OFAC–FBI evidence desk.
Read Treasury listings beside FBI wanted records without turning a parent-group affiliation into an individual designation.
One individual listing is not four.
Park Jin Hyok is individually OFAC-listed. Jon Chang Hyok, Kim Il, and Rim Jong Hyok appear in reviewed FBI materials with affiliations to OFAC-listed parent groups, but no separate public individual OFAC entry was located for those three. Parent affiliation and individual listing are different public-record facts.
RGB listing timeline, 2010–2025.
This curated timeline shows reviewed RGB-linked targets in selected actions. It is not a count of all DPRK sanctions.
| Year | Targets added | Names | Public focus |
|---|---|---|---|
| 2010 | 3 | Reconnaissance General Bureau; Kim Yong Chol; