North Korean ex-military hackers infiltrated two major national banks, stealing funds that were transferred to cryptocurrency wallets.

Key Takeaways
  • North Korean former military hackers infiltrated Central Bank of Korea and Trade Bank networks on July 12.
  • The criminal group stole state trade funds and transferred them to overseas cryptocurrency wallets through shell accounts.
  • North Korean State Security Agency deployed signal detection vehicles and arrested the masterminds in a Pyongyang safe house raid.

A report by the defector-run 《Daily NK》 says a criminal group made up of former military hackers who have retired from North Korea’s Reconnaissance General Bureau (now the Reconnaissance Intelligence Bureau) was recently discovered to have compromised the internal network systems of the North Korean Central Bank and the Trade Bank. On July 12, North Korea’s National Intelligence Service raided a safehouse in Pyongyang and arrested the mastermind and IT personnel who were laundering money, confiscating computer equipment valued at dozens of thousands of USD and multiple unregistered mobile phone numbers.

Criminal group composition: a cross-industry mix of former Reconnaissance General Bureau veterans and university elites

The mastermind of the incident is several retired military veterans who previously worked at North Korea’s Reconnaissance General Bureau (now the Reconnaissance Intelligence Bureau, long known for cyber espionage and hacking operations). After retiring, they recruited young IT talents from Kim Chaek University of Technology and Pyongyang University of Science and Technology, and together built an encrypted cryptocurrency trading network designed to deliberately evade state surveillance, with the goal of earning foreign currency and accumulating wealth.

The group used special wireless communication devices manufactured in China and encrypted communication software, and leveraged the hacking skills they accumulated during their time in the military and at university to successfully breach the internal systems of the two banks and their cross-border payment mechanisms.

Money-laundering route: a complete chain of splitting small amounts, overseas crypto wallets, and cashing out at the border

The group’s fund transfer path is as follows:

· Compromise the internal network systems of the North Korean Central Bank and the Trade Bank

· Disperse state trade funds into shell (front) accounts

· Split into multiple small-value transfers and send them into overseas cryptocurrency wallets

· Convert the cryptocurrency into cash through Chinese brokers

· Have border contacts in areas such as Sinŭiju and Hyesan promptly exchange the funds into USD and yuan

The North Korea intelligence apparatus’s pursuit process and the safehouse raid

North Korean officials initially noticed a slight discrepancy in amounts during the review of foreign currency payment approvals, and at the same time detected suspicious records of access from overseas IP addresses. The National Intelligence Service then launched a secret internal investigation.

Following the encrypted traffic of cryptocurrency transactions, investigators identified a safehouse in Pyongyang and carried out a nighttime raid on the evening of July 12. They arrested the mastermind and IT personnel on the spot and seized computer equipment worth dozens of thousands of USD as well as unregistered mobile phone-number devices. During the operation, armed intelligence personnel reportedly deployed perimeter security around the Trade Bank’s headquarters and the North Korean Central Bank’s computer center, and sent signal-detection vehicles to track the abnormal wireless frequencies reportedly used by the group. Authorities are said to expect to impose severe punishment on those involved.

FAQ

Who is the mastermind behind this North Korean internal hacking case, and when was he arrested?

According to Daily NK’s report, the mastermind is several military hackers who retired from North Korea’s Reconnaissance General Bureau (now the Reconnaissance Intelligence Bureau). They recruited IT talent from top North Korean universities such as Kim Chaek University of Technology to form the criminal group. On July 12, 2026, North Korea’s National Intelligence Service raided a safehouse in Pyongyang and arrested everyone involved. The related reports have not yet been fully verified by independent media such as CoinDesk.

How does the group launder the stolen funds?

The group disperses stolen state trade funds into shell accounts, splits them into multiple small-value transactions to send to overseas cryptocurrency wallets, then converts the cryptocurrency into cash through Chinese brokers, and ultimately has border contacts in areas such as Sinŭiju and Hyesan exchange the funds into USD and yuan.

How big was the scale of North Korea’s cryptocurrency theft revealed in the CertiK report?

According to a report published by CertiK in May 2026, hacker groups linked to North Korea caused cryptocurrency losses of up to $2.06 billion in 2025, accounting for 60% of global cryptocurrency theft losses. Since 2016, the cumulative amount stolen has reached $6.75 billion.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments