A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide
For years, North Korea’s stealthy hackers and scam IT workers have infiltrated companies, stealing corporate secrets and plundering billions in cryptocurrency to help fund the totalitarian regime and its weapons programs. Now, a security researcher who has spent almost two years inside the systems belonging to a group of those North Korean hackers is raising the alarm on just how effective and far reaching the targeting of individual employees and contractors has been in breaching organizations across the globe.
Since Greece-based cybersecurity researcher Vangelis Stykas gained access to North Korean systems 22 months ago, he says, he has found evidence that 1,640 companies across 57 countries have been impacted by the country’s hacking operations. Among these, Stykas will detail at the Black Hat security conference in Las Vegas today, around 700 to 800 of the impacted organizations have had “really damaging” intrusions.
“It’s company access, it’s root access to servers, it’s root access to AWS,” the researcher tells WIRED, referring to Amazon Web Services and the term “root” to mean the highest level of permissions in a computer system. “For crypto companies, it’s keys, it’s blockchain access—it’s ridiculous access.”
Stykas, the CTO at cybersecurity firm Kumio, says he accessed multiple command-and-control servers used by the hackers, though he asked WIRED not to reveal the details of how he gained that access due to the sensitivity of that information. In some cases, he notes, the hackers appeared to have infected themselves with their own malware—which, as a result, gave him access to the hackers’ workstations, too. “I have access to their Slack, I have access to their Discord, I have access to a lot of stuff,” Stykas says, adding he has seen around 5 terabytes of data in total.
As he probed those systems over months, Stykas identified potential victims—by analyzing developer keys, source code, and more—and says he has disclosed the incidents to those impacted. As part of his talk at Black Hat, Stykas is publicly naming around a dozen of the impacted companies—these are, he says, largely the ones that handled the disclosures well and/or fixed possible compromises. The researcher says these include the Boston Children’s Hospital (which held a vast Covid-19 database of Americans’ personal health data), the large Japanese tech firm AEON Smart Technology, Chinese phone manufacturer Oppo, cryptocurrency firms Coinbase and Uniswap Labs, Italy’s Supreme Judicial Council, a subsidiary of Saudi Arabian bank Al Rajhi Bank, and Digitaal Vlaanderen, part of the Flemish Government in Belgium.
Multiple companies and organizations named in this article did not respond to WIRED’s request for comment about the incidents. Japan’s Computer Emergency Response Team says it confirmed the security researcher’s findings and worked with AEON Smart Technology on “remediation.”
“We can confirm that we were notified of this incident on March 3, 2026 by the Centre for Cybersecurity Belgium (CCB), following the researcher’s disclosure,” a spokesperson for the Flemish government says. “As part of that response, the affected workstation was isolated and the potentially exposed credentials and access were revoked and rotated. Based on our investigation, the incident has been contained and remediated.”
A spokesperson for Boston Children’s Hospital says that the incident “involved a former independent contractor’s personal device” and not the hospital’s systems. “Upon notification, our cybersecurity and IT teams immediately investigated, disabled any remaining active access credentials within hours, and found no evidence of unauthorized access to Boston Children’s systems,” the spokesperson says, adding that the “data at issue” was already publicly available.
Meanwhile, a Coinbase spokesperson says they investigated a contractor, who they found was in the United States, and “uncovered no evidence that he was either located in North Korea nor affiliated with the DPRK government” before it was reported by the researcher, using DPRK to refer to the Democratic People’s Republic of Korea. “However, our security controls identified potential risks in their technology setup, suggesting they may have outsourced their work to a third party, and we terminated the contractor within 30 days of onboarding, prior to receiving a tip from Vangelis Stykas,” the spokesperson says. They add that “no sensitive information was compromised and no customer data was exposed.”





















































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































































