LogoLogo

Podcasts

Newsletters

Videos

Catalog

People

About

Search

Seriously Risky Business Newsletter

August 06, 2026

Srsly Risky Biz: Being a North Korean Hacker Is About to Be Less Fun

Written by

Tom Uren
Tom Uren

Policy & Intelligence

Your weekly dose of Seriously Risky Business news is written by Tom Uren and edited by Patrick Gray and Amberleigh Jack. This week's edition is sponsored by Permiso Security.

You can hear a podcast discussion of this newsletter by searching for "Risky Business News" in your podcatcher or subscribing via this RSS feed.

Srsly Risky Biz: Being a North Korean Hacker Is About to Be Less Fun

Photo by Steve Barker on Unsplash

North Korea will have to rein in its pet hackers after seemingly losing control over them. 

Last week we covered the news that a group of former North Korean military intelligence operatives had been caught hacking into the country's banks to steal funds for their personal benefit. 

Daily NK reports Pyongyang's elite are shocked at "the scale and audacity of the scheme". Punishment for those involved will reportedly be extreme, with one official saying "It will be hard for the entire family line to survive". Grim.

The outlet also says officials in North Korea's Reconnaissance General Bureau, the organisation responsible for cyber espionage, are worried that the scandal could even roll uphill and claim their scalps.

We expect, therefore, that this incident will result in some substantial tightening of operational controls.

North Korea's state-sanctioned cyber crime operations can be lumped into three buckets: high-value targeted cryptocurrency hacks, broad-based fraudulent worker scheme, and ransomware extortion operations.

There is some evidence that in addition to former operatives stealing from North Korean banks, the government there is also losing control over its ransomware operators.

North Korea first dipped its toe into ransomware by developing its own strains. In 2021 and 2022 one of its hacker groups, Andariel, created two different ransomware strains that it used on organisations in the US, South Korea and Japan, including against the American health sector. 

After dabbling in roll-your-own ransomware, in recent years North Korean hackers began collaborating with the ransomware-as-a-service (RaaS) ecosystem. Threat intelligence reports say that Andariel used Play ransomware in 2024 and Medusa ransomware in 2025. 

Last week, South Korean security firm AnhLab reported that a state-controlled North Korean hacker group is also collaborating with Gunra ransomware. It's unclear whether this collaboration is state sanctioned or not.

North Korean cyber units are supposed to funnel stolen funds into the state's coffers. By design, however, RaaS offerings help skilled individuals profit from their hacks. 

Given the recent hack of the country’s banks, and this news of DPRK operators getting cozy with criminal outfits, we suspect that RGB officials might start to look at RaaS operations a bit differently. If you're personally on the hook for extreme punishments if your underlings go rogue, why put them in a position where they're tempted to put their hands in the cookie jar?

So what's next for North Korean state-sponsored hacks? Scaling back its ransomware operations is one possibility, but it is not the only option. We suspect a strong tightening of controls on its hacking teams in general is more likely.

There is good evidence that North Korea uses very tight internal controls on its scam IT workers already. North Korean defectors have described constant surveillance and screen monitoring, isolation, movement restrictions and strict work quotas. 

It doesn't appear that the same level of control is currently applied to the country's hackers. A 2014 report says they were viewed as the elite of the military. Rather than being intensively surveilled, they had privilege and more freedom. 

That's almost certainly a thing of the past. Being a state-backed DPRK hacker is about to be a lot less fun.

Cyber War Is Here, and America Is Politically Unprepared

Multiple cyber provocations targeting America's water sector have revealed how unprepared the US is to deal with the political fallout of cyber attacks against critical infrastructure.

The Washington Post reported US intelligence agencies have determined that Iran is behind the attacks on water facilities in Minnesota that we covered last week. Now, at least a dozen states have experienced similar disruptions. Per Risky Bulletin:

Some of the new public incidents have been reported in Clayton County, Georgia and the city of Duchesne, Utah. Customers were left low pressure or no water in Clayton County in the middle of the night last week. In Utah, the cyberattack made pumps run dry while their control panels said they were pumping water. The incident impacted an oilfield wastewater disposal site but did not cause any environmental damage. 

