
Security researcher Vangelis Stykas spent two years inside North Korean hackers' servers and uncovered hundreds of breached networks. A stark reminder of nation-state cyber threats.
In the high-stakes world of cybersecurity, the hunter sometimes becomes the hunted. Security researcher Vangelis Stykas accomplished something few have ever done: he turned the tables on North Korean hackers. For nearly two years, Stykas maintained covert access to servers used by these state-sponsored cybercriminals. During that time, he uncovered evidence of breaches spanning the globe — hundreds of networks compromised across multiple industries and nations.
The investigation, first reported by Wired, provides an unprecedented inside look at North Korea’s cyber operations. It also serves as an urgent wake-up call for security teams. If a single researcher can access threat actors’ infrastructure for two years, the scale of attacks they are conducting is likely far greater than most organizations assume.
North Korean hacking groups rank among the world’s most sophisticated state-sponsored cyber actors. They operate with impunity, supported by a government that relies heavily on cybercrime to generate revenue and gather intelligence.
What makes Stykas’s investigation unique is the viewpoint he achieved. By compromising the hackers’ own servers, he observed their tactics, techniques, and procedures from the inside. This kind of access is exceedingly rare. Most threat intelligence relies on external observation — analyzing malware, tracking command-and-control infrastructure, and correlating attack patterns. Stykas had a front-row seat.
When you observe threat actors on their own infrastructure, you gain insights external monitoring cannot provide. According to the Wired report, Stykas witnessed the full extent of their reach: networks breached across numerous sectors globally.
The intelligence gathered in such operations can:
This kind of access carries significant risk. Operating against state-sponsored groups demands meticulous operational security. One mistake could expose the researcher’s identity and compromise the entire investigation.
Maintaining covert access for nearly two years is extraordinary. It demands more than technical skill — it requires patience, discipline, and a deep understanding of the target’s routines.
Staying hidden inside an adversary’s infrastructure is a constant cat-and-mouse game. Researchers must blend in with normal activity, carefully manage credentials, and prioritize intelligence without tipping their hand. Every action leaves traces. The fact that Stykas sustained access for two years speaks both to his skill and to the hackers’ overconfidence in their own security.
The findings are sobering. From the vantage point of the compromised servers, Stykas documented activity indicating that North Korean hackers had breached hundreds of networks worldwide, according to Wired.
These are not merely low-value targets. The affected networks span multiple sectors, suggesting strategic and opportunistic targeting. Each compromised network represents potential access to more systems, more data, and more leverage.
Hundreds of breached networks is a staggering statistic. Most organizations assume they are too small to be targeted by nation-state actors. The reality is far more complex.
Famous North Korean cyber operations — the Sony Pictures hack of 2014, the WannaCry ransomware outbreak of 2017, the Bangladesh Bank heist of 2016 — dominate public attention. But these represent only the visible peaks of a much larger iceberg.
Behind the headlines, North Korean hacking groups engage in:
The breadth suggests a highly organized, well-resourced cyber program. It also suggests that many breached organizations may not even know they have been compromised.
Network breaches frequently lie dormant for months or years before discovery — if they are discovered at all. Attackers maintain persistent access for long-term intelligence collection or wait for the optimal moment to strike. For many victims, absence of evidence is not evidence of absence.
Security teams must adopt a proactive threat-hunting posture instead of waiting for alerts to trigger a response.
Understanding the motivations behind these attacks is essential for contextualizing the threat.
International sanctions have severely limited North Korea’s legitimate economic opportunities. Cybercrime offers a route around these restrictions. United Nations reports estimate North Korea has generated hundreds of millions of dollars through cyberattacks to fund weapons programs.
Cryptocurrency heists, bank fraud, and ransomware payments flow directly into regime coffers. The hundreds of breached networks likely serve this economic motive above all.
Beyond money, North Korean operations support broader strategic objectives:
Every breached network is a card held in reserve.
For security professionals, this investigation delivers two uncomfortable truths.
First, your threat model is broader than you think. If North Korean hackers have breached hundreds of networks worldwide, there is a real chance your organization — or a partner or vendor — has been affected. Supply chain attacks are a favored technique of state-sponsored actors. A smaller vendor with weak security can serve as a stepping stone to a larger enterprise.
Here are actionable measures your organization can take:
Most importantly, adopt a questioning posture. If your security team does not actively hunt for threats, you will not know what you have missed.
Stykas’s work raises critical questions about the future of cyber conflict. If one researcher can penetrate a nation-state’s hacking infrastructure for two years, what might espionage agencies be doing quietly in the background?
The decision to share these findings publicly is significant. Threat intelligence is most valuable when shared widely. Organizations can use this investigation to:
Public disclosure transforms a single researcher’s work into a global defensive asset.
The story of Vangelis Stykas and hundreds of breached networks is more than a fascinating investigation. It is a warning about the scale of the cyber threat facing organizations today.
North Korean hackers are not operating somewhere far away — they are operating inside networks like yours, possibly right now. The evidence is clear: hundreds of networks worldwide have been breached, and the full extent of the damage may not yet be known.
For security professionals, the message is straightforward: take nation-state threats seriously, invest in proactive defense, and never assume your organization is too small or too well-defended to be a target. The hunters are out there. Make sure you do not become their prey.
The exact method isn't publicly detailed, but Stykas compromised the hackers' own infrastructure to gain covert access. He then maintained that access for nearly two years, allowing him to observe their operations from the inside. His operation required meticulous security to avoid detection by a state-sponsored adversary.
He found evidence of hundreds of breached networks spanning the globe, affecting multiple industries and nations. He also gained visibility into the hackers' tactics, techniques, and procedures, including potential target lists, malware variants, and infrastructure not yet used in attacks. This provided an unprecedented look at the scale of North Korean cyber operations.
Most threat intelligence relies on external observation, like analyzing malware or tracking command-and-control servers. Stykas's inside access revealed the full reach of North Korean hackers from their own servers, offering insights that external monitoring cannot provide. It also serves as a stark reminder that state-sponsored cyber threats are far more extensive than many organizations assume.
They are state-sponsored cyber actors considered among the world's most sophisticated, and they operate with government support. Their activities include cybercrime to generate revenue and intelligence gathering for the North Korean state. They are known for operating with impunity and targeting organizations across many sectors globally.
Organizations should assume they could be targets and adopt a proactive security posture, including continuous monitoring, threat intelligence, and strong incident response plans. The investigation highlights that even sophisticated attackers can be compromised, but the scale of their operations is vast—so defenders need to prepare for advanced, persistent threats. Regularly updating security controls and educating employees are also essential steps.