Follow Cyber Kendra on Google News! | WhatsApp | Telegram

Add as a preferred source on Google

North Korea Arrests Its Own Hackers Over Bank Heist

North Korea arrested ex-military hackers accused of breaching two state banks and laundering funds through crypto wallets and Chinese brokers.

North Korea Hacker Arrested

The country that built the world's most prolific state hacking program just discovered what every CISO already knows: the people you train to break in can break in anywhere — including your own vault.

North Korea's National Intelligence Agency has arrested a ring of former military cyber operators accused of looting two state banks and washing the money through cryptocurrency, according to Seoul-based outlet Daily NK, which cited an anonymous source in Pyongyang. The report has not been independently verified.

The ringleaders were reportedly discharged veterans of a cyber unit under the Reconnaissance and Intelligence General Bureau — North Korea's military intelligence arm — who recruited young IT talent from Kim Chaek University of Technology and Pyongyang University of Science after leaving service. They allegedly breached the internal networks and foreign payment systems of the Chosun Central Bank, which handles currency issuance, and the Foreign Trade Bank, which processes the country's overseas payments.

The tradecraft is familiar to anyone who has read a DPRK threat report. The group is said to have skimmed state trade funds and foreign currency from shell accounts in tiny increments — structuring, in anti-money-laundering terms — then pushed the money into overseas crypto wallets, where Chinese brokers converted it back to dollars and yuan. Handlers in the border cities of Sinuiju and Hyesan reportedly settled the cash in real time, coordinating over encrypted messaging apps, unregistered burner phones, and Chinese wireless gear.

What broke the operation was not exotic forensics. Officials noticed small mismatches in foreign-currency payment approvals and flagged odd overseas IP access logs, triggering a covert probe that traced encrypted transaction traffic to a Pyongyang safe house raided on the night of July 12. Agents reportedly caught the crew mid-laundering at their keyboards and seized hundreds of thousands of dollars in equipment.

That detection path is the takeaway for defenders. Reconciliation gaps in payment approvals and geographically impossible logins remain the two highest-yield insider-threat signals in any finance stack — and both are cheap to monitor. Pair transaction-level reconciliation with conditional access on IP and device, enforce dual approval on outbound payments, and log privileged access to core banking systems separately from the admins who hold it.

Context on scale: North Korean operators stole a record $2 billion in crypto last year, per Chainalysis, and TRM Labs pegged them at 76% of all hack and scam losses through April.

Pyongyang's elite are reportedly rattled. One official, quoted via Daily NK's source, warned it would be "hard for the entire family line to survive."

Post a Comment