North Korea's Lazarus Group breached Bitrefill, a Sweden-based crypto gift card platform, on March 1, 2026, by exploiting a compromised employee laptop and a legacy credential to access production secrets. The attackers drained hot wallets and accessed approximately 18,500 customer purchase records before being detected through

7m read timeFrom cyble.com
Post cover image
Table of contents
A Breach That Started with a LaptopInside the Bitrefill CyberattackData Exposure: Limited but SignificantAttribution to Lazarus Group and DPRKCyble’s Tracking of Lazarus Group and DPRK Cyber OperationsWhy Cryptocurrency Platforms Are Prime TargetsThe Playbook of Lazarus GroupResponse and RecoveryConclusion

Sort: