ClosedLow impactAI Refreshed

North Korea-linked hackers target software developers via GitHub

Occurred 9 Jun 2026·Detected 14 Jun 2026·
Global cyber campaign targeting developers, attributed to North Korean state-sponsored actors2 reportsEnded 1 Jul 2026
CyberPolitical Violence & WarCyber

North Korea-linked state-sponsored threat actors are conducting a cyber campaign against software developers via GitHub, using fake recruiter personas and malicious code repositories. Reporting cites roughly 100 organisations targeted and approximately 250 lure emails over a six-week window, with stated aims of cryptocurrency theft and source code or intellectual property theft. No insured compromise, corporate network breach, or specific financial loss has been confirmed on current public evidence.

AI-generated from linked source reports. See our correction policy.

Impact verdict

Low impact. Loss pathway remains unconfirmed. Reporting describes tradecraft and scale (~100 organisations targeted, ~250 lure emails over six weeks) but no insured compromise, claims data, or loss estimate. The activity is consistent with recurring DPRK intrusion tradecraft relevant to cyber and political risk books, but routine state-sponsored intrusion attempts absent a confirmed corporate breach do not, on current evidence, trigger a market-moving insured event. Severity is held at low because no insured-industry loss figures are present, so economic or sentiment signals alone cannot force an upgrade.

View assessment methodology

Premium discovery tier

Unlock analyst briefs, intelligence depth, and the revision timeline

Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.

Start two-week trial

Affected countries

🇰🇵 North Korea

Lloyd's classifications

Tracking this kind of risk? Get an email when Cyber events escalate.

Get alerts