North Korea Rocked by Internal Bank Hack: Former Military Cybercriminals Infiltrate Core Financial Systems
In a stunning development, North Korea’s tightly controlled financial sector has been compromised from within. Daily NK, a news outlet run by North Korean defectors, reports that a sophisticated criminal syndicate comprised of former military hackers successfully breached the internal network systems of both the Central Bank of Korea and the Foreign Trade Bank.
This elite hacking group allegedly converted stolen state trade funds into cryptocurrency and engaged in extensive foreign currency smuggling across border regions. North Korea’s State Security Department (formerly the Ministry of State Security) reportedly apprehended the entire network on July 12.
The infiltration of these two institutions, which form the bedrock of North Korea’s financial architecture—the Central Bank managing currency issuance and state treasury, and the Foreign Trade Bank handling international payments and foreign exchange—has sent shockwaves through Pyongyang’s leadership.
While CoinDesk and Cybernews have also cited Daily NK’s report, both emphasized that the claims could not be independently verified.
The Masterminds: Elite Hackers and Academics Forge a Crypto Underworld
Sources speaking to Daily NK revealed that the masterminds behind this audacious scheme were former military personnel, veterans of North Korea’s notorious Reconnaissance General Bureau (now the Reconnaissance Intelligence General Bureau), an organization infamous for its long history of state-sponsored cyber espionage and hacking operations.
Upon retiring from military service, these individuals leveraged their expertise to recruit young, brilliant IT talents from prestigious institutions like Kim Chaek University of Technology and Pyongyang University of Science and Technology. Together, they constructed a clandestine cryptocurrency trading network specifically designed to bypass stringent state surveillance, with the clear objective of amassing personal wealth in foreign currency.
To evade detection, the group employed specialized Chinese-made wireless communication equipment and encrypted communication software. Utilizing advanced hacking techniques honed during their military careers and academic pursuits, they successfully penetrated the internal systems and cross-border payment mechanisms of the two critical banks.
Once inside, they meticulously siphoned off national trade funds and foreign currency, dispersed across various nominee accounts. These funds were then meticulously broken down into numerous small transfers, channeled into overseas cryptocurrency wallets, and converted into cash via Chinese brokers. Contacts in border cities such as Sinuiju and Hyesan facilitated the immediate exchange of these funds into US dollars and Chinese Yuan.
The Takedown: Intelligence Agencies Unravel the Network in a Dramatic Raid
The elaborate scheme began to unravel when North Korean officials detected subtle discrepancies during foreign currency payment approvals, coupled with suspicious foreign IP access records. The State Security Department swiftly launched a covert internal investigation.
Investigators meticulously tracked the encrypted traffic generated by the cryptocurrency transactions, ultimately pinpointing a safe house within Pyongyang. On the night of July 12, a dramatic raid was executed, catching the masterminds and IT personnel red-handed as they laundered money at their computers. Authorities seized computer equipment valued at hundreds of thousands of dollars, along with multiple unregistered mobile phones the group used to circumvent surveillance.
The operation itself was a tense affair. Armed intelligence personnel established perimeters around the Foreign Trade Bank headquarters and the Central Bank of Korea’s computer center, severing external connections. Signal detection vehicles were deployed across Pyongyang to trace the group’s anomalous wireless frequencies, creating a palpable atmosphere of tension throughout the city.
News of the arrests sent ripples of shock through Pyongyang’s elite circles, military ranks, and university communities. Authorities are reportedly preparing to impose severe sentences on those implicated in the high-profile case.
North Korea’s Enduring Cybercrime Challenge: A Global Concern
While this internal bank infiltration may be an isolated incident, it starkly underscores North Korea’s long-standing reliance on cyber technology for illicit financial activities.
According to a May report by blockchain analytics firm CertiK, North Korean-affiliated hacking groups are projected to cause cryptocurrency losses totaling $2.06 billion by 2025, accounting for a staggering 60% of global cryptocurrency theft losses. Since 2016, the cumulative stolen amount attributed to these groups has reached an astonishing $6.75 billion.
Taylor Monahan, the report’s author, highlighted that social engineering remains the primary attack vector for North Korean hacking groups. Furthermore, stolen funds are often laundered with alarming speed through decentralized exchanges and cross-chain bridges.
CertiK also noted that the U.S. Department of Justice filed a civil forfeiture lawsuit in June last year for $7.7 million in cryptocurrency linked to a North Korean IT worker’s money laundering network.
Case documents further revealed that a wallet controlled by Sim Hyon Sop, a representative of North Korea’s sanctioned Foreign Trade Bank, received over $24 million in cryptocurrency between August 2021 and March 2023.
This latest internal bank infiltration incident serves as a potent reminder that while North Korea actively engages in external cryptocurrency attacks, its own internal financial infrastructure remains vulnerable to significant cybersecurity threats.
(The above content is excerpted and reproduced with authorization from our partner CryptoCity. Original link.)
Disclaimer: This article provides market information only. All content and views are for reference purposes and do not constitute investment advice. They do not represent the views and positions of BlockTempo. Investors should make their own decisions and trades. The author and BlockTempo will not be held responsible for any direct or indirect losses incurred by investors’ transactions.