korean hacking activities.






