ctipilot.ch

Digitaal Vlaanderen compromise disclosed in the Stykas North Korea victim-set research

incident · incident:nk-contagious-interview-flemish-government-2026-08

Researcher Vangelis Stykas disclosed at Black Hat USA on 2026-08-05, from nearly two years of maintained access to North Korean actors' servers, that 1,640 organisations across 57 countries were impacted, 700 to 800 of them with intrusions he describes as really damaging. Digitaal Vlaanderen, part of the Flemish Government in Belgium, confirmed to WIRED that Belgium's Centre for Cybersecurity notified it on 2026-03-03, that the affected workstation was isolated and exposed credentials rotated, and that the incident is contained and remediated. Compromised external contractors holding access to many organisations at once — up to 30 in cases Stykas observed — were the principal blast-radius multiplier.

Coverage timeline
1
first 2026-08-08 → last 2026-08-08
Peak priority
high
1 high
Sources cited
2
2 hosts
Sections touched
1
active-threats
Co-occurring entities
1
see Related entities below
ATT&CK techniques
4
pinned v19.1 · see below

ATT&CK techniques

4 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-08/dprk-contagious-interview-blast-radius-flemish-government · ATT&CK page ↗

T1199Trusted Relationship×1

Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network.

Evidence: 2026-08-08/dprk-contagious-interview-blast-radius-flemish-government · ATT&CK page ↗

T1566Phishing×1

Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be targeted, known as spearphishing. In spearphishing, a specific individual, company, or industry will be targeted by the adversary. More generally, adversaries can conduct non-targeted phishing, such as in mass malware spam campaigns.

Evidence: 2026-08-08/dprk-contagious-interview-blast-radius-flemish-government · ATT&CK page ↗

Execution TA0002

T1204.002User Execution: Malicious File×1

An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from Spearphishing Attachment. Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, .reg, and .iso.

Evidence: 2026-08-08/dprk-contagious-interview-blast-radius-flemish-government · ATT&CK page ↗

Persistence TA0003

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-08/dprk-contagious-interview-blast-radius-flemish-government · ATT&CK page ↗

Privilege Escalation TA0004

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-08/dprk-contagious-interview-blast-radius-flemish-government · ATT&CK page ↗

Stealth TA0005

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-08-08/dprk-contagious-interview-blast-radius-flemish-government · ATT&CK page ↗

Story timeline

  1. 2026-08-08A Flemish Government agency confirms a DPRK compromise reached it through a contractor's workstation — one of 1,640 organisations a researcher counted from inside the actors' own servers
    active-threatsTwo years inside North Korean C2 infrastructure produces a victim count, an EU government confirmation, and a contractor with access to 30 companies

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

related to

Where this entity is cited

  • active-threats1

Source distribution

  • databreaches.net1 (50%)
  • wired.com1 (50%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Digitaal Vlaanderen compromise disclosed in the Stykas North Korea victim-set research (1)

2026-08-08 · view entry permalink →

HIGHNATOB2

A Flemish Government agency confirms a DPRK compromise reached it through a contractor's workstation — one of 1,640 organisations a researcher counted from inside the actors' own servers

The interesting number in this disclosure is not the victim count. Researcher Vangelis Stykas told Black Hat USA on 2026-08-05 that nearly two years of maintained access to North Korean actors' servers — in some cases reaching the operators' own infected workstations — let him identify "1,640 companies across 57 countries" affected by the country's operations, with around 700 to 800 of them suffering intrusions he describes as "really damaging": company access, root access to servers, root access to AWS (WIRED, 2026-08-05).

The number that changes a defender's model is 30. For many of the impacted organisations, Stykas says, compromised external contractors — who often held developer keys or access to multiple systems — vastly increased the blast radius of a single successful attack: "I have seen a couple of contractors that had access to up to 30 companies" (WIRED, 2026-08-05). The initial access is the long-documented one: developers lured with fake job offers at high salaries and asked to download a program as a coding test, which silently installs malware — the technique Microsoft tracks as the Contagious Interview campaign, running since as early as 2022 (WIRED, 2026-08-05).

One European government body is named and has confirmed. A spokesperson for the Flemish government told WIRED: "We can confirm that we were notified of this incident on March 3, 2026 by the Centre for Cybersecurity Belgium (CCB), following the researcher's disclosure," adding that the affected workstation was isolated, potentially exposed credentials and access were revoked and rotated, and that on its investigation the incident has been contained and remediated (WIRED, 2026-08-05). Japan's CERT says it confirmed the researcher's findings and worked with AEON Smart Technology on remediation. Boston Children's Hospital, also named, says the incident involved a former contractor's personal device rather than its own systems (DataBreaches.net, 2026-08-07). Other named organisations did not respond to WIRED. Stykas attributes broadly to North Korean operations and names no tracked cluster.

Triage: this campaign's initial access looks like ordinary developer behaviour by design — an engineer running an unfamiliar project as part of a hiring process is a developer running an unfamiliar project. The discriminator available in telemetry is not the execution itself but its provenance and timing: a build or interpreter chain originating from a freshly cloned repository or a downloaded archive that no ticket, project or repository in the organisation accounts for, on an endpoint belonging to someone who is not being onboarded to that work.

1,640 companies across 57 countries

WIRED 2026-08-05

We can confirm that we were notified of this incident on March 3, 2026 by the Centre for Cybersecurity Belgium (CCB), following the researcher’s disclosure,

WIRED (spokesperson for the Flemish government)

I have seen a couple of contractors that had access to up to 30 companies,

WIRED (Vangelis Stykas)
incident08 Aug 04:57Zmulti-sourceOpen finding ↗