Being a North Korean Hacker Is About to Be Less Fun
Being a North Korean Hacker Is About to Be Less Fun
North Korea will have to rein in its pet hackers after seemingly losing control over them.
Last week we covered the news that a group of former North Korean military intelligence operatives had been caught hacking into the country's banks to steal funds for their personal benefit.
Daily NK reports Pyongyang's elite are shocked at "the scale and audacity of the scheme." Punishment for those involved will reportedly be extreme, with one official saying, "It will be hard for the entire family line to survive." Grim.
The outlet also says officials in North Korea's Reconnaissance General Bureau (RGB), the organization responsible for cyber espionage, are worried that the scandal could even roll uphill and claim their scalps.
We expect, therefore, that this incident will result in some substantial tightening of operational controls.
North Korea's state-sanctioned cybercrime operations can be lumped into three buckets: high-value targeted cryptocurrency hacks, broad-based fraudulent worker schemes, and ransomware extortion operations.
There is some evidence that in addition to former operatives stealing from North Korean banks, the government there is also losing control over its ransomware operators.
North Korea first dipped its toe into ransomware by developing its own strains. In 2021 and 2022, one of its hacker groups, Andariel, created two different ransomware strains that it used on organizations in the U.S., South Korea, and Japan, including against the American health sector.
After dabbling in roll-your-own ransomware, in recent years North Korean hackers began collaborating with the ransomware-as-a-service (RaaS) ecosystem. Threat intelligence reports say that Andariel used Play ransomware in 2024 and Medusa ransomware in 2025.
Last week, South Korean security firm AnhLab reported that a state-controlled North Korean hacker group is also collaborating with Gunra ransomware. It's unclear whether this collaboration is state sanctioned or not.
North Korean cyber units are supposed to funnel stolen funds into the state's coffers. By design, however, RaaS offerings help skilled individuals profit from their hacks.
Given the recent hack of the country’s banks, and this news of DPRK operators getting cozy with criminal outfits, we suspect that RGB officials might start to look at RaaS operations a bit differently. If you're personally on the hook for extreme punishments if your underlings go rogue, why put them in a position where they're tempted to put their hands in the cookie jar?
So what's next for North Korean state-sponsored hacks? Scaling back its ransomware operations is one possibility, but it is not the only option. We suspect a strong tightening of controls on its hacking teams in general is more likely.
There is good evidence that North Korea uses very tight internal controls on its scam information technology (IT) workers already. North Korean defectors have described constant surveillance and screen monitoring, isolation, movement restrictions, and strict work quotas.
It doesn't appear that the same level of control is currently applied to the country's hackers. A 2014 report says they were viewed as the elite of the military. Rather than being intensively surveilled, they had privilege and more freedom.
That's almost certainly a thing of the past. Being a state-backed DPRK hacker is about to be a lot less fun.
Cyber War Is Here, and America Is Politically Unprepared
Multiple cyber provocations targeting America's water sector have revealed how unprepared the U.S. is to deal with the political fallout of cyberattacks against critical infrastructure.
The Washington Post reported U.S. intelligence agencies have determined that Iran is behind the attacks on water facilities in Minnesota that we covered last week. Now, at least a dozen states have experienced similar disruptions. Per Risky Bulletin:
Some of the new public incidents have been reported in Clayton County, Georgia and the city of Duchesne, Utah. Customers were left low pressure or no water in Clayton County in the middle of the night last week. In Utah, the cyberattack made pumps run dry while their control panels said they were pumping water. The incident impacted an oilfield wastewater disposal site but did not cause any environmental damage.
A Cybersecurity and Infrastructure Security Agency (CISA) advisory about the escalating activity says that it has "resulted in boil water notices" and led to "sustained manual operations."
This campaign is historically significant. As far as we know, it is the first time a country has responded to kinetic attacks in the cyber domain by targeting an aggressor's critical infrastructure.
The direct impact of the hacks on water supply have been manageable so far, which is consistent with what we've seen in other conflicts over the past several years.
The effects of wartime cyberattacks are relatively short-lived, and they have been most useful when combined with tightly orchestrated conventional operations, such as America's 2025 strikes against Iranian nuclear facilities or its capture of Venezuelan President Nicolás Maduro. Without complementary conventional action, Iran's attacks on America's water systems don't amount to much.
Having said that, the strategic goal of the campaign is to erode political support for the war. In our view, widespread publicity without accompanying devastation is the perfect way to achieve that goal.
This campaign was entirely predictable. As we've written before, if you bomb Iran, you should expect cyber operations against critical infrastructure in return. Even as far back as 2013, Iranian hackers compromised control systems at a New York state dam and tried to affect its operation.
We're only surprised that this current campaign took so long to spin up.
