A group of hackers from North Korea's Reconnaissance General Bureau (RGB) were linked to the JumpCloud breach due to an operational security (OPSEC) error, inadvertently revealing their real IP addresses.
See also: Are Lazarus hackers behind the JumpCloud hack?

The hacker group, known as UNC4899, was observed using a combination of commercial VPNs and Operational Relay Boxes (ORBs), over IPsec L2TP tunnels, to hide its true location.
Mandiant reports that the UNC4899 perpetrators have used multiple VPN providers for this purpose in previous attacks, including ExpressVPN, NordVPN, TorGuard, and others.
Although North Korean state hackers are known for using commercial VPN services to hide their IP addresses and real locations, during the JumpCloud attack, the VPNs they were using failed and revealed their location in Pyongyang while connecting to network .
“ Mandiant observed the UNC4899 threat actor connecting directly to an attacker-controlled ORB from the 175.45.178[.]0/24 subnet ,” the researchers said
In addition to OPSEC surveillance, Mandiant security researchers also discovered attack infrastructure that is linked to previous related breaches involving North Korean hackers, further reinforcing the effectiveness of the breach by North Korean hackers.
See also: JumpCloud: Hacking attack led to breach

“We believe with high confidence that UNC4899 is a cryptocurrency that falls under RGB. UNC4899’s targeting is selective and they have been observed gaining access to victim networks via JumpCloud,” Mandiant added.
On Thursday, JumpCloud confirmed that an APT group from North Korea was responsible for the breach that occurred in June, following a report from security researchers at SentinelOne and CrowdStrike earlier that day.
Mandiant predicts that more people may be experiencing the effects of this attack now. On July 5, after a week of a hacker breaching its network with spear-phishing, JumpCloud was forced to redirect all admin API keys.
Although the company has already addressed the attack, it has not yet revealed the exact number of affected customers.
See also: JumpCloud: Reinstates admin API keys due to an “ongoing incident”
JumpCloud plays a central role in strengthening the security of online systems. By providing its services, it allows organizations to manage user identities and strengthen their security practices. However, recent attacks prove that even the most sophisticated systems are not invulnerable and highlight the need for constant vigilance and awareness in the field of cybersecurity.
