A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide
2026-08-05 • Wired •
A Greece-based security researcher, Vangelis Stykas, spent 22 months inside North Korean hackers' command-and-control servers and found evidence that 1,640 companies across 57 countries were impacted by DPRK hacking operations, with 700–800 suffering "really damaging" intrusions including root access to servers, AWS, and cryptocurrency wallets. The intrusions primarily used the Contagious Interview fake-job-offer tactic—luring software developers to download malware-laced coding tests—and North Korean IT workers infiltrated companies via fraudulent remote employment. Despite access to highly sensitive data such as health and criminal records, the hackers kept a tight focus on stealing cryptocurrency, though persistent access creates the risk of later espionage piggybacking.