UN Investigating 35 North Korean Military-Funding Cyberattacks

A more detailed U.N. report says North Korea is attacking banks via the SWIFT network, hacking crypto exchanges and cryptojacking.

AccessTimeIconAug 13, 2019 at 9:15 a.m. UTC
Updated Sep 13, 2021 at 11:19 a.m. UTC
10 Years of Decentralizing the Future
May 29-31, 2024 - Austin, TexasThe biggest and most established global hub for everything crypto, blockchain and Web3.Register Now

After a U.N. report recently accused the North Korean regime of carrying out major cyberattacks of banks and crypto exchanges to fund its weapons of mass destruction programs, a longer version of the report has set out the claims in new detail.

As reported on Aug. 6, the earlier confidential U.N. report seen by Reuters – researched by “independent experts” and presented to the U.N. Security Council North Korea sanctions committee – suggests that North Korea has used “widespread and increasingly sophisticated” hacks to collect roughly $2 billion.

The new lengthier version of the report, seen by Associated Press, sets out that North Korea may have carried out at least 35 hacks in 17 countries and that the U.S. experts are investigating.

The UN says that South Korea bore the brunt of the efforts, having suffered 10 attacks. The nation's Bithumb cryptocurrency exchange is said to have been hacked at least four times.

India came next with three cyberattacks, while Bangladesh and Chile each had two attacks. Thirteen nations suffered one attack each, listed in the report as: Costa Rica, Gambia, Guatemala, Kuwait, Liberia, Malaysia, Malta, Nigeria, Poland, Slovenia, South Africa, Tunisia and Vietnam.

The report further describes North Korea's modus operandi, saying that the nation employs three "low risk and high yield" methods to grab illicit gains.

As well as targeting crypto exchanges and users, North Korea's hacking experts also carry out attacks through the SWIFT bank messaging network, “with bank employee computers and infrastructure accessed to send fraudulent messages and destroy evidence.”

In one attack, the hackers managed to take over the ATM network for an entire nation and force 10,000 payments to alleged North Korean operatives.

North Korea is also said to be mining cryptocurrency via illicit cryptojacking malware to fund a "professional branch of the military.”

North Korea military parade image via Shutterstock

Disclosure

Please note that our privacy policy, terms of use, cookies, and do not sell my personal information has been updated.

CoinDesk is an award-winning media outlet that covers the cryptocurrency industry. Its journalists abide by a strict set of editorial policies. In November 2023, CoinDesk was acquired by the Bullish group, owner of Bullish, a regulated, digital assets exchange. The Bullish group is majority-owned by Block.one; both companies have interests in a variety of blockchain and digital asset businesses and significant holdings of digital assets, including bitcoin. CoinDesk operates as an independent subsidiary with an editorial committee to protect journalistic independence. CoinDesk offers all employees above a certain salary threshold, including journalists, stock options in the Bullish group as part of their compensation.


Learn more about Consensus 2024, CoinDesk's longest-running and most influential event that brings together all sides of crypto, blockchain and Web3. Head to consensus.coindesk.com to register and buy your pass now.