A Greek cybersecurity researcher has exposed the scale of North Korea's hacking operations after gaining access to the hackers' own systems nearly two years ago. Vangelis Stykas, CTO of Kumio, says he found evidence that 1,640 companies across 57 countries were compromised by North Korean cyber actors. Around 700 to 800 of these suffered severe breaches, including full root access to corporate servers and Amazon Web Services accounts. For cryptocurrency firms, attackers obtained blockchain keys and deep system access, according to Stykas.

Stykas gained entry through command-and-control servers used by the hackers, discovering in some cases that the hackers had infected themselves with their own malware. This allowed him to access their internal communications on Slack and Discord, along with approximately 5 terabytes of data. He identified victims by analyzing developer keys and source code, disclosing findings directly to affected organizations. At the Black Hat conference in Las Vegas, he publicly named about a dozen companies, including Boston Children's Hospital, Japanese tech firm AEON Smart Technology, Chinese phone maker Oppo, crypto platforms Coinbase and Uniswap Labs, Italy's Supreme Judicial Council, a subsidiary of Saudi Arabia's Al Rajhi Bank, and Digitaal Vlaanderen, part of Belgium's Flemish government.

Japan's Computer Emergency Response Team confirmed the breach at AEON Smart Technology and said remediation was carried out. The Flemish government said it isolated the affected workstation and revoked exposed credentials after being notified on March 3, 2026. Boston Children's Hospital stated the incident involved a former contractor's personal device, not its systems. Coinbase said it terminated a U.S.-based contractor within 30 days of onboarding due to security risks, before learning of Stykas's report, and found no evidence linking the individual to North Korea.

💡 NaijaBuzz Take

The researcher accessed North Korean hackers' internal tools because they infected themselves with their own malware—an operational flaw that exposed their entire infrastructure. This self-inflicted breach raises questions about the reliability of attribution when attackers leave digital traces through carelessness rather than sophisticated tradecraft. Some named companies acted quickly to contain access, while others have not responded publicly to the allegations.

Editorial note: AI-assisted opinion, not established fact. Full disclaimer →