//

North Korea Used IT Workers to Infiltrate Global Animation Studios, Cryptocurrency Firms

According to the report, North Korea’s cryptocurrency thefts began escalating around 2017, coinciding with intensifying international sanctions and a booming, lightly regulated crypto industry.

1 min read
Kim Jong-un and his daughter, Kim Ju-ae, visited the newly built Kalma coastal tourist area in Wonsan, North Korea [ Photo: KCNA]

Japanese and major American animation studios, including HBO Max and Amazon, have unknowingly hired undercover North Korean IT workers as part of a sophisticated sanctions evasion scheme, a multi-government report revealed Wednesday.

The 138-page report from the Multilateral Sanctions Monitoring Team—which includes Japan, the U.S., Australia, France, Canada, Italy, New Zealand, Germany, the U.K., South Korea, and the Netherlands—warns that North Korea is using IT personnel abroad to fund its military and circumvent international restrictions, including by hacking cryptocurrency exchanges.

North Korean IT workers have been identified operating in Japan, the U.S., the UAE, and Ukraine, often using false identities or claiming citizenship from countries such as Italy, Malaysia, Singapore, Ukraine, the U.S., and Vietnam. “The identities used were a combination of real and fabricated personas,” the report said.

The report also highlighted a rising trend of extortion by North Korean IT operatives. Recently fired employees have threatened to release sensitive company data or provide it to competitors. In one case in 2024, North Korean hackers registered a company in Japan as a front to funnel money and claim loans under false pretenses.

North Korea, along with Russia, is one of the most sanctioned nations in the world but has developed sophisticated methods to bypass restrictions. These include hacking cryptocurrency exchanges, selling stolen data on the dark web, and carrying out extortion campaigns, sometimes with life-threatening consequences.

In 2024, North Korean hacker Rim Jong Hyok was charged in the U.S. after deploying ransomware to extort hospitals and medical providers, then laundering the proceeds. In February 2025, a campaign called “ClickFake Interview” targeted cryptocurrency job seekers through fake interview websites, tricking them into installing malware that allowed hackers to access sensitive data.

The report also details a high-profile cryptocurrency theft in May 2024, when North Korean hackers stole around $308 million from DMM Bitcoin, a Japanese exchange, using LinkedIn to pose as a recruiter and compromise an employee’s device. The hack ultimately forced the company to cease operations by December 2024.

Under the leadership of Kim Jong Un, the report said, North Korea’s cyber operations have expanded into a full-scale national program with sophistication approaching that of China and Russia. Cryptocurrency heists and weapons sales to Russia made up the bulk of North Korea’s foreign revenue in 2024, with hackers stealing at least $1.19 billion in cryptocurrency—up roughly 50% from 2023. From January through September 2025, North Korean hackers reportedly stole at least $1.65 billion in digital assets.

Sri Lanka Guardian

The Sri Lanka Guardian is an online web portal founded in August 2007 by a group of concerned Sri Lankan citizens including journalists, activists, academics and retired civil servants. We are independent and non-profit. Email: editor@slguardian.org

Leave a Reply

Your email address will not be published.

Latest from Blog