iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
Relay Q: London Startup's AI Microphone Puts Hands-Free Voice Dictation on the Desktop Google Pixel 10a Crowned Best Budget Pixel in WIRED's Updated 2026 Buying Guide Global Steel Wire seeks fresh Santander terminal concession Veritas Shipmanagement books fresh ultramax pair at COSCO yard, Splash247 reports Seanergy linked to fresh newcastlemax at Hengli as dry bulk orderbook grows Weaker rupee may push foreign assets over FAST-DS Rs 1 crore limit, raising tax bill 45 Indian power plants face critically low coal stocks as monsoon hits supply SFL Makes Fresh $363m Car Carrier Play With Four LNG Dual-Fuel Newbuilds Iran Blacklist Threatens Hormuz Shuttle Tanker Lifeline for Gulf Crude Keyfield International Enters Dredging Market with $24.7m Vessel Acquisition Relay Q: London Startup's AI Microphone Puts Hands-Free Voice Dictation on the Desktop Google Pixel 10a Crowned Best Budget Pixel in WIRED's Updated 2026 Buying Guide Global Steel Wire seeks fresh Santander terminal concession Veritas Shipmanagement books fresh ultramax pair at COSCO yard, Splash247 reports Seanergy linked to fresh newcastlemax at Hengli as dry bulk orderbook grows Weaker rupee may push foreign assets over FAST-DS Rs 1 crore limit, raising tax bill 45 Indian power plants face critically low coal stocks as monsoon hits supply SFL Makes Fresh $363m Car Carrier Play With Four LNG Dual-Fuel Newbuilds Iran Blacklist Threatens Hormuz Shuttle Tanker Lifeline for Gulf Crude Keyfield International Enters Dredging Market with $24.7m Vessel Acquisition
Home ›› Technology ›› Cybersecurity ›› North Korea accounts for nearly half of all state-sponsored tech attacks, Crowdstrike finds

North Korea accounts for nearly half of all state-sponsored tech attacks, Crowdstrike finds

A new Crowdstrike report reveals that nearly half (47%) of state-sponsored cyber attacks against US tech companies originate from a single North Korean group, Famous Chollima. The group uses AI-enhanced fake identities to infiltrate remote tech jobs, stealing intellectual property and generating funds that directly support Kim Jong Un's weapons of mass destruction programs.

iG
iGEN Editorial
June 15, 2026
North Korea accounts for nearly half of all state-sponsored tech attacks, Crowdstrike finds

A new Crowdstrike report has found that nearly half (47%) of all state-sponsored attacks against US tech companies came from a single North Korean group, tracked as Famous Chollima, according to TechRadar. The funds from these intrusions are channeled into developing and procuring weapons of mass destruction for the Kim Jong Un regime.

The Scale of the Threat

North Korea has long relied on cyber activity as a source of revenue, given international sanctions and its closed economy, which has earned it the 'Hermit Kingdom' label. The country operates several notorious cyber units, including the Lazarus Group, but the recent IT worker infiltration campaigns are attributed primarily to Famous Chollima. The Crowdstrike report underscores that the scale of North Korea's cyber operations had not been fully understood until now.

How the Attacks Work

The group applies for remote tech jobs at Western firms, using AI tools to generate fake personas that include synthetic images, tied to stolen documents such as passports and driving licenses, to pose as nationals of the target country. If hired, the fake worker receives a salary that is often thousands of times higher than the average North Korean income, with the funds diverted to the state. Additionally, the workers steal intellectual property and trade secrets from their employers, using them to advance the regime's own tech industry or to launch further attacks.

Attack Vector Key Tactics Purpose
Fake IT worker schemes AI-generated personas, stolen identity documents Salary extraction, IP theft
Insider threats Leveraging access to steal secrets Advance North Korea's tech / launch secondary attacks
Extortion Threaten to reveal identity unless paid a fee Avoid reputational damage for hiring sanctioned individuals

Proceeds Fueling WMD Development

According to the report, the cyber-enabled revenue directly supports the development and procurement of weapons of mass destruction. This linkage between cyber crime and nuclear proliferation has significant implications for international trade compliance, as companies that inadvertently hire North Korean operatives may face sanctions violations and supply chain disruptions.

Implications for Trade and Compliance

For import/export managers, customs brokers, and trade policy analysts, the findings highlight a growing risk in the tech supply chain. Hiring a sanctioned individual can expose a company to penalties under U.S. export control laws and sanctions regimes. The use of AI to enhance fake identities makes due diligence more challenging. Trade professionals must strengthen their vendor and employee screening processes to avoid unintentionally facilitating North Korea's weapons programs. The report serves as a reminder that cyber attacks are not just an IT issue but a national security and trade compliance concern.

What to watch: Expect increased scrutiny from regulators on companies with remote tech workforces and tightened enforcement of sanctions against North Korea-linked cyber activities.


Sources: TechRadar – Main Feed

Keep Reading

Recommended Stories