South Korean Report Finds State-Sponsored Cyberattacks From North Korea China and Russia Rose 7.5 Percent in First Half 2026 With NK Accounting for 99 Incidents
North Korea's shift toward AI-generated lures, deepfake identities and code-repository infiltration signals a move from one-off credential theft to persistent access inside software supply chains, widening exposure for crypto and developer platforms beyond the incidents counted. China's falling incident total alongside sustained telecom-focused espionage and expansion into Southeast Asia and the Middle East points to consolidation toward fewer, longer intrusions rather than reduced capability, though the overall rise may instead reflect improved detection and attribution at S2W rather than higher adversary tempo. Russia's parallel growth in espionage and destructive strikes on Eastern European energy and government networks suggests a lower threshold for pairing collection with disruption as the war continues. Sourcing rests entirely on S2W's own report, with other outlets merely recapitulating its figures, leaving defenders' email-based defenses increasingly mismatched against AI-enabled social engineering.
5 sources
- State-sponsored cyberattacks from N. Korea, China, Russia rise 7.5% in 1st half of 2026 -
Korea Times - Hacking Targeting South Korea by Suspected North Korean Groups Rises… Exploiting AI and Deepfakes -
SBS News - 상반기 국가 배후 해킹 158건 포착… 북한, 한국 집중 타격 -
Cheonji Ilbo (CJ News) - North Korean Hackers Target South Korea Most Frequently; AI and Deepfakes Now in Their Arsenal -
BigGo Finance - 2026 First Half State-Sponsored Advanced Persistent Threat (APT) Group Threat Trends Report -
S2W