2026-08-08 · view entry permalink →
A Flemish Government agency confirms a DPRK compromise reached it through a contractor's workstation — one of 1,640 organisations a researcher counted from inside the actors' own servers
The interesting number in this disclosure is not the victim count. Researcher Vangelis Stykas told Black Hat USA on 2026-08-05 that nearly two years of maintained access to North Korean actors' servers — in some cases reaching the operators' own infected workstations — let him identify "1,640 companies across 57 countries" affected by the country's operations, with around 700 to 800 of them suffering intrusions he describes as "really damaging": company access, root access to servers, root access to AWS (WIRED, 2026-08-05).
The number that changes a defender's model is 30. For many of the impacted organisations, Stykas says, compromised external contractors — who often held developer keys or access to multiple systems — vastly increased the blast radius of a single successful attack: "I have seen a couple of contractors that had access to up to 30 companies" (WIRED, 2026-08-05). The initial access is the long-documented one: developers lured with fake job offers at high salaries and asked to download a program as a coding test, which silently installs malware — the technique Microsoft tracks as the Contagious Interview campaign, running since as early as 2022 (WIRED, 2026-08-05).
One European government body is named and has confirmed. A spokesperson for the Flemish government told WIRED: "We can confirm that we were notified of this incident on March 3, 2026 by the Centre for Cybersecurity Belgium (CCB), following the researcher's disclosure," adding that the affected workstation was isolated, potentially exposed credentials and access were revoked and rotated, and that on its investigation the incident has been contained and remediated (WIRED, 2026-08-05). Japan's CERT says it confirmed the researcher's findings and worked with AEON Smart Technology on remediation. Boston Children's Hospital, also named, says the incident involved a former contractor's personal device rather than its own systems (DataBreaches.net, 2026-08-07). Other named organisations did not respond to WIRED. Stykas attributes broadly to North Korean operations and names no tracked cluster.
Triage: this campaign's initial access looks like ordinary developer behaviour by design — an engineer running an unfamiliar project as part of a hiring process is a developer running an unfamiliar project. The discriminator available in telemetry is not the execution itself but its provenance and timing: a build or interpreter chain originating from a freshly cloned repository or a downloaded archive that no ticket, project or repository in the organisation accounts for, on an endpoint belonging to someone who is not being onboarded to that work.
1,640 companies across 57 countries
We can confirm that we were notified of this incident on March 3, 2026 by the Centre for Cybersecurity Belgium (CCB), following the researcher’s disclosure,
I have seen a couple of contractors that had access to up to 30 companies,