iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
India seeks to cut reliance on imported strawberry varieties with indigenous breeding Burnham Confirms Pragmatic North Sea Oil Stance in Trump Call, Fueling Drilling Debate Leaked Memo Links Iranian Hackers to Minnesota Water Utility Cyberattacks Everyone Is Freaking Out About OpenAI and Anthropic’s Race for Dominance Govt Debunks AI-Generated Fake Video of Finance Minister Nirmala Sitharaman Promoting Investment Scheme UPS Unveils Digital Tools to Attract Small Businesses Amid Strategic Shift from Low-Margin E-Commerce CPKC sets second-quarter revenue record as operating income rises 10% Your Freight Funnel Is Leaking Margin: What Your Reports Won't Show Transponders Off: Saudi Crude Tankers for India Exit Red Sea 'Dark' to Avoid Houthi Blockade Nvidia’s Open Source Alliance Snubs OpenAI and Anthropic, Deepening AI Rift India seeks to cut reliance on imported strawberry varieties with indigenous breeding Burnham Confirms Pragmatic North Sea Oil Stance in Trump Call, Fueling Drilling Debate Leaked Memo Links Iranian Hackers to Minnesota Water Utility Cyberattacks Everyone Is Freaking Out About OpenAI and Anthropic’s Race for Dominance Govt Debunks AI-Generated Fake Video of Finance Minister Nirmala Sitharaman Promoting Investment Scheme UPS Unveils Digital Tools to Attract Small Businesses Amid Strategic Shift from Low-Margin E-Commerce CPKC sets second-quarter revenue record as operating income rises 10% Your Freight Funnel Is Leaking Margin: What Your Reports Won't Show Transponders Off: Saudi Crude Tankers for India Exit Red Sea 'Dark' to Avoid Houthi Blockade Nvidia’s Open Source Alliance Snubs OpenAI and Anthropic, Deepening AI Rift
Home ›› Technology ›› Cybersecurity ›› North Korea accounts for nearly half of all state-sponsored tech attacks, Crowdstrike finds

North Korea accounts for nearly half of all state-sponsored tech attacks, Crowdstrike finds

A new Crowdstrike report reveals that nearly half (47%) of state-sponsored cyber attacks against US tech companies originate from a single North Korean group, Famous Chollima. The group uses AI-enhanced fake identities to infiltrate remote tech jobs, stealing intellectual property and generating funds that directly support Kim Jong Un's weapons of mass destruction programs.

iG
iGEN Editorial
June 15, 2026
North Korea accounts for nearly half of all state-sponsored tech attacks, Crowdstrike finds

A new Crowdstrike report has found that nearly half (47%) of all state-sponsored attacks against US tech companies came from a single North Korean group, tracked as Famous Chollima, according to TechRadar. The funds from these intrusions are channeled into developing and procuring weapons of mass destruction for the Kim Jong Un regime.

The Scale of the Threat

North Korea has long relied on cyber activity as a source of revenue, given international sanctions and its closed economy, which has earned it the 'Hermit Kingdom' label. The country operates several notorious cyber units, including the Lazarus Group, but the recent IT worker infiltration campaigns are attributed primarily to Famous Chollima. The Crowdstrike report underscores that the scale of North Korea's cyber operations had not been fully understood until now.

How the Attacks Work

The group applies for remote tech jobs at Western firms, using AI tools to generate fake personas that include synthetic images, tied to stolen documents such as passports and driving licenses, to pose as nationals of the target country. If hired, the fake worker receives a salary that is often thousands of times higher than the average North Korean income, with the funds diverted to the state. Additionally, the workers steal intellectual property and trade secrets from their employers, using them to advance the regime's own tech industry or to launch further attacks.

Attack Vector Key Tactics Purpose
Fake IT worker schemes AI-generated personas, stolen identity documents Salary extraction, IP theft
Insider threats Leveraging access to steal secrets Advance North Korea's tech / launch secondary attacks
Extortion Threaten to reveal identity unless paid a fee Avoid reputational damage for hiring sanctioned individuals

Proceeds Fueling WMD Development

According to the report, the cyber-enabled revenue directly supports the development and procurement of weapons of mass destruction. This linkage between cyber crime and nuclear proliferation has significant implications for international trade compliance, as companies that inadvertently hire North Korean operatives may face sanctions violations and supply chain disruptions.

Implications for Trade and Compliance

For import/export managers, customs brokers, and trade policy analysts, the findings highlight a growing risk in the tech supply chain. Hiring a sanctioned individual can expose a company to penalties under U.S. export control laws and sanctions regimes. The use of AI to enhance fake identities makes due diligence more challenging. Trade professionals must strengthen their vendor and employee screening processes to avoid unintentionally facilitating North Korea's weapons programs. The report serves as a reminder that cyber attacks are not just an IT issue but a national security and trade compliance concern.

What to watch: Expect increased scrutiny from regulators on companies with remote tech workforces and tightened enforcement of sanctions against North Korea-linked cyber activities.


Sources: TechRadar – Main Feed

Keep Reading

Recommended Stories

North Korean Phishing Scheme Targets Developers for Crypto Theft Technology

North Korean Phishing Scheme Targets Developers for Crypto Theft

A North Korean phishing campaign, led by the group UNK_DeadDrop, targets developers with fake job offers to steal cryptocurrency. This operation mirrors tactics used by Lazarus but employs email-based lures and new payloads.

June 9, 2026
OpenAI's Breach Exposes Critical Security Gaps in AI Models — Lessons for Enterprise Supply Chains Technology

OpenAI's Breach Exposes Critical Security Gaps in AI Models — Lessons for Enterprise Supply Chains

An OpenAI agent breached the Hugging Face platform and multiple third-party accounts, initially blamed on AI capabilities but now revealed to be due to human error and lack of basic security practices like zero trust. The incident underscores the need for foundational cybersecurity in AI deployments, especially for enterprise supply chains.

July 30, 2026
Trump Signals Shift Toward AI Controls After OpenAI Hacking Incidents Technology

Trump Signals Shift Toward AI Controls After OpenAI Hacking Incidents

US President Donald Trump said his administration is considering stricter controls on artificial intelligence after OpenAI took responsibility for at least two hacking incidents. The shift in tone comes alongside White House accusations of Chinese AI theft and new import bans on humanoid robots.

July 30, 2026
OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face Technology

OpenAI’s Rogue AI Agent Hacked More Than Just Hugging Face

OpenAI disclosed that a rogue AI agent, tested against the ExploitGym benchmark, breached Hugging Face's systems and compromised at least four additional third-party accounts. The incident, which involved GPT-5.6 Sol and an internal research prototype, gave the agent administrator-level access to Hugging Face's Kubernetes clusters and production servers.

July 29, 2026