TechNewsReel
Live

Researcher Infiltrates North Korean Hacking Infrastructure for 22 Months

Vangelis Stykas gained access to state-sponsored servers, revealing breaches of 1,640 companies worldwide.

TechNewsReel Newsroom · August 6, 2026

A Greece-based security researcher spent nearly two years inside the digital infrastructure used by North Korean hackers to launch global cyberattacks. Vangelis Stykas maintained unauthorized access to these systems for 22 months, providing a rare look into the operational scale of state-sponsored hacking.

During his infiltration, Stykas monitored the activities of North Korean operators and uncovered the extent of their reach. His research identified evidence that 1,640 companies across 57 different countries had been impacted by these hacking operations. The data suggests a systematic effort to breach a vast number of global networks, far exceeding the scope of many previously documented campaigns.

The Researcher's Background

Stykas is a security specialist based in Thessaloniki, Greece, with a professional focus on API and web application security, specifically regarding cloud back-ends for connected devices. In addition to his independent research, he serves as the cofounder and CTO of the security firm Kumio AI. His technical expertise in cloud infrastructure likely facilitated the long-term persistence required to remain undetected within the hostile environment of a state-sponsored hacking network.

Implications for Global Security

This infiltration matters because it exposes the true operational scale of North Korean cyber warfare. While intelligence agencies often report on high-profile thefts or political disruptions, Stykas's findings demonstrate a broader, more pervasive pattern of infiltration. The fact that over a thousand companies across dozens of nations were compromised indicates that North Korean operators are casting a wide net, likely seeking a variety of strategic, financial, or intelligence-gathering targets.

Future Outlook

The discovery highlights a critical vulnerability in how state-sponsored actors manage their own infrastructure, showing that even the attackers can be compromised. Security professionals will now be looking for further evidence of the specific vectors used to breach the 1,640 identified companies. As the full details of the monitored activity emerge, the industry will need to determine if these breaches were used for long-term espionage or immediate financial gain. This case serves as a reminder that the digital battleground is fluid, and the roles of hunter and hunted can shift rapidly when infrastructure is poorly secured.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.