South Korean authorities reported on 28 November 2025 that the North Korean Lazarus Group had stolen $30.4 million in cryptocurrency from the domestic exchange Upbit.
State-Attributed Theft Is Its Own Category
Almost every state-linked file in this corpus concerns collection: metadata at 25-0304, network diagrams at 25-0611, correspondence at 25-0408 and 25-1213. The objective is knowledge and the value is not denominated in currency.
This is a state operation whose objective is money. It sits alongside 25-0221, where $1.5 billion left an exchange in a single afternoon, and it makes cryptocurrency exchanges the one target class where espionage-grade capability is applied to straightforward theft.
Which Is Why The Defensive Problem Is Unusual
An exchange faces the capability of a national intelligence service with the persistence of a criminal enterprise. It cannot deter with prosecution, cannot rely on sanctions — per 25-0213, sanctions do not interrupt state operational tempo — and cannot reverse the transaction once settlement completes, per 25-1210.
The corpus files no other sector facing that combination.
Official Attribution Is Worth More Than A Research Assessment
This desk grades most attribution as claim, per 26-0217. Attribution by a national authority, published in its own jurisdiction and concerning its own exchange, sits above vendor tradecraft matching.
It is still an assessment rather than a court finding — the standard applied at 25-0812 — and this desk records it as the highest-confidence category available short of conviction.
Compiled from public reporting of an official announcement, listed below. Attribution is the authorities’ assessment as reported. The intrusion route is not established. Corrections: corrections@forensicpost.com.
- Significant cyber incidentsCSIS
- Top data breaches in 2025, month-wiseSecurity Boulevard