SUMMARY
North Korea is one of the world's most isolated countries, and ordinary citizens have extremely limited access to the global internet. Yet North Korean hackers have repeatedly targeted banks, technology companies, cryptocurrency platforms and governments around the world. The apparent contradiction disappears when the country's restricted internet system is separated from the highly privileged access given to selected cyber operators. North Korea combines specially trained hackers, overseas operations, foreign infrastructure, proxy networks, compromised computers and fraudulent IT workers to reach the global internet while keeping most of its population offline.
North Korea is one of the most digitally isolated countries on Earth.
For most ordinary North Koreans, the global internet that billions of people use every day is largely out of reach. Instead, the country operates a tightly controlled domestic network known as Kwangmyong, where access to information and online services is heavily restricted by the government.
Yet the country's cyber operators appear across the digital world.
North Korea-linked groups have been accused of stealing cryptocurrency, targeting financial institutions, conducting espionage, compromising software projects and infiltrating companies through fake identities. In recent years, North Korean cyber operations have also expanded into fraudulent remote employment schemes.
So how can a country that restricts internet access so heavily produce hackers capable of operating against organizations thousands of kilometres away?
The answer is that North Korea's internet restrictions do not apply equally to everyone.
Ordinary North Koreans and Cyber Operatives Live in Different Digital Worlds
North Korea's internet system is designed around strict government control.
Ordinary citizens generally cannot freely browse the global web. Instead, many have access only to the country's tightly controlled internal network, Kwangmyong.
But North Korea's government has a very different approach to people working in sensitive areas such as intelligence, military operations, science and cyber warfare.
Selected researchers, universities, government organizations and cyber operators can receive access to international networks that ordinary citizens cannot use.
This creates an important distinction.
North Korea does not need to give 20 million people unrestricted internet access to conduct global cyber operations. It only needs to provide the necessary connectivity to a relatively small number of carefully selected personnel.
North Korea Treats Cyber Skills as a Strategic Asset
For the North Korean government, cyber operations offer something extremely valuable: global reach without requiring a conventional military presence.
A missile requires physical infrastructure, fuel, launch equipment and a visible military system.
A cyber operation can sometimes begin with a computer, an internet connection and specialized expertise.
That makes cyber capabilities particularly attractive to a country facing extensive economic sanctions and limited access to international financial systems.
U.S. authorities have repeatedly accused North Korean military hackers of conducting cyberattacks and financial crimes around the world. The U.S. Justice Department previously described North Korean military hackers as being involved in attacks against banks, businesses and cryptocurrency targets. 0
Some Hackers Operate Outside North Korea
This is one of the biggest reasons North Korean hackers can appear to be everywhere.
Cyber operations associated with North Korea do not necessarily originate from a computer physically located inside North Korea.
North Korean operators have been linked to infrastructure and personnel operating through third countries. Cybersecurity researchers have documented the use of networks, servers and other infrastructure outside North Korea to make operations harder to trace.
Research from the Center for Strategic and International Studies has described North Korea's use of third countries as an important part of its cyber strategy. 1
This means that investigators looking at an attack may see infrastructure located in another country even when the operation is ultimately attributed to North Korean actors.
China and Other Countries Can Become Part of the Infrastructure
North Korean cyber operations have historically benefited from infrastructure outside the country, particularly because North Korea's own international connectivity is limited.
That can include rented servers, compromised machines, proxy services and other technical infrastructure.
The use of foreign infrastructure does not necessarily mean that a foreign government is directing or knowingly supporting a particular attack. Cybercriminals and state-backed hackers routinely use infrastructure in countries unrelated to the target or attacker in order to disguise their location.
For North Korea, this is especially useful because its own internet infrastructure is relatively easy for researchers and governments to identify and monitor.
The Hackers Don't Need to Sit in Pyongyang
Another misconception is that every North Korean cyber operation must be physically conducted from inside the country.
That is not how modern cyber operations work.
A hacker can operate through a chain of computers and servers distributed across several countries. An operator may connect to an overseas server, use compromised infrastructure and then target a victim somewhere else.
As a result, the victim may never see a direct connection from a North Korean network.
This makes geographical distance far less important in cyberspace than it is in conventional warfare.
North Korea Also Uses Fake IT Workers
Perhaps the most striking example of North Korea's global reach is its remote IT worker operation.
North Korean workers have been accused of obtaining employment with foreign companies while concealing their true identities and locations.
The workers can perform legitimate technical tasks while secretly generating income for the North Korean regime and potentially gaining access to sensitive corporate systems.
The FBI says North Korea relies on a network of skilled IT workers deployed both inside and outside the country who use false identities to earn money remotely. U.S. authorities say revenues from these operations help fund North Korea's weapons programs. 2
Recent investigations show that the scheme has expanded beyond traditional software jobs. Security researchers have found North Korean operatives targeting areas including healthcare, sales and marketing while using stolen identities and sophisticated methods to conceal their locations. 3
Some Workers May Never Look Like Hackers
This is what makes the IT worker operation particularly difficult to detect.
A traditional hacker may attempt to break into a company's network from outside.
A fraudulent IT worker can potentially obtain legitimate credentials by getting hired.
Once inside, the person may have access to company systems, source code, internal communications or sensitive information as part of their normal job.
