Desk live·
ForensicPost
Ransomware/Geopolitics/File 25-1129

Lazarus Group Took $30.4 Million From Upbit, South Korean Authorities Say

South Korean authorities reported on 28 November 2025 that the Lazarus Group had taken $30.4 million in cryptocurrency from the Upbit exchange.

Constructed geometry · not a chart of case data
JurisdictionSouth Koreathe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetUpbit
ActorLazarus Group
S. Rosler11 min readConfidence: high2 sources reviewed

South Korean authorities reported on 28 November 2025 that the North Korean Lazarus Group had stolen $30.4 million in cryptocurrency from the domestic exchange Upbit.

State-Attributed Theft Is Its Own Category

Almost every state-linked file in this corpus concerns collection: metadata at 25-0304, network diagrams at 25-0611, correspondence at 25-0408 and 25-1213. The objective is knowledge and the value is not denominated in currency.

This is a state operation whose objective is money. It sits alongside 25-0221, where $1.5 billion left an exchange in a single afternoon, and it makes cryptocurrency exchanges the one target class where espionage-grade capability is applied to straightforward theft.

Which Is Why The Defensive Problem Is Unusual

An exchange faces the capability of a national intelligence service with the persistence of a criminal enterprise. It cannot deter with prosecution, cannot rely on sanctions — per 25-0213, sanctions do not interrupt state operational tempo — and cannot reverse the transaction once settlement completes, per 25-1210.

The corpus files no other sector facing that combination.

Official Attribution Is Worth More Than A Research Assessment

This desk grades most attribution as claim, per 26-0217. Attribution by a national authority, published in its own jurisdiction and concerning its own exchange, sits above vendor tradecraft matching.

It is still an assessment rather than a court finding — the standard applied at 25-0812 — and this desk records it as the highest-confidence category available short of conviction.

How we reported this

Compiled from public reporting of an official announcement, listed below. Attribution is the authorities’ assessment as reported. The intrusion route is not established. Corrections: corrections@forensicpost.com.

Sources
  1. Significant cyber incidentsCSIS
  2. Top data breaches in 2025, month-wiseSecurity Boulevard
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary