Key Takeaways
- Pyongyang authorities detained former state-employed hackers for targeting domestic financial institutions
- The operatives allegedly breached the DPRK’s Central Bank and Foreign Trade Bank systems
- Diverted funds were transformed into cryptocurrency and processed through Chinese intermediaries
- The suspects employed fragmented transactions and secure communication tools to evade surveillance
- Detentions occurred on July 12 at a secure location in Pyongyang following detection of irregular activity
A group of former military cyber operatives and technology experts in North Korea have been detained on suspicion of embezzling government funds from two state-controlled financial institutions and converting the proceeds through digital currency channels.
The account emerged Thursday from Daily NK, a South Korean news organization, attributing the information to an undisclosed source based in Pyongyang. Independent confirmation of these allegations by Cointelegraph and similar media outlets has not been possible.
Based on available information, the operatives infiltrated internal networks belonging to the Central Bank of the Democratic People’s Republic of Korea and the Foreign Trade Bank. They redirected foreign currency reserves and state commercial funds into cryptocurrency accounts located outside the country.
The purported operation depended on collaborators stationed in Chinese cities near the border. Facilitators in Sinuiju and Hyesan allegedly exchanged the digital assets for U.S. dollars and Chinese yuan immediately upon receipt.
Detection avoidance measures included fragmenting transfers into minimal increments. The group also utilized encrypted communication platforms, unregistered mobile devices, and Chinese networking hardware.
Details of the Detention Operation
North Korea’s National Intelligence Agency apprehended the individuals on July 12 at a clandestine residence in Pyongyang. Authorities indicated they identified irregularities in foreign currency transaction authorizations and traced questionable overseas internet protocol addresses.
Should these reports prove accurate, they would represent an unusual instance of North Korean cyber personnel targeting domestic government infrastructure instead of international entities.
The DPRK has established a reputation for deploying government-sponsored hacking teams against foreign cryptocurrency platforms. These operations generate revenue streams and circumvent economic sanctions imposed by the international community.
Pyongyang’s History of Digital Currency Theft
The money laundering techniques outlined in the Daily NK account resemble strategies employed by confirmed North Korean cyber units conducting overseas operations.
Previous multinational sanctions oversight documentation has identified Chinese peer-to-peer currency traders as critical participants in transforming stolen digital assets into traditional currency for Pyongyang-affiliated operatives.
According to blockchain intelligence company Chainalysis, North Korean hackers extracted an unprecedented $2 billion in cryptocurrency during 2025.
TRM Labs calculated that entities linked to North Korea accounted for 76% of total cryptocurrency theft and fraud losses extending through April 2026.
Daily NK operates from Seoul and maintains a network of informants within North Korean territory. Verification of reporting from the isolated nation remains challenging due to severe limitations on access and information distribution.
No official governmental or international organization has corroborated the account at the time of this publication.


