North Korean authorities have arrested a group of ex-military cyber experts suspected of stealing government money from two state-owned banks and laundering it using cryptocurrency. The crackdown occurred on July 12 in Pyongyang after officials detected unusual foreign currency transactions and suspicious online activity.

Details of the Alleged Breach

According to a report from South Korean outlet Daily NK, the suspects hacked into the Central Bank of the DPRK and the Foreign Trade Bank. They allegedly diverted foreign currency reserves and trade funds into crypto wallets held abroad. The stolen funds were converted through intermediaries based in Chinese border cities like Sinuiju and Hyesan, instantly swapping digital assets into US dollars and Chinese yuan.

The operation reportedly used fragmented fund transfers to avoid detection and relied on encrypted messaging apps, unregistered mobile devices, and Chinese wireless networks to communicate covertly. While these allegations have not been independently verified by sources such as Cointelegraph, they suggest a sophisticated laundering scheme involving cross-border crypto channels.

Reaction and Context

The North Korean National Intelligence Agency carried out the arrest at a secure location in the capital. This move is notable since the regime is better known for cyberattacks targeting foreign cryptocurrency platforms to generate revenue amid sanctions. Here, internal operatives allegedly targeted domestic government assets, a rare and striking development.

This case ties into broader trends in North Korean cybercrime and crypto laundering. It connects with previous stories about the regime’s hacking activities and use of crypto to sidestep sanctions. The incident highlights the complex role of crypto in state-level cyber operations and financial control.