North Korea's Lazarus Group breached Bitrefill, a Sweden-based crypto gift card platform, on March 1, 2026, by exploiting a compromised employee laptop and a legacy credential to access production secrets. The attackers drained hot wallets and accessed approximately 18,500 customer purchase records before being detected through
Table of contents
A Breach That Started with a LaptopInside the Bitrefill CyberattackData Exposure: Limited but SignificantAttribution to Lazarus Group and DPRKCyble’s Tracking of Lazarus Group and DPRK Cyber OperationsWhy Cryptocurrency Platforms Are Prime TargetsThe Playbook of Lazarus GroupResponse and RecoveryConclusionSort: