North Korean authorities have reportedly arrested a group of former state-trained cyber specialists accused of hacking two of the country’s most important banks and laundering stolen government funds through cryptocurrency.
The case is unusual because North Korea is widely accused of using cyber units to steal money from overseas banks and digital-asset businesses. This time, however, the alleged attackers are said to have turned the technical skills developed inside the state against North Korea’s own financial institutions.
The claims originate from a Daily NK investigation published on July 24, 2026. The report relies on an anonymous source in Pyongyang and has not been independently confirmed by North Korean state media or an outside government. Details should therefore be treated as credible allegations rather than established facts.
Hackers Allegedly Breached Two State Banks
According to Daily NK, the group penetrated the internal networks of the Chosun Central Bank and the Foreign Trade Bank.
The Chosun Central Bank manages functions associated with currency issuance and state funds. The Foreign Trade Bank handles international payments and foreign-currency transactions, making it particularly important to a country operating under extensive international sanctions.
The suspects allegedly diverted portions of state trade funds and foreign currency held in shell accounts. Instead of attempting one large transfer that might immediately attract attention, they reportedly divided the money into smaller amounts before sending it to cryptocurrency wallets outside North Korea.
No confirmed estimate of the total amount stolen has been released. The report also does not identify the cryptocurrencies involved, the exact banks or exchanges through which the assets moved, or the names of the detained suspects.
Former Cyber Operators Reportedly Led the Scheme
The alleged ringleaders were reportedly discharged members of a cyber operations unit connected to North Korea’s military intelligence apparatus.
Daily NK says the former operatives recruited talented technology specialists from Kim Chaek University of Technology and Pyongyang University of Science. Together, they allegedly created a private cryptocurrency trading and laundering network designed to operate outside official state control.
The suspects were not accused of defecting or working for a foreign intelligence agency. Their apparent objective was personal enrichment. They allegedly used training and technical capabilities originally provided by the government to steal from the same system they had previously served.
That distinction makes the case especially sensitive for Pyongyang. It suggests that highly trained personnel trusted with advanced cyber capabilities may be able to reuse those skills after leaving formal government service.
How the Alleged Crypto-Laundering Network Worked
The group reportedly used specialised Chinese-made wireless equipment and encrypted messaging applications to avoid North Korea’s tightly controlled communications systems.
After accessing the banks, the hackers allegedly moved small portions of the stolen funds into overseas cryptocurrency wallets. Brokers operating in China then converted the digital assets into conventional currency.
Contacts in North Korean border cities, including Sinuiju and Hyesan, reportedly helped exchange the laundered funds for US dollars and Chinese yuan. This would have created a chain connecting compromised bank accounts, overseas wallets, Chinese intermediaries and physical cash networks near the border.
The reported method resembles techniques used in international crypto-laundering operations. Funds are separated into smaller transactions, moved between addresses and sometimes exchanged across multiple assets or blockchains before being converted into cash.
The US Department of Justice has described similar methods in previous cases involving North Korean actors. Its 2025 forfeiture complaint involving North Korean IT workers identified tactics including false identities, small transfers, token swapping, movement between blockchains and the commingling of criminal proceeds.
Small Discrepancies Reportedly Exposed the Operation
The alleged scheme was not discovered through one dramatic missing payment. Officials reportedly began noticing small inconsistencies in foreign-currency approvals and suspicious overseas internet activity.
North Korea’s intelligence service then launched a covert investigation. Investigators reportedly traced encrypted cryptocurrency traffic to a safe house in Pyongyang and raided it on July 12.
Daily NK claims agents found members of the group operating computers and laundering funds at the location. Authorities reportedly seized expensive computing equipment and unregistered mobile phones intended to avoid government monitoring. Security personnel also restricted access around the two banks’ computer facilities while signal-detection vehicles searched for unusual wireless transmissions.
The report does not explain how investigators connected blockchain transactions to the suspects or whether cryptocurrency held in overseas wallets was recovered.
Why the Foreign Trade Bank Matters
The Foreign Trade Bank is North Korea’s primary institution for foreign exchange and international financial activity. It has also appeared repeatedly in US sanctions and criminal cases involving alleged money laundering.
