North Korea has arrested a group of its own former military cyber operatives and elite IT specialists for hacking two of the country's most sensitive state banks and laundering the stolen funds through cryptocurrency.
According to reports, the arrests place when North Korea's National Intelligence Agency, the successor to the Ministry of State Security, raided a safe house in Pyongyang and reportedly caught the suspects in the act of laundering funds at their computers.
The targets were the Chosun Central Bank, which oversees currency issuance and the management of state funds, and the Foreign Trade Bank, which handles foreign payments, international settlements, and foreign-currency transactions.
The ringleaders were discharged veterans of a cyber operations unit under the Reconnaissance and Intelligence General Bureau, the modern successor to the Reconnaissance General Bureau, North Korea’s military intelligence agency long associated with state-sponsored hacking and cryptocurrency theft.
After leaving the military, these veterans recruited young IT talents from elite institutions including Kim Chaek University of Technology and Pyongyang University of Science and Technology.
According to reports, the group used advanced hacking skills developed during military service and university training to breach the tightly controlled internal networks and foreign-payment systems of both banks.
They diverted portions of state trade funds and foreign currency held in shell accounts, deliberately splitting the stolen amounts into very small increments to avoid triggering internal alerts.
The money was then moved into overseas cryptocurrency wallets.
Chinese brokers converted the crypto into U.S. dollars and Chinese yuan in near real time, while border networks in Sinuiju in North Pyongan Province and Hyesan in Ryanggang Province facilitated the cash-out or smuggling of the fiat currency.
To stay hidden, the group relied on Chinese-made specialized wireless equipment, encrypted messaging apps, and unregistered burner phones, and tools commonly used inside North Korea to evade state surveillance.
Officials first noticed small but repeated discrepancies in foreign-currency payment approvals and also flagged suspicious overseas IP access records linked to the banks’ systems.
The National Intelligence Agency opened a covert internal investigation and eventually traced encrypted cryptocurrency transaction traffic back to the Pyongyang safe house.
The night raid followed.
Authorities seized high-end computer equipment valued in the hundreds of thousands of dollars along with the group’s unregistered phones. In the immediate aftermath, armed agents sealed off access to the Foreign Trade Bank headquarters and the Central Bank’s computing center, while mobile signal-detection vehicles swept the capital.
The case has reportedly caused significant shock among Pyongyang’s elite, military circles, and university communities.
One official was quoted via the source as saying the suspects "used the skills the state trained them with to defend the country, and instead robbed the country’s coffers."
Harsh punishment is expected, potentially extending to entire family lines under North Korea’s long-standing guilt-by-association system known as yeonjwaje. Senior figures in the Reconnaissance and Intelligence General Bureau and in the science and technology education sector are said to be nervous that blame could spread upward.
This incident is striking precisely because of North Korea's well-documented record as one of the world's most aggressive state-linked cyber actors.
Despite most of its citizens lack internet access, the Hermit Kingdom is one of the places where hackers thrive. North Korea operates massive state-backed cyber units like the Lazarus Group despite domestic internet bans.
Elite hackers bypass isolation by working from overseas or specialized state compounds, stealing billions in cryptocurrency to fund the regime.
Groups tied to the same intelligence structures, like the Lazarus Group and related units, have stolen billions of dollars in cryptocurrency from exchanges and protocols worldwide over the past decade, witj money widely believed to help fund the regime under international sanctions.
Reports suggest roughly two billion dollars stolen by North Korean-linked actors in the previous year, and other trackers have attributed a very high percentage of recent crypto hacks and scams to them.
In this case, the same skill set and tools that the regime cultivates for external theft were turned inward against the state’s own financial arteries.
















































































































































































































































































































































