A CISA advisory about the escalating activity says that it has "resulted in boil water notices" and led to "sustained manual operations".

This campaign is historically significant. As far as we know, it is the first time a country has responded to kinetic attacks in the cyber domain by targeting an aggressor's critical infrastructure. 

The direct impact of the hacks on water supply have been manageable so far, which is consistent with what we've seen in other conflicts over the last several years. 

The effects of wartime cyber attacks are relatively short-lived and they have been most useful when combined with tightly orchestrated conventional operations, such as America's 2025 strikes against Iranian nuclear facilities or its capture of Venezuelan President Nicolas Maduro. Without complementary conventional action, Iran's attacks on America's water systems don't amount to much. 

Having said that, the strategic goal of the campaign is to erode political support for the war. In our view, widespread publicity without accompanying devastation is the perfect way to achieve that goal.

This campaign was entirely predictable. As we've written before, if you bomb Iran, you should expect cyber operations against critical infrastructure in return. Even as far back as 2013 Iranian hackers compromised control systems at a New York state dam and tried to affect its operation. 

We're only surprised that this current campaign took so long to spin up. 

The US government's response has so far been fairly muted. CISA has advised organisations to remove targeted devices from the internet and to connect to them using VPNs or gateway devices, to enable passwords and use strong ones, and allowlist IP addresses for remote access.

Since it was pretty clear that Iran would respond to missiles with cyber, we think running a campaign to fix these vulnerabilities before military action against Iran would have left the US government in a much better place to deal with this campaign.

It's true that a preparatory cyber security drive like this wouldn't have made America's water infrastructure perfectly secure. It's too big, too decentralised and too resource constrained. It could, however, have made a political difference. "We understand the problem, we've been putting mitigations in place, some systems remain vulnerable but we can assure everyone the impacts will be limited". In other words: We've got this under control.

As it stands, despite the campaign's predictability, the Trump administration is on the back foot. President Donald Trump even blamed Minnesota and its officials for the attacks. 

That's some pretty bonkers politics, and exactly the sort of sound byte Iran will chalk up in the "win" column.

Watch James Wilson and Tom Uren discuss this edition of the newsletter:

Three Reasons to Be Cheerful This Week:

  1. Chrome in the AI era: Google's Chrome team has described how they are using AI to make the browser safer by improving vulnerability discovery and patching. The team uses AI agents coupled with harnesses to carry out find and fix vulnerabilities as well as to triage external bug reports. Google says that over the previous two stable releases it fixed 1072 security bugs. 
  2. OpenAI disrupts Cambodian scammers: OpenAI announced last week that it had disrupted a Cambodia-based scam operation that was using ChatGPT to support "investment, romance, gambling and impersonation schemes". The good news here is that a tip from WhatsApp led OpenAI to what it found to be a coordinated network of accounts. We are all in favour of more coordination to counter scam compounds.
  3. Romance scammer gets seven years: The US Department of Justice announced last week that Derrick Van Yeboah was sentenced to 85 months in prison for his role in romance and business email compromise scams. The Ghanaian was involved in a criminal organisation that stole and laundered more than USD$100 million from dozens of victims. The DoJ says Van Yeboah "personally perpetrated many of the romance scams by impersonating fake romantic partners" with victims. His victims transferred millions of dollars to the gang.   

Sponsor Section

In this Risky Business sponsor interview, James Wilson chats with Permiso CTO Ian Ahl about detecting ShinyHunters-style attackers as they move through cloud and SaaS environments.

Shorts

Frontier Lab Cybersecurity Testing Controls Are Rubbish

In recent weeks OpenAI and then Anthropic announced that their AI agents have, ahem, exceeded expectations in different testing scenarios. In both cases, AI models escaped notional testing sandboxes, and the companies detected the escapes days to weeks after the fact.  

By contrast, the UK's AI Security Institute (AISI) wrote this week: 

On 28th July 2026, AISI's Security Team detected unusual data transfers leaving our research systems during a routine cyber evaluation. On investigation, we found that some of the agents being tested had engaged in sustained, potentially harmful activity directed at real people and organisations. We declared a security incident and, within roughly one hour of discovery, had contained it and begun a full investigation. [emphasis added]

How refreshingly competent!

AISI's write up covers essentially the same type of behaviour as described by OpenAI and Anthropic, but it is far better. It states things plainly without guff and corpo-speak. 

Risky Biz Talks

You can find the audio edition of this newsletter and other fine podcasts and interviews in the Risky Biz News feed (RSS, iTunes or Spotify).  

In our last "Between Two Nerds" discussion Tom Uren and The Grugq talk about whether hacker culture is inherently anti-authoritarian and how different states get their country's hackers to work for them.

Or watch it on YouTube!

From Risky Bulletin:

Hacker breaches Hungary's State Treasury: The same hacker who hit and wiped Romania's land registry database has now hacked Hungary's State Treasury in another brazen intrusion into an extremely sensitive government system.

The incident took place last week and portions of the stolen data have since been put up for sale on an underground hacking forum.

The intrusion was confirmed to local journalists by Hungary's State Treasury over the weekend. 

[more on Risky Bulletin]

Russia is behind the recent hotel WiFi hacks: A Russian state-sponsored hacking group is behind a recent hacking wave that has targeted and compromised hotel WiFi gateways across the globe.

Microsoft says the campaign is far larger and more complex than it was initially covered in a ReliaQuest report two weeks ago.

ReliaQuest said the hackers were modifying DNS traffic on hotel networks to redirect users to Microsoft-themed phishing sites. Microsoft says the attacks also redirected users to malware downloads, often using ClickFix pages to trick users into downloading and running the payloads.

[more on Risky Bulletin]

Non-profit offers $22,000 bounty for INC ransomware group: An international crime-fighting non-profit organization is offering a $22,000 bounty for any information on members of the INC ransomware group.

To be eligible for a payout, the provided information must lead to the identification, arrest, or disruption of the gang's operations.

Crime Stoppers International is the international branch of Crime Stoppers, a US foundation that was established in the 70s to allow anonymous and private individuals to provide aid in US law enforcement investigations that may lack manpower or resources.

[more on Risky Bulletin]

Recent Newsletters

  • Srsly Risky Biz: Being a North Korean Hacker Is About to Be Less Fun
  • Risky Bulletin: Hacker breaches Hungary's State Treasury
  • Risky Bulletin: Russia is behind the recent hotel WiFi hacks
  • Risky Bulletin: Non-profit offers $22,000 bounty for INC ransomware group
  • Srsly Risky Biz: Chipping Away at Chinese AI Risks

Recent Videos

  • Between Two Nerds: Hackers vs the state
  • Srsly Risky Biz: Chipping away at Chinese AI risks
  • Risky Business (846): OpenAI built a fireplace out of wood
  • Between Two Nerds: Cyber is people
  • Srsly Risky Biz: Knives are out for open-weight AI models

Recent Podcasts

  • Srsly Risky Biz: Being a North Korean hacker is about to be less fun
  • Risky Business #847 -- Oops! Claude's accidental hacking spree
  • Risky Bulletin: Hacker breaches Hungary's State Treasury
  • Between Two Nerds: Hackers vs the state
  • Risky Bulletin: Anthropic models also did the hacky-hacky
Risky Business Media

Risky Business

  • Home
  • Podcasts
  • Newsletters
  • Video
  • Sitemap

Risky Business Media

  • About
  • People
  • Advertising
  • Sponsor Enquiries: sales@risky.biz

Risky Connections

  • Risky Business on Apple Podcasts
  • Risky Business on Spotify
  • Risky Bulletin on Apple Podcasts
  • Risky Bulletin on Spotify
  • Risky Business Features on Apple Podcasts
  • Risky Business Features on Spotify
  • Risky Business Stories on Apple Podcasts
  • Risky Business Stories on Spotify
  • YouTube
  • LinkedIn

Risky Contacts

Risky Business Media Pty Ltd
PO Box 774
Byron Bay NSW 2481
General Email: editorial@risky.biz

© Risky Business Media 2007–2026. All rights reserved.
ABN 73 618 465 517