Every story tagged State Sponsored Attack, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.
3 stories · open in the command center
North Korea-linked threat actors stole $577M in cryptocurrency across two major protocol hacks in April 2026, representing 76% of all crypto theft losses year-to-date and highlighting the escalating threat of state-sponsored attacks on blockchain and financial infrastructure. This incident underscores critical vulnerabilities in decentralized finance systems and demonstrates how adversaries are targeting high-value digital assets, requiring IT leaders to reassess their security posture for any blockchain-dependent operations and third-party integrations. Organizations must recognize that nation-state actors are increasingly sophisticated in targeting emerging technology platforms, necessitating enhanced monitoring, threat intelligence integration, and incident response capabilities.
North Korean state-sponsored hackers stole $290M in cryptocurrency from Kelp DAO by exploiting weak multi-signature security controls in cross-blockchain bridge infrastructure, marking the largest crypto theft of 2026. This attack underscores the escalating sophistication of nation-state threat actors targeting financial systems, with North Korea having stolen over $6 billion in crypto since 2017 to fund its regime. The incident highlights critical vulnerabilities in third-party integrations and multi-party verification systems that extend beyond cryptocurrency to any distributed digital asset infrastructure.
Russian state-linked hackers attempted a destructive cyberattack on Swedish critical infrastructure in early 2025, marking an escalation from denial-of-service tactics to coordinated operations targeting energy systems across Europe with real-world disruption capabilities. This incident, alongside recent attacks on Poland's power grid, Norwegian dams, and Ukrainian utilities, signals a fundamental shift in threat sophistication and intent that demands immediate strengthening of industrial control system defenses and resilience planning. IT organizations must now treat critical infrastructure protection as a national security imperative rather than a purely operational concern, requiring enhanced monitoring, segmentation, and recovery capabilities.