A cybersecurity researcher who infiltrated North Korean hacking systems has uncovered evidence that 1,640 companies across 57 countries were impacted by the regime's operations, according to findings presented at the Black Hat security conference in Las Vegas. Vangelis Stykas, CTO at cybersecurity firm Kumio, spent 22 months inside multiple command-and-control servers used by North Korean hackers, discovering the scope of intrusions designed to steal corporate secrets and cryptocurrency to fund the totalitarian government and its weapons programs. The Greece-based researcher revealed that approximately 700 to 800 of those impacted organizations suffered "really damaging" breaches.

Stykas accessed the hackers' systems after they appeared to infect themselves with their own malware, which gave him entry to their workstations as well as their command-and-control infrastructure. He examined roughly 5 terabytes of data, including access to the hackers' Slack and Discord communications. By analyzing developer keys, source code, and other materials, the researcher identified potential victims and disclosed the incidents to those affected over the course of his investigation. Among the publicly named organizations are Boston Children's Hospital, which held a vast Covid-19 database of Americans' personal health data, Japanese tech firm AEON Smart Technology, Chinese phone maker Oppo, cryptocurrency platforms Coinbase and Uniswap Labs, Italy's Supreme Judicial Council, a subsidiary of Saudi Arabian bank Al Rajhi Bank, and Digitaal Vlaanderen, part of Belgium's Flemish Government.

"It's company access, it's root access to servers, it's root access to AWS," Stykas told WIRED, referring to Amazon Web Services and the term "root" to indicate the highest level of permissions in a computer system. For cryptocurrency firms, the compromises included "keys" and "blockchain access," representing what he described as "ridiculous access." The researcher chose to publicly identify roughly a dozen companies at Black Hat, focusing primarily on those that handled disclosures effectively or remediated potential compromises. Multiple organizations named in the disclosure either confirmed the incidents or stated they found no evidence of unauthorized access to their core systems, with responses ranging from immediate credential rotation to termination of contractors within 30 days.

North Korea's hacking operations have for years targeted individual employees and contractors as a pathway into organizations worldwide, using both stealthy intrusion techniques and scam IT workers who gain employment to pilfer billions in cryptocurrency. The scale revealed by Stykas's access demonstrates how effective this strategy has proven in penetrating corporate defenses globally. Organizations across sectors—from healthcare and government to technology and finance—have been compromised through these tactics, which exploit human vulnerabilities rather than purely technical ones. The breadth of access obtained by these operatives, including root-level server permissions and blockchain keys, underscores the severity of potential damage beyond simple data theft.

The findings highlight an ongoing threat that spans continents and industries, with disclosure responses varying widely among affected entities. Some organizations immediately isolated compromised workstations and rotated credentials, while others disputed the severity or contested whether breaches touched their core systems. The researcher's extended access to North Korean hacking infrastructure provides a rare window into the operational scale of state-sponsored cybercrime, revealing that hundreds of companies may be sitting on active compromises without full awareness of the intrusion's depth. Organizations must now grapple with whether existing contractor vetting and access controls can detect operatives working on behalf of hostile governments who successfully embed themselves within corporate environments. For decision-makers, this incident reframes vendor and contractor risk from a compliance checkbox into an existential security question. The uncomfortable reality is that technical defenses alone cannot solve a threat that enters through the front door with valid credentials and legitimate-seeming employment.