North Korean hackers have now plundered $2 billion this year and an overall total of $6 billion in stolen crypto. The state-sponsored hacking teams have demonstrated creative means of penetrating crypto platforms and are responsible for at least 30 incidents in 2025, including a $1.46 billion theft from Bybit.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
North Korea's new record for stolen crypto, $1.34 billion, represents 61% of the total of about $2.2. billion stolen in 2024. Skilled state-backed North Korean hackers are almost single-handedly keeping numbers above the $1 billion level globally.
North Korean hackers intensify their efforts against blockchain and Web3 developers, using nearly 200 malicious npm packages in the ongoing Contagious Interview hacking campaign.
North Korean hackers are using ClickFix social engineering tactics to compromise devices and perform data exfiltration in a highly focused cyber espionage campaign.
Lazarus hacking group found to be developing capabilities in supply chain attacks and using the MATA framework to conduct cyber espionage on the defense industry.
Cyber attack on Norwegian media company Amedia halted the publication of printed newspapers and potentially compromised personal information of employees and subscribers.
The resources to get past traditional MFA solutions are now available to even the most rudimentary hackers, and many MFA platforms simply aren’t designed to keep up – with either hackers or evolving guidelines.
Genesis dark web market that is thought to have facilitated the sale of some 80 million credentials is now in the hands of law enforcement, after an international campaign that involved about 200 raids and 100 arrests.
Compromised data belonging to ten companies is on sale on the dark web by a hacking group called ShinyHunters. The 73 million stolen user records is being sold for $18,000.
Collaborative international law enforcement effort appears to have at least temporarily crippled the notorious REvil ransomware gang, taking the group's Tor sites and dark web infrastructure off the internet and putting it beyond reach.










