Research: North Korea's internet use has surged ~300% since 2017 despite US sanctions, with ~50% of its traffic flowing through a new connection in Russia
The North has evaded America's “maximum pressure” campaign with a 300 percent increase in internet use that has opened up new opportunities for cybercrime.
Context & Ripple Effects
The 300% surge caps an arc the related coverage has tracked for years: back in late 2017, defector interviews already pointed to an increasing number of North Koreans carrying phones tied to a heavily monitored intranet, and by 2018 Wall Street Journal investigators found operatives earning millions abroad under fake identities on services like Github, Slack, and Paypal. What the new research adds is the infrastructure layer — connectivity kept growing straight through the 'maximum pressure' campaign, and roughly half of it now rides a fresh Russian route rather than whatever path preceded it.
That matters because the coverage consistently ties bandwidth to revenue: the New Yorker's 2021 reporting describes hacking operations run almost purely to fund the regime, and the Financial Times documents how those operations scaled into crypto cyber crime targeting Axie Infinity and Bangladesh Bank. More pipes, more traffic, more opportunities for exactly that activity.
First-order effects
- US 'maximum pressure' sanctions have failed at their connectivity objective: internet use tripled after 2017, and the new Russian connection gives Pyongyang a second transit path that dilutes any single point of external leverage.
- Russian network operators hosting the new route are now carrying about half of North Korea's outbound traffic, making them a material node in how the regime reaches the open internet.
Second-order effects
- Expanded connectivity directly feeds the revenue machine documented in later coverage — the hacking operations profiled by the New Yorker and the crypto thefts detailed by the Financial Times scale with the access and tooling a larger online footprint provides.
- Sanctions enforcers in Washington face a harder target: blocking trade goods proved insufficient, so pressure migrates toward naming and restricting the intermediaries — hosts, transit providers, identity platforms — that the 2018 fake-identity investigation showed the regime exploits.
Third-order effects
- If the pattern holds, sanctions against isolated states become a routing problem rather than a trade problem: each new national connection (Russia here) re-arms the sanctioned economy and forces enforcement toward infrastructure providers and third-party platforms.
- State cybercrime consolidates as a structural revenue pillar for closed economies — the same trajectory the coverage traces from monitored domestic phones to industrial-scale crypto theft — which pushes regulators toward treating nation-state hacking as a financial-sanctions issue, not only a security one.
The trend: Sanctioned states are building redundant internet paths through willing neighbors while converting growing connectivity into state-directed cybercrime revenue, outpacing a sanctions regime designed for trade interdiction.