Japan-based Crypto Businesses Warned of Possible Cyberattack Threat

Crypto companies in Japan asked to defend against hacks from North Korea’s Lazarus group

article-image

Tokyo, Japan; Source: Shutterstock

share

key takeaways

  • Lazarus is most likely targeting Japanese crypto operators through cyberattacks, authorities say
  • Crypto businesses urged to caution against phishing attacks and social engineering

North Korean hacking group Lazarus plotting phishing and social engineering attacks against crypto businesses, authorities in Japan have warned.

Local police, Japan’s financial regulator and the National Center of Incident Readiness and Strategy warned local crypto businesses in a recent advisory statement about further hacking attempts. They also laid out preventive measures to monitor breaches.

Since Lazarus is state-sponsored, it is believed proceeds from the hacks may go toward North Korea’s nuclear weapons program. The group has also been associated with using crypto mixer Tornado Cash, recently sanctioned by the US Treasury, to conceal the origin of stolen funds.

The authorities didn’t mention which crypto businesses were targeted by Lazarus, but warned that security measures such as improved private key management are warranted.

They asked both individuals and companies to implement countermeasures such as ensuring the origin of downloaded files is a trusted source, interfaces to web applications are legitimate and private keys are stored offline, such as on a hardware wallet.

Lazarus is believed to have stolen more than $1.75 billion worth of cryptoassets since its formation in 2009, Chainalysis found last year. The group has been behind several crypto exchange hacks, including the theft of $49 million worth of crypto from Upbit in 2019.

After several companies had their internal systems hacked and crypto stolen, police reportedly launched an investigation within a special investigation unit. They eventually found Lazarus to be the culprit.

A local report by Japan News states it isn’t usual to name a suspected attacker before a more substantial action like an arrest, but that publicly naming the group is also viewed as an effective move to preempt attacks, as it could prompt people to take action and remain vigilant.


Start your day with top crypto insights from David Canellis and Katherine Ross. Subscribe to the Empire newsletter.

Tags

Upcoming Events

Salt Lake City, UT

WED - FRI, OCTOBER 9 - 11, 2024

Pack your bags, anon — we’re heading west! Join us in the beautiful Salt Lake City for the third installment of Permissionless. Come for the alpha, stay for the fresh air. Permissionless III promises unforgettable panels, killer networking opportunities, and mountains […]

recent research

Avail.jpg

Research

Data publishing costs have historically been a bottleneck for rollups, and as more rollups launch, interoperability will continue to be a major challenge. Avail presents a potential solution to rollup fragmentation through its three products: Avail DA, Nexus, and Fusion, which together aim to unify the web3 experience.

article-image

Bitcoin miners need to explore unconventional energy avenues or be buried by the financial realities created by this halving

article-image

BlackRock’s iShares Bitcoin Trust continues to see daily positive net flows, though its inflow total for a single day hit a new low Wednesday

article-image

Binance is making moves, from receiving a new license in Dubai to switching its SAFU fund to USDC

article-image

Miner stocks have historically underperformed bitcoin before the halving and outperformed the asset after the event, analysts note

article-image

After a one-week trial, a jury convicted crypto trader Avraham Eisenberg

article-image

A verdict in Avraham Eisenberg’s criminal fraud trial is expected this afternoon