Key Takeaways
- Former North Korean military intelligence operatives reportedly stole from domestic banks for personal gain, exposing a serious internal-control failure.
- Pyongyang may impose tighter surveillance on hackers, particularly those working with ransomware-as-a-service groups.
- Businesses should expect North Korean cyber activity to remain aggressive even if internal oversight changes its tactics and targeting.
North Korea's cyber apparatus faces an unusual threat from within. Former military intelligence operatives have reportedly been caught hacking the country's own banks and diverting money for personal benefit, rather than sending proceeds to the state.
Daily NK reported that Pyongyang's elite were shocked by the "scale and audacity of the scheme." One official described the expected punishment in stark terms: "It will be hard for the entire family line to survive." Officials in the Reconnaissance General Bureau, or RGB, are also reportedly concerned that responsibility could travel up the chain of command.
That prospect changes the incentives surrounding North Korea's cyber operations. RGB managers are not merely dealing with a theft investigation. They are confronting evidence that technically skilled personnel, once given access, autonomy, and criminal connections, can redirect the machinery of state-backed hacking toward themselves.
Cybercrime generates billions in revenue for North Korea. Chainalysis estimated that DPRK-linked actors stole at least $2.02 billion in cryptocurrency during 2025, an increase of 51% year over year. Its cumulative lower-bound estimate reached $6.75 billion. DPRK attacks also accounted for a record 76% of service compromises, reflecting a focus on valuable cryptocurrency services rather than indiscriminate malware distribution.
The cybercrime ecosystem includes targeted cryptocurrency theft, exemplified by Lazarus Group's attack on Bybit in February 2025 and regional attention surrounding exchanges such as Upbit. It also involves fraudulent IT workers securing remote jobs overseas, alongside widespread ransomware and extortion campaigns.
These operations depend on trusted personnel working outside conventional North Korean institutions. That creates an uncomfortable question for Pyongyang: how much freedom can it give hackers without creating opportunities for private enrichment?
Ransomware presents a difficult governance problem for state oversight. Andariel developed and deployed its own ransomware strains in 2021 and 2022, targeting organizations in the U.S., South Korea, and Japan, including the American health sector. The group later moved closer to the ransomware-as-a-service market, using Play ransomware in 2024 and Medusa ransomware in 2025.
South Korean security firm AnhLab recently reported that a state-controlled North Korean hacking group was also collaborating with Gunra ransomware. Whether that relationship received formal state approval remains unclear. Regardless, ransomware-as-a-service introduces payment-sharing arrangements, criminal intermediaries, and infrastructure outside Pyongyang's direct control.
North Korea is unlikely to abandon cyber-enabled revenue collection. The amounts involved are too substantial, and sanctions constrain its access to conventional international finance. The Korea Economic Institute of America characterizes North Korean cybercrime as a growing challenge for the U.S.-South Korea alliance, particularly where cryptocurrency theft and sanctions evasion overlap.
A more plausible outcome is tighter supervision. Defectors have described North Korean fraudulent IT workers operating under constant surveillance, screen monitoring, movement restrictions, isolation, and strict quotas. Historically, elite military hackers appear to have enjoyed greater privilege and freedom. The bank thefts could bring those arrangements closer together.
For defenders, stricter RGB oversight will not necessarily reduce attack volume. It could instead produce more centralized target selection, additional monitoring of cryptocurrency flows, and less tolerance for operations that expose personnel to independent criminal networks.
Security teams can prepare by mapping observed North Korean behavior through MITRE ATT&CK and organizing controls around identity, access, detection, and recovery. Cryptocurrency businesses should give particular attention to privileged access, transaction approval workflows, and social engineering against developers. Other employers must strengthen remote-worker verification and monitor unusual access to proprietary data.
Pyongyang's response may make life harsher for its cyber operators. For businesses outside North Korea, however, the underlying threat is likely to persist, characterized by more discipline and a sharper focus on revenue that reaches the state.
⬇️