Security Researcher Spent 22 Months Inside North Korean Hackers’ Servers, Found 1,640 Breached Companies

A Greece-based cybersecurity researcher has spent nearly two years with access to North Korean hackers’ command-and-control servers, uncovering evidence that 1,640 companies across 57 countries have been compromised by the country’s hacking operations. Vangelis Stykas, CTO at cybersecurity firm Kumio, presented his findings at the Black Hat security conference in Las Vegas on August 5, 2026.

Stykas says he gained access to multiple servers used by the North Korean hackers roughly 22 months ago, though he declined to reveal the method due to its sensitivity. In some cases, the hackers appear to have infected their own workstations with their own malware, inadvertently giving Stykas access to those machines as well. “I have access to their Slack, I have access to their Discord, I have access to a lot of stuff,” he told WIRED, noting he has observed around 5 terabytes of data in total.

Of the 1,640 affected organizations, Stykas says 700 to 800 suffered “really damaging” intrusions — including root-level access to servers and Amazon Web Services environments, as well as cryptocurrency keys and blockchain access. At Black Hat, he publicly named roughly a dozen companies, including Boston Children’s Hospital, Japanese tech firm AEON Smart Technology, Chinese phone manufacturer Oppo, cryptocurrency platforms Coinbase and Uniswap Labs, Italy’s Supreme Judicial Council, a subsidiary of Saudi Arabian bank Al Rajhi Bank, and Digitaal Vlaanderen, part of the Flemish Government in Belgium.

Several named organizations confirmed and addressed the incidents. The Flemish government said it isolated an affected workstation and revoked exposed credentials following notification in March 2026. Boston Children’s Hospital said the breach involved a former independent contractor’s personal device, not its own systems, and found no evidence of unauthorized access. Coinbase said it terminated a contractor within 30 days of onboarding after identifying risks in their technology setup, and that no customer data was exposed.

North Korea’s hacking operations are widely understood to fund the country’s regime and weapons programs through stolen cryptocurrency and corporate espionage. The scale of intrusions documented by Stykas suggests the targeting of individual employees and contractors has been a highly effective vector for breaching organizations worldwide.

Source: WIRED

This article was generated by AI and cites original sources.
Scroll to Top