iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
India's trade with West Asia gradually improving: Commerce Secretary Rajesh Agrawal Cass Report: Freight Volume Recovery On Track for Second Half of 2026 India Receives 32% Deficient Rains During June 1-15, IMD Data Shows ANNAM.AI and Syngenta Partner to Deliver AI-Driven Climate-Smart Agriculture to Indian Farmers Microsoft CEO Satya Nadella warns AI dominance could 'hollow out entire industries' Open-source Discord alternatives: What Stoat and Element actually fix - Engadget India launches producer price index; wholesale inflation gauge to be phased out in five years India, UK work to resolve issues holding up trade pact implementation, says official ‘Let the oil flow’: What Trump’s possible peace deal with Iran, Strait of Hormuz opening mean for India Samsung MAX VPN Shuts Down June 15, 2026, Leaving 50 Million Users Seeking Alternatives India's trade with West Asia gradually improving: Commerce Secretary Rajesh Agrawal Cass Report: Freight Volume Recovery On Track for Second Half of 2026 India Receives 32% Deficient Rains During June 1-15, IMD Data Shows ANNAM.AI and Syngenta Partner to Deliver AI-Driven Climate-Smart Agriculture to Indian Farmers Microsoft CEO Satya Nadella warns AI dominance could 'hollow out entire industries' Open-source Discord alternatives: What Stoat and Element actually fix - Engadget India launches producer price index; wholesale inflation gauge to be phased out in five years India, UK work to resolve issues holding up trade pact implementation, says official ‘Let the oil flow’: What Trump’s possible peace deal with Iran, Strait of Hormuz opening mean for India Samsung MAX VPN Shuts Down June 15, 2026, Leaving 50 Million Users Seeking Alternatives
Home ›› Technology ›› Cybersecurity ›› North Korea accounts for nearly half of all state-sponsored tech attacks, Crowdstrike finds

North Korea accounts for nearly half of all state-sponsored tech attacks, Crowdstrike finds

A new Crowdstrike report reveals that nearly half (47%) of state-sponsored cyber attacks against US tech companies originate from a single North Korean group, Famous Chollima. The group uses AI-enhanced fake identities to infiltrate remote tech jobs, stealing intellectual property and generating funds that directly support Kim Jong Un's weapons of mass destruction programs.

iG
iGEN Editorial
June 15, 2026
North Korea accounts for nearly half of all state-sponsored tech attacks, Crowdstrike finds

A new Crowdstrike report has found that nearly half (47%) of all state-sponsored attacks against US tech companies came from a single North Korean group, tracked as Famous Chollima, according to TechRadar. The funds from these intrusions are channeled into developing and procuring weapons of mass destruction for the Kim Jong Un regime.

The Scale of the Threat

North Korea has long relied on cyber activity as a source of revenue, given international sanctions and its closed economy, which has earned it the 'Hermit Kingdom' label. The country operates several notorious cyber units, including the Lazarus Group, but the recent IT worker infiltration campaigns are attributed primarily to Famous Chollima. The Crowdstrike report underscores that the scale of North Korea's cyber operations had not been fully understood until now.

How the Attacks Work

The group applies for remote tech jobs at Western firms, using AI tools to generate fake personas that include synthetic images, tied to stolen documents such as passports and driving licenses, to pose as nationals of the target country. If hired, the fake worker receives a salary that is often thousands of times higher than the average North Korean income, with the funds diverted to the state. Additionally, the workers steal intellectual property and trade secrets from their employers, using them to advance the regime's own tech industry or to launch further attacks.

Attack Vector Key Tactics Purpose
Fake IT worker schemes AI-generated personas, stolen identity documents Salary extraction, IP theft
Insider threats Leveraging access to steal secrets Advance North Korea's tech / launch secondary attacks
Extortion Threaten to reveal identity unless paid a fee Avoid reputational damage for hiring sanctioned individuals

Proceeds Fueling WMD Development

According to the report, the cyber-enabled revenue directly supports the development and procurement of weapons of mass destruction. This linkage between cyber crime and nuclear proliferation has significant implications for international trade compliance, as companies that inadvertently hire North Korean operatives may face sanctions violations and supply chain disruptions.

Implications for Trade and Compliance

For import/export managers, customs brokers, and trade policy analysts, the findings highlight a growing risk in the tech supply chain. Hiring a sanctioned individual can expose a company to penalties under U.S. export control laws and sanctions regimes. The use of AI to enhance fake identities makes due diligence more challenging. Trade professionals must strengthen their vendor and employee screening processes to avoid unintentionally facilitating North Korea's weapons programs. The report serves as a reminder that cyber attacks are not just an IT issue but a national security and trade compliance concern.

What to watch: Expect increased scrutiny from regulators on companies with remote tech workforces and tightened enforcement of sanctions against North Korea-linked cyber activities.


Sources: TechRadar – Main Feed

Keep Reading

Recommended Stories

North Korean Phishing Scheme Targets Developers for Crypto Theft Technology

North Korean Phishing Scheme Targets Developers for Crypto Theft

A North Korean phishing campaign, led by the group UNK_DeadDrop, targets developers with fake job offers to steal cryptocurrency. This operation mirrors tactics used by Lazarus but employs email-based lures and new payloads.

June 9, 2026
Novo Nordisk Reveals Clinical Trials Data Breached in Cyberattack, Patient IDs Exposed Technology

Novo Nordisk Reveals Clinical Trials Data Breached in Cyberattack, Patient IDs Exposed

Novo Nordisk, the maker of Ozempic and Wegovy, confirmed a cyberattack that breached pseudonymized clinical trial data, including patient IDs, biomarkers, and lifestyle factors. The company stated no personally identifiable information (PII) was exposed and core operations remain unaffected. Third-party cybersecurity experts are investigating.

June 15, 2026
How emerging tech is rewriting cyberwarfare: AI and quantum computing shift the balance Technology

How emerging tech is rewriting cyberwarfare: AI and quantum computing shift the balance

AI, quantum computing, and automation are converging to fundamentally alter cyberwarfare. According to a TechRadar analysis, 65% of IT decision-makers say AI innovation outruns cybersecurity policies, while 79% fear nation-states will use AI for sophisticated attacks. Quantum computing, though not yet commercial, is already seen as an existential threat by a quarter of IT leaders, with China and Russia actively developing quantum-based weapons and navigation systems.

June 15, 2026
Meta confirms thousands of Instagram accounts were hacked by abusing its AI chatbot Technology

Meta confirms thousands of Instagram accounts were hacked by abusing its AI chatbot

Meta confirmed that hackers abused a flaw in its AI chatbot to reset passwords for thousands of Instagram accounts, affecting at least 20,225 users. The attack exploited a bug that allowed the chatbot to send password reset links to unverified email addresses. This incident underscores the security risks enterprises face when deploying AI chatbots for account management and authentication.

June 14, 2026