North Korea Arrests Former Military Hackers Accused of Targeting State Banks
Key Takeaways
- •Daily NK reported that North Korean authorities arrested former military hackers accused of breaching the Foreign Trade Bank and Chosun Central Bank.
- •The suspects were allegedly caught during a July 12 raid while laundering hundreds of millions of dollars through cryptocurrency channels.
- •Authorities reportedly treated the case as both a financial breach and an internal-security matter after finding suspicious transfer approvals, foreign IP addresses and unauthorized communications.
- •The alleged network used cryptocurrency wallets, Chinese exchange brokers, border-city intermediaries and covert communications tools to move and convert funds.
- •The report is notable because North Korea is more often identified as a source of major cryptocurrency theft rather than as a victim of such activity.

North Korea has arrested a group of former military hackers accused of breaching two of the country’s own state banks and laundering the stolen funds through cryptocurrency, according to a Daily NK report. The claim could not be independently verified.
The arrests reportedly took place on the night of July 12, when officers from the National Intelligence Agency raided a safe house in the capital. According to the source cited in the report, the officers found the suspects at their computers while they were in the process of laundering hundreds of millions of dollars. Authorities confiscated disposable cellphones and other equipment said to be worth hundreds of thousands of dollars.
Following the raid, armed officers isolated the headquarters of the Foreign Trade Bank and the computer center of the Chosun Central Bank, the state bank responsible for issuing North Korea’s local currency. The move blocked outside access to the facilities. The source also said vehicles equipped to detect mobile phone signals searched Pyongyang for unauthorized radio signals.
The report said the arrests were connected to the discovery of irregularities in foreign-currency transfer approvals and suspicious foreign IP addresses. The focus on bank approvals, external network access and unauthorized communications indicates that authorities treated the case as both a financial breach and an internal-security matter, according to the details described in the report.
Former cyber personnel accused of using state tools against the system
According to the source, officials were especially alarmed because the alleged ringleaders were discharged personnel from a cyber unit of the Reconnaissance and Intelligence General Bureau, North Korea’s military intelligence agency. The individuals had reportedly taken part in overseas operations before leaving the unit.
After being discharged, the former cyber personnel allegedly recruited young technical specialists from Kim Chaek University of Technology and Pyongyang University of Science. Together, they formed a clandestine network intended to siphon funds without the knowledge of the state security apparatus, the report said.
The source said the motive was personal gain rather than political or ideological opposition. That detail made the case unusual because it allegedly involved North Korea’s own cyber capabilities being turned against its domestic financial system. If confirmed, the case would add a rare internal dimension to the country’s better-known cyber operations: personnel trained for overseas activity allegedly using similar technical and laundering methods outside official control. One official was quoted as saying that, beyond standard disciplinary measures, the families of those involved would have to live in permanent fear because the punishment “will be hard for the entire family line to survive.”
The alleged method resembled the way state-sponsored hackers are often reported to launder cryptocurrency proceeds through China. The network transferred foreign currency and funds belonging to state trading companies in small batches from internal bank accounts to cryptocurrency wallets overseas, according to the report.
The digital assets were then exchanged for Chinese yuan and U.S. dollars through cryptocurrency exchange brokers in China. Physical cash transfers were carried out through local intermediaries in the border cities of Sinuiju in North Pyongan province and Hyesan in Ryanggang province. The participants allegedly used encrypted messengers, unregistered mobile phones and Chinese-made satellite communication devices to conceal their identities.
North Korea reported as both perpetrator and victim
The reported incident is notable because North Korea is more commonly described as the perpetrator in cryptocurrency theft and laundering cases. According to TRM Labs data, state-sponsored hackers accounted for 76% of all value stolen in crypto heists through April 2026, or roughly $577 million. Most of that total came from two operations: a $285 million exploit on April 1 and a $292 million exploit involving KelpDAO on April 18.
TRM has put the regime’s cumulative cryptocurrency theft at more than $6 billion, including funds withdrawn from the compromised Drift Protocol smart contract, and about $6 billion in total since 2017. Blockchain intelligence company Chainalysis has also said North Korean hackers stole a record $2 billion in cryptocurrency during the past fiscal year.
A multinational coalition monitoring sanctions against North Korea concluded that Chinese over-the-counter currency dealers played a crucial role in converting cryptocurrency proceeds from North Korean hackers into cash. The alleged criminal scheme described in the latest report suggests a similar use of Chinese intermediaries, which is why the reported involvement of brokers, border-city cash transfers and communications equipment is central to understanding the case.