

Tracing the Path of Election Vulnerabilities from Dandong to Washington
Roy KimCo-author of The Dandong Project: A Report on 21st-Century Hybrid Warfare
A Strange Parallel Between Two Democracies
On July 16, 2026, President Donald Trump publicly made three notable statements regarding U.S. election security and election integrity.
First, he stated that China had stolen the personal information of approximately 220 million American voters.
Second, he asserted that approximately 270,000 ineligible "ghost voters" had been found on statewide voter registration rolls, including those in Michigan.
Third, he identified North Korea—alongside Russia, China, and Iran—as one of the hostile states possessing the capability to threaten America's election infrastructure.
Nearly three years earlier, on October 10, 2023, South Korea issued a remarkably similar warning.
In an official announcement, South Korea's National Intelligence Service (NIS) concluded that external actors, including North Korea, could penetrate the National Election Commission's computer network at any time and potentially manipulate voter registration databases as well as vote counting systems.
Although issued at different times, both warnings point to the same underlying concern: hostile foreign actors possess the capability to compromise critical election infrastructure.
Where do these two cases intersect?
This article traces that connection.
Its starting point lies in Dandong, China, in 2001.
1. The Seed Planted in Dandong — When North Korea Helped Build the System
In August 2001, Hana Program Center officially began operations in Dandong, China.
The center was operated by a South Korean company known as South-North Hanabiz, which conducted business domestically under the name Hanabiz.com. Its business model was straightforward: software projects contracted in South Korea were outsourced to North Korean developers working in Dandong.
The center also entered into a joint development agreement with Dasan CNS, a South Korean network equipment developer.
The project emerged during President Kim Dae-jung's Sunshine Policy, which encouraged inter-Korean economic cooperation.
Officially, Hana Program Center presented itself as a software development company.
Its own website, however, publicly listed joint development projects that included "DASAN WEB NMS Application" and "DASAN NETWORK Equipment System." Those records indicate that North Korean developers participated in projects involving Dasan's network management software and network equipment systems.
Following the sinking of the ROKS Cheonan in 2010, South Korea suspended most inter-Korean economic cooperation under the May 24 Measures. Hana Program Center officially shut down the following year.
Exactly one year later, in 2012, one of North Korea's most sophisticated cyber operations units—now closely monitored by both U.S. and South Korean intelligence agencies—began operating at full scale.
Its name was Kimsuky.
You are unauthorized to view this page. Please log in to read this page in full.
이 페이지를 보실 권한이 없습니다. 이 글 전문과 한글 버전을 읽으시려면 로그인을 먼저 해주십시오.
Please renew your membership or subscribe a membership if you didn't yet. Thank you.
멤버십을 갱신하시거나, 만약 구독하지 않으셨다면 구독을 먼저 해주시기 바랍니다. 감사합니다.
정기구독 신청하기 ← click here to subscribe. 여기를 클릭해서 구독해 주세요.



