Drooid Logo
Back to story perspectives

Full Breakdown

North Korean Hackers Target Hundreds of Global Firms, Prompting Diplomatic Pushback

8/6/2026, 10:39:54 AM

Scope of the Campaign

Cybersecurity researcher Vangelis Stykas, CTO of Kumio, says he has been monitoring North Korean hacking groups for 22 months. He estimates that 1,640 companies in 57 countries have been compromised, with 700–800 experiencing “really damaging” intrusions that gave attackers root access to servers and cloud platforms such as Amazon Web Services. Stykas accessed command-and-control servers, Slack channels and Discord servers used by the hackers, reviewing roughly 5 terabytes of data.

Notable Victims and Technical Reach

Among the disclosed victims are Boston Children’s Hospital (holder of a large COVID-19 patient database), Japan’s AEON Smart Technology, Chinese phone maker Oppo, cryptocurrency platforms Coinbase and Uniswap Labs, Italy’s Supreme Judicial Council, a subsidiary of Saudi Arabia’s Al Rajhi Bank, and Digitaal Vlaanderen of the Flemish Government. Japan’s Computer Emergency Response Team confirmed the findings and assisted AEON Smart Technology with remediation.

Official Statements & Responses

North Korean state media (KCNA) on August 4 accused the United States and its allies of fabricating cyber-threat warnings to damage Pyongyang’s image and justify pressure on sovereign states. A foreign-ministry spokesperson called the U.S.–led “joint warning” a political accusation and criticized the Multilateral Sanctions Monitoring Team, which had warned that North Korean IT workers use false identities, AI tools and remote-job schemes to fund nuclear and missile programs.

Impact and Industry Reaction

The revelations highlight how North Korean actors target not only government and defense entities but also health, finance and blockchain firms, leveraging stolen developer keys and source code. The disclosed root-level access raises concerns about long-term data exfiltration and cryptocurrency theft. Companies that responded promptly to Stykas’s disclosures have begun remediation, while others remain silent.

Verbatim Quotes

  • “For crypto companies, it’s keys, it’s blockchain access—it’s ridiculous access.” — Vangelis Stykas, greece-based cybersecurity researcher
  • “I have access to their Slack, I have access to their Discord, I have access to a lot of stuff,” — Vangelis Stykas, greece-based cybersecurity researcher