Observed Signal · Jun 10, 2026 · Report Release · Source: techcrunch · Impact: 3/5 · Sentiment: Negative
North Korea behind nearly half of US tech hacks
CrowdStrike's 2026 Technology Threat Landscape report finds North Korean hackers, operating under the group name 'Famous Chollima,' were responsible for roughly 47% of documented state-backed 'hands-on-keyboard' intrusions targeting U.S. tech companies between April 2025 and May 2026. The group commonly poses as remote IT workers, developers or recruiters using stolen credentials, real-time deepfake images and fraudulent identity documents to gain jobs and persistent access. Operators steal intellectual property and cryptocurrency — often funneling salaries and stolen funds back to the Kim regime — and sometimes extort companies with threatened disclosures. The report highlights targeting of blockchain developers and ongoing use of these operations to finance Pyongyang’s prohibited weapons programs.
A major cybersecurity vendor reports concentrated, state-backed identity-fraud intrusions and crypto theft that threaten tech-sector security, developer hiring/trust and could affect companies across the ad/tech ecosystem.
Track CrowdStrike Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- CrowdStrike published an annual technology threat report covering April 2025 to May 2026.
- CrowdStrike attributes 47% of state-backed activity targeting the tech sector in that period to a North Korean group it calls 'Famous Chollima.'
- Famous Chollima poses as remote developers, IT workers and recruiters using stolen credentials, real-time deepfake images and fraudulent identity documents.
- The operators steal intellectual property and cryptocurrency, funneling salaries and stolen funds back to the North Korean regime and sometimes using extortion.
Connected Companies & Entities
1 Entity mappedOntology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
North Korean Hackers Infiltrate Western Firms as Fake Developers
U.S. authorities have sanctioned six individuals and two organisations accused of placing North Korean IT workers as fake developers into Western companies. According to U.S. agencies, these embedded workers earned about $800 million in wages in 2024, funds allegedly directed to Pyongyang’s weapons programmes; in the same period North Korea reportedly stole about $2 billion in cryptocurrencies. The campaign — observed in Europe and involving intermediaries operating from Spain and a shell company in Vietnam — included theft of source code, transfer of code repositories to private accounts, deployment of malware and later extortion of employers. Google Threat Intelligence Group noted increased applications from North Korean IT candidates in Europe. The FBI has advised companies to conduct in-person interviews, restrict new hires’ access, monitor network and remote connections, and vet external recruiters.
CrowdStrike: China Escalating AI Cyberespionage
CrowdStrike warned in a June 2026 report that China-affiliated state-sponsored actors have increased targeted cyberattacks against U.S. technology companies to steal AI capabilities and intellectual property. The firm said China-nexus actors accounted for more than 58% of state-sponsored targeted attacks against tech firms in the 12 months ending March 31, 2026, and that attackers maintained persistent access to North American tech organizations by exploiting vulnerabilities. CrowdStrike also reported North Korea-affiliated actors attempting to infiltrate IT workforces for revenue generation. The Cyberspace Administration of China did not respond to requests for comment. The story references earlier complaints from Anthropic and OpenAI about Chinese firms extracting competitive intelligence and notes recent public releases of Anthropic’s Claude Fable 5.
Two Americans Sentenced for Assisting North Korea
Two American men were each sentenced to 18 months in prison for assisting North Korean operatives who posed as remote IT workers to infiltrate U.S. companies. Prosecutors found the defendants hosted laptops in their homes that North Korean actors used, under false identities, to access corporate systems — a method reportedly used to target numerous Fortune 500 firms. The article places the case in a broader trend: attackers use deepfakes, AI-generated résumés and stolen identities to win remote jobs, and researchers estimate the technique has generated substantial revenue for North Korea. The story references a prior, larger prosecution (Christina Chapman), FBI seizures, and industry/study estimates about the scale and financial impact of these infiltrator schemes. Publication date: 2026-05-10.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
