North Korean Hackers Breach Over 1,600 Organizations Worldwide, Researcher Reveals
A Greece-based cybersecurity researcher, Vangelis Stykas, has uncovered the staggering scale of North Korea’s cyber espionage operations after gaining access to the hackers’ command-and-control servers over the past 22 months. His findings, presented at the Black Hat security conference in Las Vegas, reveal that 1,640 companies across 57 countries have been compromised, with 700 to 800 organizations suffering severe intrusions including root-level access to servers, AWS environments, and cryptocurrency wallets.
Stykas, CTO of cybersecurity firm Kumio, infiltrated the hackers’ systems partly due to their own operational mistakes, such as infecting their workstations with their malware granting him access to their communications (Slack, Discord) and approximately 5 terabytes of stolen data. Among the victims he identified and disclosed were Boston Children’s Hospital (which held a COVID-19 health database), Japanese tech firm AEON Smart Technology, Chinese phone manufacturer Oppo, cryptocurrency platforms Coinbase and Uniswap Labs, Italy’s Supreme Judicial Council, a subsidiary of Saudi Arabia’s Al Rajhi Bank, and Digitaal Vlaanderen (part of Belgium’s Flemish government).
Several organizations confirmed the incidents. The Flemish government stated that affected credentials were revoked and the breach contained after notification by Belgium’s cybersecurity agency. Boston Children’s Hospital clarified that the compromise involved a former contractor’s personal device, not its internal systems, and that no unauthorized access was found. Coinbase terminated a contractor after detecting potential outsourcing risks but confirmed no sensitive data was exposed.
Japan’s Computer Emergency Response Team verified the breach at AEON Smart Technology and assisted in remediation. Other named entities, including Oppo and Uniswap Labs, did not respond to requests for comment.
The revelations underscore the global reach and sophistication of North Korea’s cyber operations, which have long targeted corporations and cryptocurrency firms to fund the regime’s weapons programs. Stykas’ findings highlight how individual employees and contractors remain a critical vector for large-scale breaches.
Coinbase TPRM report: https://www.rankiteo.com/company/coinbase
Boston Children’s Hospital TPRM report: https://www.rankiteo.com/company/bostonchildrenshospital
Oppo TPRM report: https://www.rankiteo.com/company/kumon-education-franchise-business-opportunity
"id": "boskumcoi1785976557",
"linkid": "bostonchildrenshospital, kumon-education-franchise-business-opportunity, coinbase",
"type": "Cyber Attack",
"date": "8/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Healthcare',
'location': 'United States',
'name': 'Boston Children’s Hospital',
'type': 'Healthcare'},
{'industry': 'Technology',
'location': 'Japan',
'name': 'AEON Smart Technology',
'type': 'Technology'},
{'industry': 'Telecommunications',
'location': 'China',
'name': 'Oppo',
'type': 'Technology'},
{'industry': 'Cryptocurrency',
'location': 'United States',
'name': 'Coinbase',
'type': 'Financial Services'},
{'industry': 'Cryptocurrency',
'location': 'United States',
'name': 'Uniswap Labs',
'type': 'Financial Services'},
{'industry': 'Judicial',
'location': 'Italy',
'name': 'Italy’s Supreme Judicial Council',
'type': 'Government'},
{'industry': 'Banking',
'location': 'Saudi Arabia',
'name': 'Al Rajhi Bank (subsidiary)',
'type': 'Financial Services'},
{'industry': 'Government Services',
'location': 'Belgium',
'name': 'Digitaal Vlaanderen',
'type': 'Government'}],
'attack_vector': 'Compromised personal devices, contractors, and operational '
'mistakes by threat actors',
'data_breach': {'data_exfiltration': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['COVID-19 health database',
'Cryptocurrency wallet data',
'General sensitive data']},
'description': 'A Greece-based cybersecurity researcher, Vangelis Stykas, '
'uncovered the scale of North Korea’s cyber espionage '
'operations after gaining access to the hackers’ '
'command-and-control servers. The findings reveal that 1,640 '
'companies across 57 countries were compromised, with 700 to '
'800 organizations suffering severe intrusions including '
'root-level access to servers, AWS environments, and '
'cryptocurrency wallets. Approximately 5 terabytes of stolen '
"data were recovered from the hackers' systems.",
'impact': {'data_compromised': '5 terabytes',
'operational_impact': 'Root-level access to critical systems',
'systems_affected': ['Servers',
'AWS environments',
'Cryptocurrency wallets']},
'initial_access_broker': {'entry_point': 'Contractors, personal devices',
'high_value_targets': ['Cryptocurrency platforms',
'Government entities',
'Healthcare organizations']},
'investigation_status': 'Ongoing',
'lessons_learned': 'Individual employees and contractors remain a critical '
'vector for large-scale breaches. Operational mistakes by '
'threat actors can expose their own infrastructure.',
'motivation': 'Funding regime’s weapons programs, cyber espionage',
'post_incident_analysis': {'root_causes': ['Operational mistakes by threat '
'actors',
'Compromised contractors and '
'personal devices']},
'references': [{'source': 'Black Hat security conference presentation'},
{'source': 'Japan’s Computer Emergency Response Team'}],
'regulatory_compliance': {'regulatory_notifications': ['Belgium’s '
'cybersecurity agency '
'notified the Flemish '
'government']},
'response': {'containment_measures': ['Revoked affected credentials',
'Terminated contractor access']},
'threat_actor': 'North Korean Hackers',
'title': 'North Korean Hackers Breach Over 1,600 Organizations Worldwide',
'type': 'Cyber Espionage'}