North Korea-linked hackers target software developers via GitHub
North Korea-linked state-sponsored threat actors are conducting a cyber campaign against software developers via GitHub, using fake recruiter personas and malicious code repositories. Reporting cites roughly 100 organisations targeted and approximately 250 lure emails over a six-week window, with stated aims of cryptocurrency theft and source code or intellectual property theft. No insured compromise, corporate network breach, or specific financial loss has been confirmed on current public evidence.
AI-generated from linked source reports. See our correction policy.
Impact verdict
Low impact. Loss pathway remains unconfirmed. Reporting describes tradecraft and scale (~100 organisations targeted, ~250 lure emails over six weeks) but no insured compromise, claims data, or loss estimate. The activity is consistent with recurring DPRK intrusion tradecraft relevant to cyber and political risk books, but routine state-sponsored intrusion attempts absent a confirmed corporate breach do not, on current evidence, trigger a market-moving insured event. Severity is held at low because no insured-industry loss figures are present, so economic or sentiment signals alone cannot force an upgrade.
View assessment methodologyPremium discovery tier
Unlock analyst briefs, intelligence depth, and the revision timeline
Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.
Start two-week trialAffected countries
Lloyd's classifications
Tracking this kind of risk? Get an email when Cyber events escalate.
Get alerts