TL;DR
- Elite North Korean hackers, former members of a state cyberwarfare unit, were arrested on July 12 after stealing funds from the regime itself.
- The hacking group infiltrated the Chosun Central Bank and the Foreign Trade Bank, converting state funds into cryptocurrencies to launder them through brokers in China.
- The National Intelligence Agency traced the encrypted transactions to a safe house in Pyongyang and arrested those involved while the operation was still underway.
The regime of North Korea, internationally known for sponsoring massive cryptocurrency thefts, now faces an unprecedented paradox: Hackers trained by the State itself were arrested on July 12, accused of stealing and laundering funds from the country’s most sensitive financial institutions. The information comes from a report published by Daily NK, citing an anonymous source inside Pyongyang.
According to the report, the attackers infiltrated the internal networks of the Chosun Central Bank, responsible for currency issuance and state fund management, and of the Foreign Trade Bank, in charge of external payments and foreign currency transactions. Once inside, they split the funds into small transfers to evade detection tools and routed them to cryptocurrency wallets abroad. Brokers in China converted the coins into cash, while contacts in border areas exchanged those assets for US dollars and Chinese yuan.
Hackers Who Stole from Their Own Regime
The ringleaders of the group were veteran hackers discharged from a cyber operations unit under the orbit of the General Reconnaissance Bureau, the country’s main military intelligence agency. After leaving active service, they recruited young prodigies from Kim Chaek University of Technology and Pyongyang University of Science and Technology. To operate undetected, they used specialized wireless equipment of Chinese manufacture and encrypted messaging applications.
The internal investigation was triggered when regime officials began detecting small discrepancies in external payment records and suspicious accesses from foreign IPs. The National Intelligence Agency traced the encrypted transaction traffic to a safe house in Pyongyang. On the night of July 12, agents raided the location and arrested the hackers involved while they were operating in front of their computers. Computer equipment valued at hundreds of thousands of dollars and disposable phones used to evade state monitoring were also confiscated.
Severe Penalties That Could Reach Entire Families
The case caused shockwaves among the military and academic elites of the capital. According to the source, regime officials anticipate severe punishments for the detained hackers, whose consequences could extend to their entire families. North Korea, which organizations such as the UN and the US Department of the Treasury identify as one of the most active state actors in the theft of crypto assets — including attacks attributed to the Lazarus Group against platforms such as Ronin Bridge, WazirX, and DMM Bitcoin — now faces the irony of having fallen victim to the same capabilities the regime cultivated for decades.







