Incidents

228 incidents

2019-01
🇳🇿 New Zealand
#Cryptocurrency #FinancialGain
2018-12
🇰🇷 Korea, Republic of
#Government #DataBreach #Espionage
2018-12
🇨🇱 Chile
#Finance #ATM #FinancialGain
2018-10
🇨🇭 Switzerland
#Cryptocurrency #FinancialGain
2018-10
🇲🇹 Malta
#Finance #FinancialGain
2018-10
🇵🇰 Pakistan
#Finance #FinancialGain
2018-09
🇮🇩 Indonesia
#Cryptocurrency #FinancialGain
2018-09
🇰🇷 Korea, Republic of
#Cryptocurrency #SupplyChain
2018-09
🇯🇵 Japan
#Cryptocurrency #FinancialGain
2018-08
🇺🇸 United States, ZZZ
#FinancialGain
2019-02
The UN Panel of Experts listed the Spanish financial institution case among DPRK cyber-enabled financial theft activity targeting banks and cryptocurrency exchanges for sanctions-evasion revenue. The available evidence does not provide operational details…
🇪🇸 Spain
#Finance #FinancialGain
2019-02
Bank of Valletta was identified in UN and U.S. law-enforcement reporting as a 2019 Maltese bank cyber-heist tied to North Korean cyber-enabled financial crime. The linked evidence places the case within DPRK/RGB-directed operations involving SWIFT-enabled…
🇲🇹 Malta
#Finance #SWIFT #FinancialGain
2019-01
Cryptopia disclosed a January 2019 cryptocurrency exchange breach in New Zealand that triggered a police investigation and community blockchain tracing of stolen assets while key loss details were still emerging. Subsequent blockchain analysis tracked sto…
🇳🇿 New Zealand
#Cryptocurrency #FinancialGain
2018-12
In late 2018, a Gyeongbuk Hana Center employee’s PC in South Korea was infected through a malicious email, exposing files containing personal information for 997 North Korean defectors. The leaked data included names, birth dates, and addresses, while con…
🇰🇷 Korea, Republic of
#Government #DataBreach #Espionage
2018-12
UN Panel evidence lists a Thailand-linked financial-institution case in its annex of suspected DPRK cyber attacks on banks and cryptocurrency exchanges. The excerpt places the case among SWIFT-style attempted thefts and records a USD 100 million attempted…
🇹🇭 Thailand
#Finance #FinancialGain
2018-12
RedBanc, a Chilean financial network, was tied in linked reporting to a Lazarus-associated intrusion after disclosure of malware and tooling overlaps with other financial-sector activity. QuoScient reported that a Lazarus-linked tool observed in the RedBa…
🇨🇱 Chile
#Finance #ATM #FinancialGain
2018-10
trade.io reported an October 2018 contained cryptocurrency breach in which 50 million Trade Tokens reserved for its liquidity pool were moved from a hardware wallet and abnormal TIO trading appeared on external exchanges. The company said customer account…
🇨🇭 Switzerland
#Cryptocurrency #FinancialGain
2018-10
South Korea's Defense Acquisition Program Administration disclosed that 10 internet-connected PCs were compromised in late 2018 after abnormal traffic was identified from agency IP space. Reporting described leaked internal materials, delayed response, an…
🇰🇷 Korea, Republic of
#Government #DataBreach #Espionage
2018-10
FASTCash was a DPRK-attributed banking campaign in which HIDDEN COBRA/Lazarus-linked operators compromised payment-switch infrastructure to authorize fraudulent ATM withdrawals by manipulating ISO 8583 transaction responses. Reports describe AIX and later…
ZZZ
#Finance #FinancialGain
2018-10
Group-IB described an attempted attack on HSBC's Maltese office that was detected and stopped, then linked the activity to the same Lazarus SWIFT-focused cluster behind later thefts from Mexican banks, Banco de Chile, AkBank, and Bank of Valletta. The rep…
🇲🇹 Malta
#Finance #FinancialGain
2018-10
BankIslami was described in U.S. law-enforcement reporting as a 2018 ATM cash-out theft in Pakistan involving funds from North Korean-perpetrated cyber crime schemes. The linked Justice Department material places the incident alongside DPRK/RGB-linked fin…
🇵🇰 Pakistan
#Finance #FinancialGain
2018-09
Indodax is referenced in U.S. and UN-linked reporting as one of multiple cryptocurrency entities affected by North Korean cyber-enabled financial theft and laundering activity associated in security reporting with Lazarus/APT38 and Bluenoroff. Later block…
🇮🇩 Indonesia
#Cryptocurrency #FinancialGain
2018-09
The WaveString case involved Lazarus-linked supply-chain activity around the Coinis cryptocurrency trading platform and the fake software company Celas. Kaspersky reporting described attackers stealing a code-signing certificate and using it to sign malwa…
🇰🇷 Korea, Republic of
#Cryptocurrency #SupplyChain
2018-09
Zaif, a Japan-based cryptocurrency exchange, reported unauthorized external access to hot-wallet management servers on September 14, 2018, resulting in theft of BTC, MONA, and BCH from customer and exchange assets. Linked reporting describes service suspe…
🇯🇵 Japan
#Cryptocurrency #FinancialGain
2018-08
Ryuk emerged as a targeted ransomware operation against enterprises, with operators using prior network access, credential collection, lateral movement, and hands-on deployment to encrypt critical systems and disrupt organizations in sectors including gov…
🇺🇸 United States, ZZZ
#FinancialGain