In 2023, the US Justice Department charged a Foreign Trade Bank representative with participating in cryptocurrency-laundering conspiracies. Prosecutors alleged that stolen digital assets and money earned by North Korean IT workers were processed through over-the-counter traders and used to purchase goods for the country. Those allegations concerned separate international schemes and are unrelated to the newly reported internal bank theft.
The bank’s role makes a successful internal intrusion particularly serious. An attacker who gained access to its systems could potentially encounter sensitive information involving overseas payments, foreign-currency reserves, trading entities and sanctions-evasion networks.
The reported breach therefore represents more than ordinary theft. It would expose weaknesses in the financial infrastructure North Korea relies on to conduct external transactions under international restrictions.
North Korea Has Built a Powerful Cyber Apparatus
North Korea has spent years developing cyber units capable of espionage, sabotage and financially motivated attacks. The US Treasury has identified Lazarus Group, Bluenoroff and Andariel as state-controlled organisations connected to the country’s Reconnaissance General Bureau.
International investigations have linked North Korean actors to attacks on banks, cryptocurrency exchanges, blockchain bridges and technology companies. The hackers frequently combine technical compromises with social engineering, fraudulent employment and impersonation.
Chainalysis estimated that North Korea-linked hackers stole at least $2.02 billion in cryptocurrency during 2025, bringing the organisation’s lower-bound estimate of the country’s cumulative crypto theft to $6.75 billion. The company said North Korean operations increasingly relied on embedded IT workers, fake recruitment exercises and complex laundering services. Its complete findings appear in the 2026 Crypto Crime Report summary.
Elliptic separately estimated that North Korea-linked groups had stolen more than $2 billion in 2025 by early October. It cautioned that attribution is not exact and depends on blockchain analysis, laundering patterns and intelligence information.
The State’s Own Skills May Have Been Turned Against It
The reported arrests illustrate a long-term risk associated with building a large offensive cyber workforce. Personnel trained to penetrate secure networks, conceal communications and move digital funds do not lose those abilities when they leave government service.
North Korea’s restrictions on private business and foreign-currency activity may also encourage skilled individuals to create hidden commercial networks. Cryptocurrency can provide access to international value transfers without requiring direct participation in the conventional banking system.
Yet blockchain transactions are not automatically invisible. Most major public blockchains maintain permanent transaction histories. Investigators can analyse movements between addresses and identify connections with exchanges, bridges or brokers.
Elliptic notes that stolen digital assets leave traces that can be analysed even when criminals use several blockchains and laundering services. The difficulty is connecting those addresses to real people and intercepting the assets before they are converted into cash.
Harsh Punishment Is Expected
Daily NK’s source said the case has caused alarm among government officials, military personnel and university communities. Senior figures may fear that the investigation will extend to supervisors, educators or relatives associated with the suspects.
North Korea is known to impose severe penalties for crimes involving state property, unauthorised foreign-currency activity and contact with overseas networks. Daily NK reported that officials expect particularly harsh punishment because the defendants allegedly used government-funded training to steal directly from state institutions.
No official charges, trial dates or sentences have been announced publicly. The number of people detained also remains unclear.
The Most Important Questions Remain Unanswered
The report does not reveal how long the operation continued, how much money disappeared or whether insiders working inside the banks assisted the hackers. It is also unknown whether the funds belonged to ordinary state accounts, foreign-trade companies or more sensitive government programmes.
North Korean authorities have not publicly acknowledged the alleged intrusion. That silence is unsurprising because admitting that former government cyber specialists compromised the country’s central financial institutions could damage the regime’s image of total internal control.
The broader significance is difficult to ignore. North Korea has developed one of the world’s most capable financially motivated cyber operations, using digital theft to generate foreign currency and evade sanctions. The same knowledge may now have enabled insiders to target the government’s own money.
Until additional evidence emerges, the arrests should remain described as reported rather than confirmed. Even with that limitation, the case presents a striking reversal: specialists allegedly trained to steal cryptocurrency and financial assets for North Korea may have used those same capabilities to steal from North Korea itself.