The U.S. government's response has so far been fairly muted. CISA has advised organizations to remove targeted devices from the internet and to connect to them using VPNs or gateway devices, to enable passwords and use strong ones, and allowlist IP addresses for remote access.
Since it was pretty clear that Iran would respond to missiles with cyber, we think running a campaign to fix these vulnerabilities before military action against Iran would have left the U.S. government in a much better place to deal with this campaign.
It's true that a preparatory cybersecurity drive like this wouldn't have made America's water infrastructure perfectly secure. It's too big, too decentralized, and too resource constrained. It could, however, have made a political difference. "We understand the problem, we've been putting mitigations in place, some systems remain vulnerable but we can assure everyone the impacts will be limited." In other words: We've got this under control.
As it stands, despite the campaign's predictability, the Trump administration is on the back foot. President Trump even blamed Minnesota and its officials for the attacks.
That's some pretty bonkers politics, and exactly the sort of soundbite Iran will chalk up in the "win" column.
Three Reasons to Be Cheerful This Week:
- Chrome in the AI era: Google's Chrome team has described how it is using artificial intelligence (AI) to make the browser safer by improving vulnerability discovery and patching. The team uses AI agents coupled with harnesses to find and fix vulnerabilities as well as to triage external bug reports. Google says that it fixed 1,072 security bugs over the previous two stable releases.
- OpenAI disrupts Cambodian scammers: OpenAI announced last week that it had disrupted a Cambodia-based scam operation that was using ChatGPT to support "investment, romance, gambling and impersonation schemes." The good news here is that a tip from WhatsApp led OpenAI to what it found to be a coordinated network of accounts. We are all in favor of more coordination to counter scam compounds.
- Romance scammer gets seven years: The Department of Justice announced last week that Derrick Van Yeboah was sentenced to 85 months in prison for his role in romance and business email compromise scams. The Ghanaian was involved in a criminal organization that stole and laundered more than $100 million from dozens of victims. The Justice Department says Van Yeboah "personally perpetrated many of the romance scams by impersonating fake romantic partners." His victims transferred millions of dollars to the gang.
Shorts
Frontier Lab Cybersecurity Testing Controls Are Rubbish
In recent weeks, OpenAI and then Anthropic announced that their AI agents have, ahem, exceeded expectations in different testing scenarios. In both cases, AI models escaped notional testing sandboxes, and the companies detected the escapes days to weeks after the fact.
By contrast, the U.K.'s AI Security Institute (AISI) wrote this week:
On 28th July 2026, AISI's Security Team detected unusual data transfers leaving our research systems during a routine cyber evaluation. On investigation, we found that some of the agents being tested had engaged in sustained, potentially harmful activity directed at real people and organizations. We declared a security incident and, within roughly one hour of discovery, had contained it and begun a full investigation. [emphasis added]
How refreshingly competent!
AISI's write-up covers essentially the same type of behavior as described by OpenAI and Anthropic, but it is far better. It states things plainly without guff and corpo-speak.
Risky Biz Talks
You can find the audio edition of this newsletter and other fine podcasts and interviews in the Risky Biz News feed (RSS, iTunes or Spotify).
In our latest "Between Two Nerds" discussion, Tom Uren and The Grugq talk about whether hacker culture is inherently anti-authoritarian and how different states get their country's hackers to work for them.
From Risky Bulletin:
Hacker breaches Hungary's State Treasury: The same hacker who hit and wiped Romania's land registry database has now hacked Hungary's State Treasury in another brazen intrusion into an extremely sensitive government system.
The incident took place last week, and portions of the stolen data have since been put up for sale on an underground hacking forum.
The intrusion was confirmed to local journalists by Hungary's State Treasury over the weekend.
Russia is behind the recent hotel WiFi hacks: A Russian state-sponsored hacking group is behind a recent hacking wave that has targeted and compromised hotel WiFi gateways across the globe.
Microsoft says the campaign is far larger and more complex than it was initially reported to be by ReliaQuest two weeks ago.
ReliaQuest said the hackers were modifying DNS traffic on hotel networks to redirect users to Microsoft-themed phishing sites. Microsoft says the attacks also redirected users to malware downloads, often using ClickFix pages to trick users into downloading and running the payloads.
Nonprofit offers $22,000 bounty for INC ransomware group: An international crime-fighting nonprofit organization is offering a $22,000 bounty for any information on members of the INC ransomware group.
To be eligible for a payout, the provided information must lead to the identification, arrest, or disruption of the gang's operations.
Crime Stoppers International is the international branch of Crime Stoppers, a U.S. foundation that was established in the 1970s to allow anonymous and private individuals to provide aid in U.S. law enforcement investigations that may lack staffing or other resources.
