Security Current Affairs

North Korea's Elite Hackers Got Caught Robbing Their Own Banks

2026-07-25

Here's a plot twist nobody saw coming: North Korea's spy agency arrested a ring of state-trained IT operatives who used their military-grade hacking skills to loot the regime's own central bank. The irony is almost too perfect. These aren't amateurs—they're ex-members of the Reconnaissance and Intelligence General Bureau, the same outfit that's spent years systematically plundering foreign crypto exchanges and blockchain bridges to fund sanctions-busting. Except this time, they turned the toolkit inward.

According to Daily NK's sources in Pyongyang, the crew breached two major state banks: the Chosun Central Bank, which manages North Korea's currency issuance and reserves, and the Foreign Trade Bank, which handles overseas payments and currency flows. They stole state trade funds, converted them to crypto, and smuggled hard currency across the border through contacts in fringe areas. Slick operation. Too slick, as it turned out.

Detection came the mundane way. Officials noticed small discrepancies in foreign currency approvals. Then the tech side flagged weird overseas IP access. The National Intelligence Agency spun up a covert investigation, traced encrypted crypto traffic to a safe house in Pyongyang, and rolled up the entire ring on July 12. Agents caught the ringleaders and their crew actually at their computers, actively laundering funds. Confiscated equipment alone ran to hundreds of thousands of dollars.

The recruitment pipeline is fascinating. The group recruited fresh talent from Kim Chaek University of Technology and Pyongyang University of Science—basically scouting the regime's smartest young minds and flipping them into cybercriminals. That's what decades of building an elite hacking apparatus gets you: operatives talented enough to exploit the very systems they were trained to defend.

For context, North Korea has earned its reputation as a prolific cyber force the hard way. U.S. officials have connected North Korean hackers to some of the largest crypto thefts in history: Ronin Bridge, Harmony Horizon Bridge, Atomic Wallet, Alphapo, CoinEx, DMM Bitcoin, WazirX. Over the last decade, regime-linked groups have stolen billions—an estimated $1.7 billion in 2022 alone, roughly $1 billion more in 2023. Cryptocurrency theft has become a core revenue engine, a workaround for international sanctions.

But if the Daily NK report holds up, these sophisticated operators managed to breach the regime's financial core and sustain the operation long enough to accumulate substantial wealth. That speaks to either massive incompetence in the state's own security protocols, or—more likely—the kind of systemic vulnerability that emerges when you train your best and brightest exclusively in offensive tradecraft with minimal oversight.

Worth noting: Daily NK operates through networks of anonymous sources inside North Korea, who transmit information via secure channels. The outlet cross-verifies through multiple independent sources before publishing. These sources stay anonymous because contact with foreign media is a capital offense in North Korea. Caught means prison or worse. So the verification standard is inherently limited, but that's the game when you're reporting on a closed state.

Independent verification of anything inside North Korea is a brutal constraint. That said, the allegations fit the broader pattern: a regime so reliant on cyber operations for revenue that the operational culture inevitably spreads beyond state control. Train enough people in sophisticated crime, give them access to the crown jewels, and eventually someone decides the crown jewels are personal property.


Source & further reading:

Sources