Monday, August 3, 2026

Policy & Regulation

CrowdStrike report links North Korean hackers to half of US tech hacks

CrowdStrike reports that North Korean hackers posing as remote IT workers made up nearly half of all documented hands-on-keyboard intrusions at U.S. tech companies over the past year.

CrowdStrike report links North Korean hackers to half of US tech hacks
Photo: CrowdStrike press kit

A new report by cybersecurity firm CrowdStrike reveals that North Korean operatives have become a significant source of cyber intrusions across the technology sector. According to the report, which covers the period from April 2025 to May 2026, a North Korean hacking group known as Famous Chollima accounted for 47% of all state-backed activity targeting the tech sector. CrowdStrike found that these hackers, posing as remote IT workers and online recruiters, made up about half of all documented “hands-on-keyboard” intrusions at U.S. tech companies over the past year. The firm tracks these hands-on-keyboard intrusions because they represent real human hackers conducting malicious and evasive cyber activity, rather than automated malware that traditional security tools can catch. These attacks typically begin with stolen credentials, followed by the abuse of legitimate tools already present in the target’s systems to maintain persistent access.

These operatives are conducting malicious and evasive cyber activity by applying for remote roles at U.S., European, and Asian tech companies under false pretenses. To bypass security checks, the hackers utilize artificial intelligence to generate real-time deepfake images to spoof faces. They pair these deepfakes with fraudulent identity documents like stolen passports and driver licenses to pose as foreign nationals, allowing them to circumvent sanctions imposed by the West and the United Nations. Once hired, the hackers earn a salary from the companies they infiltrate, which is funneled back to the North Korean regime, while they simultaneously steal intellectual property and sensitive corporate information. When caught, the operatives often threaten to expose the stolen data unless the company pays a ransom.

Beyond corporate extortion, the hackers target blockchain developers to steal cryptocurrency, which the Kim Jong Un regime uses to skirt its inability to access the Western banking system. The stolen funds are used to fund its nuclear weapons program. The financial scale of this activity is substantial; North Korea has netted billions of dollars in stolen cryptocurrency over the years, including some $2 billion during 2025 alone.

Why it matters

This report highlights a critical shift in cyber warfare where state-backed actors are weaponizing remote work culture to infiltrate Western tech companies. By securing legitimate employment and stealing digital assets, these operatives bypass international sanctions to directly fund nuclear proliferation.