Researcher Finds 1,640 Companies Breached by North Korean Hackers
A cybersecurity expert who infiltrated North Korean hacking infrastructure reveals the massive scale of fake job interview attacks targeting developers worldwide.

Unprecedented Access to North Korean Operations
A cybersecurity researcher has spent nearly two years inside the digital infrastructure of North Korean hackers, documenting what may be one of the most extensive corporate breach campaigns ever recorded. Vangelis Stykas, CTO at cybersecurity firm Kumio, gained access to multiple command-and-control servers operated by North Korean groups and discovered evidence of intrusions at 1,640 companies spanning 57 countries.
Stykas presented his findings at the Black Hat security conference in Las Vegas, detailing how 700 to 800 of these organizations suffered what he characterizes as "really damaging" compromises. The breaches gave attackers root access to servers, AWS environments, and in cryptocurrency companies, direct access to blockchain keys and wallets.
According to WIRED, which first reported the research, Stykas accessed approximately 5 terabytes of data from the hackers' systems. In some instances, the attackers had inadvertently infected their own workstations with malware, providing the researcher with visibility into their Slack channels, Discord servers, and operational infrastructure.
The Fake Interview Playbook
The attack method employed across nearly all documented cases follows a consistent pattern: hackers pose as recruiters offering software developers lucrative job opportunities with attractive salaries. When targets engage, they receive coding tests that require downloading programs—which silently install malware on their machines.
This technique, known as Contagious Interview, has been documented since at least 2022. Microsoft has tracked the campaign as part of broader North Korean cyber operations aimed at generating revenue for the sanctioned regime.
The impact extends far beyond individual companies. Stykas found that compromised external contractors often held developer credentials or system access to dozens of organizations simultaneously. "I have seen a couple of contractors that had access to up to 30 companies," he noted.
Confirmed Victims and Response
Stykas publicly identified roughly a dozen affected organizations that either responded effectively to his disclosures or successfully remediated the breaches. These include Boston Children's Hospital, Japanese tech firm AEON Smart Technology, Chinese manufacturer Oppo, cryptocurrency platforms Coinbase and Uniswap Labs, Italy's Supreme Judicial Council, and Belgium's Digitaal Vlaanderen.
The Flemish government confirmed receiving notification in March 2025 and immediately isolated affected systems, revoking and rotating credentials. Boston Children's Hospital stated the incident involved a former contractor's personal device rather than hospital systems, with no evidence of unauthorized access to their networks.
Coinbase reported terminating a contractor within 30 days of onboarding after security controls flagged potential risks, though they found no evidence the individual was located in North Korea or affiliated with the regime.
Why It Matters
While the hackers demonstrated laser focus on cryptocurrency theft—often ignoring other sensitive data including health records and criminal databases—the persistent access they maintain creates ongoing risk. Threat intelligence researcher Marcus Hutchins warns that espionage teams could exploit these established footholds at any time. The research also highlights a critical vulnerability in contractor security: external developers with multi-company access create exponential risk when compromised. With hundreds of warned organizations never responding and new victims added daily, the actual scope of North Korean infiltration likely extends far beyond the documented cases.
The details were first reported by WIRED.
This is an original analysis by the Omega editorial team. Source reporting: WIRED.
Want systems like this working for your business?
Book a Call