North Korean authorities have arrested a group of elite, state-trained hackers accused of stealing and laundering digital assets belonging to the country’s own financial institutions, according to Daily NK, a South Korea-based media outlet specializing in North Korea news. The arrests reportedly took place on July 12 after an internal probe linked suspicious cryptocurrency transactions to a safe house in Pyongyang.
Hackers targeted state banks
The group allegedly broke into the networks of the Chosun Central Bank and the Foreign Trade Bank of North Korea. Both institutions are central to North Korea’s efforts to manage domestic and cross-border financial operations and have frequently come under international scrutiny for sanctions violations.
According to a source cited by Daily NK, the cybercrime ring was led by individuals with previous affiliations to the Reconnaissance and Intelligence General Bureau, North Korea’s main agency for espionage and cyber warfare. The group reportedly included talented new recruits from top North Korean universities, including Kim Chaek University of Technology and Pyongyang University of Science.
Investigators found that the hackers used advanced military-grade hacking skills, encrypted messaging, and Chinese wireless technology to orchestrate the theft. The funds were allegedly funneled out of the country with the help of brokers operating in China.
Chinese intermediaries reportedly converted the stolen cryptocurrency into cash, which was then smuggled back into North Korea through contacts stationed in border areas.
Mini dictionary: Reconnaissance and Intelligence General Bureau, North Korea’s primary intelligence agency responsible for foreign espionage, cyber operations, and clandestine activities.
Pyongyang’s well-documented cyber operations
North Korea has gained global notoriety as a major sponsor of sophisticated cryptocurrency and cyber-enabled thefts. International authorities, including the United Nations and governments from the United States, South Korea, and Japan, have repeatedly accused North Korean entities of orchestrating large-scale crypto heists around the world.
Among the most prominent of these groups is the Lazarus Group, often linked to billion-dollar thefts from blockchain projects and crypto exchanges. U.S. officials attribute some of the most significant crypto attacks in recent history to North Korean operatives, including incidents targeting the Ronin Bridge, Harmony Horizon Bridge, Atomic Wallet, Alphapo, CoinEx, DMM Bitcoin, and WazirX platforms.
| Targeted Platform | Attack Year | Alleged Stolen Amount |
|---|---|---|
| Ronin Bridge | 2022 | $620 million |
| Harmony Horizon Bridge | 2022 | $100 million |
| Atomic Wallet | 2023 | $35 million |
| CoinEx | 2023 | $70 million |
Despite mounting evidence and repeated international accusations, Pyongyang has consistently dismissed claims of involvement in such operations, labeling them as politically motivated fabrications.
North Korea has long faced accusations from the United States, United Nations, and its neighbors over its cyber units’ role in global cryptocurrency thefts, including attacks connected to Ronin Bridge and Harmony Horizon Bridge.
Unprecedented internal incident
The latest episode differs from North Korea’s typical external hacking operations. In this case, the hackers reportedly targeted the regime’s own institutions, raising questions within the country’s security apparatus about loyalty and oversight.
If confirmed, the incident would reflect an unprecedented situation where cyber operatives, trained for offensive missions beyond North Korea, diverted their skills internally, causing losses to the state’s own funds.
Individuals reportedly educated and equipped by the North Korean government for sophisticated cyber missions are now accused of breaching the trust of the very institutions they served.