Investigators have found cases involving stolen identities, remote-access equipment, proxy services and other methods designed to make a worker appear to be located somewhere they are not.
In August 2026, reports emerged that the FBI was investigating how a North Korean remote IT worker managed to obtain employment with a U.S. government agency. 4
Cryptocurrency Became Another Target
North Korean cyber operators have also become notorious for targeting cryptocurrency.
Cryptocurrency is particularly attractive because digital assets can potentially be stolen remotely and moved across international networks without physically transporting cash.
North Korean-linked groups have been accused of stealing billions of dollars in cryptocurrency over the years.
Those operations have included attacks against cryptocurrency exchanges, blockchain companies and individuals holding digital assets.
The financial motivation is significant because North Korea faces extensive international sanctions that restrict its access to conventional sources of foreign currency.
The Money Can Move Even When North Korea Cannot
This is another key part of the answer.
North Korea does not need unrestricted access to the international banking system to benefit from cyber theft.
Cyber operators can steal digital assets and use complicated networks of wallets, intermediaries and other mechanisms to obscure the movement of funds.
U.S. authorities have consequently targeted people and organizations accused of helping North Korea convert or move money generated through IT worker schemes and cybercrime. The U.S. Treasury has also linked North Korean cyber activity to efforts supporting the country's weapons programs. 5
North Korean Hackers Are Becoming More Sophisticated
The country's cyber capabilities are also evolving.
In August 2026, Reuters reported that South Korean cybersecurity researchers had identified evidence that the North Korean hacking group Kimsuky was developing and using artificial intelligence tools to support cyber operations.
The researchers said the group was moving beyond simply using AI to create convincing phishing messages. AI was reportedly being integrated into areas such as data analysis, malware development and attack automation. 6
That development is important because artificial intelligence can potentially allow a relatively small group of skilled operators to automate parts of complicated cyber operations.
North Korea Has Also Targeted Software Developers
The threat is not limited to banks and cryptocurrency exchanges.
In 2026, North Korea-linked hackers were accused of compromising software development environments and targeting widely used open-source projects.
One investigation reported that suspected North Korean hackers used elaborate social-engineering techniques to compromise a developer and ultimately push malicious updates to an open-source project. 7
This type of attack demonstrates why the modern software supply chain has become such an important battlefield.
A hacker does not necessarily have to attack millions of computers individually. Compromising one developer, software package or widely used service can potentially create access to many downstream victims.
North Korea's Cyber Advantage Is Asymmetrical
There is a deeper strategic reason why cyber operations are attractive to Pyongyang.
The cost of launching a cyberattack can be dramatically lower than the cost of maintaining a conventional military operation.
A country can spend years and enormous amounts of money building aircraft, ships and missiles. Cyber operations require skilled personnel, computers, training and access to global networks.
And the attacker does not have to defeat an entire country's defenses.
In many cases, the attacker only needs to find one vulnerable organization, one careless employee or one compromised account.
Why the Internet Restriction Does Not Stop Them
The apparent contradiction can therefore be explained in five simple points.
First: North Korea's internet restrictions primarily affect ordinary citizens, not the country's intelligence and cyber organizations.
Second: selected cyber personnel can receive privileged access to international networks.
Third: North Korean operators can work through infrastructure located outside the country.
Fourth: North Korea sends some IT workers overseas or disguises their identities so they can operate within foreign companies.
Fifth: cyber operations are inherently global. A hacker does not need to physically enter another country to target its computer systems.
The Real Weakness Is Often the Victim
North Korean cyber operations also demonstrate an uncomfortable reality about cybersecurity.
A country can have sophisticated national defenses and still suffer a major breach because an employee clicks a malicious link, reuses a password, downloads a fake software update or unknowingly hires someone using a stolen identity.
That is why modern cybersecurity is increasingly focused on people and processes as much as firewalls and antivirus software.
Why North Korea's Model Is So Difficult to Stop
Completely stopping North Korean cyber operations is extremely difficult because the country does not have to maintain a conventional internet environment for the entire population.
It can concentrate resources on a relatively small number of highly trained specialists while using international infrastructure to reach the rest of the world.
The strategy also benefits from the fact that cyber operations cross borders almost instantly.
A North Korean operator can target a company in the United States, route traffic through another country, steal cryptocurrency belonging to a victim in Asia and use infrastructure hosted somewhere else—all without physically leaving North Korea.
The Bigger Lesson
North Korea's cyber program shows that internet isolation and cyber power are not opposites.
A government can severely restrict the digital freedom of its citizens while giving a small group of specialists extensive access to the global internet.
In fact, the country's isolation may make cyber operations even more strategically valuable. When conventional economic and diplomatic channels are restricted, digital operations provide another way to obtain money, intelligence and technological information.
Conclusion
North Korea's restricted internet can make the country's cyber capabilities seem impossible at first glance.
But there is no real contradiction.
Ordinary North Koreans may have little access to the global internet, while carefully selected hackers, intelligence officers and IT workers can operate through privileged connections, foreign infrastructure and overseas networks.
That small, specialized workforce can then reach victims around the world.
The result is one of the most unusual cybersecurity models in the world: a country that keeps much of its population digitally isolated while simultaneously using the global internet as a battlefield, source of revenue and intelligence-gathering tool.
North Korea does not need everyone to be online.
It only needs the right people to be online.
Daily Touch Insights


