A security researcher said he infiltrated infrastructure used by North Korean hackers for 22 months and uncovered evidence tying the operation to 1,640 companies in 57 countries, with 700 to 800 organizations allegedly suffering serious intrusions. A WIRED report, cited in social media coverage, described the findings as showing that North Korean operators had breached hundreds of networks worldwide, while researcher Vangelis Stykas, CTO of Kumio, publicly identified roughly a dozen affected organizations.
Among those named was Boston Children’s Hospital, which disputed that its own systems were compromised. The hospital said the incident involved only a former contractor’s personal device rather than a breach of hospital systems. The reporting highlights both the scale of the alleged North Korean campaign and the uncertainty that can follow public attribution, as victim organizations challenge how exposure and impact are characterized.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
WIRED reported that security researchers exploited vulnerabilities in a child-focused GPS smartwatch to track and eavesdrop on a reporter in real time in New York. The demonstration highlighted surveillance and privacy risks in insecure GPS-enabled consumer devices for children.
Security researcher Vangelis Stykas publicly named Boston Children's Hospital as one of roughly a dozen organizations impacted by the North Korean hacking operation. This disclosure was reported as part of the broader reporting on the campaign.
A Wired article reported that a security professional hacked North Korean hackers and found they had breached hundreds of networks worldwide. The provided source material includes only the headline-level claim and no further verified incident details.
Reporting on Vangelis Stykas's Black Hat 2026 findings publicly identified additional affected organizations beyond Boston Children's, including AEON Smart Technology, Oppo, Coinbase, Uniswap Labs, Italy’s Consiglio Superiore della Magistratura, a subsidiary of Al Rajhi Bank, and Digitaal Vlaanderen. The disclosures expanded the list of known victims tied to the North Korean Contagious Interview operation.
Boston Children's Hospital disputed that its own systems were breached, saying the issue was limited to a former contractor's personal device. The statement challenged its characterization as a directly breached victim in the operation.
Vangelis Stykas said he spent 22 months inside systems used by a North Korean hacking group, where he gathered evidence about the scope of their operations. He said this access linked the operation to 1,640 companies in 57 countries and indicated 700 to 800 seriously damaging intrusions.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcemalware.news
Open sourcedatabreaches.net
Open sourcewired.com
Open sourcebsky.app
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.