North Korean security services have arrested a group of former elite state hackers who successfully breached the country’s Central Bank and Foreign Trade Bank, stealing government funds through cryptocurrency conversion and cash smuggling. The revelation that veterans of North Korea’s cyber operations units turned against their own government has shocked officials in Pyongyang.
According to sources speaking to Daily NK, the National Intelligence Service (formerly the Ministry of State Security) detained the group members on July 12. The hackers targeted two critical financial institutions: the Central Bank of North Korea, responsible for currency issuance and state fund management, and the Foreign Trade Bank, which handles the country’s foreign payments.
Who Led the Hacking Operation?
The operation was led by former military personnel from the cyber operations unit of the General Reconnaissance Bureau, North Korea’s military intelligence agency. After leaving military service, these veterans recruited talented young IT specialists from Kim Chaek University of Technology and Pyongyang University of Science and Technology. The group secretly established a cryptocurrency trading network to launder the stolen funds, with participants motivated purely by personal enrichment rather than any political objectives.
How Did the Hackers Execute the Breach?
The criminals utilized specialized Chinese-manufactured wireless equipment and encrypted messaging applications, leveraging technical skills developed during their military service and university training. These capabilities enabled them to penetrate the heavily guarded internal networks and payment systems of both banks. They withdrew portions of state trade funds and foreign currency in small amounts to avoid detection, then transferred the funds to overseas cryptocurrency wallets. Chinese brokers converted the cryptocurrency into cash, while contacts in border regions exchanged the laundered funds for U.S. dollars and Chinese yuan in real-time. The network included accomplices in Sinuiju in North Pyongan Province and Hyesan in Yanggang Province.
How Were the Hackers Caught?
Despite causing significant financial damage, the group was quickly exposed. Officials in Pyongyang noticed small discrepancies when reconciling foreign currency payments and discovered suspicious logs and connections from foreign IP addresses. The National Intelligence Service launched an internal investigation, and investigators determined that encrypted traffic originated from a safe house in Pyongyang. On the night of July 12, agents raided the location and caught the ringleaders and IT specialists red-handed while sitting at computers laundering funds. Authorities confiscated computer equipment worth hundreds of thousands of dollars and seized unregistered disposable phones.
What Followed the Arrests?
Armed National Intelligence Service personnel took positions around the Foreign Trade Bank headquarters and the Central Bank computing center, completely blocking outside access. Vehicles equipped with signal detection equipment deployed throughout Pyongyang to locate additional equipment operating on the same non-standard frequencies used by the group. News of the case spread among Pyongyang’s elite, military, and university communities, causing shock due to the scale and audacity of the scheme. One official reportedly stated that the hackers used skills the state taught them to protect the country but instead robbed the state treasury, suggesting punishment would extend beyond typical collective responsibility principles to affect the criminals’ families. High-ranking officials from the General Reconnaissance Bureau and the scientific-technical education sector are reportedly exercising caution, fearing the scandal may implicate them as well.
Source: Xakep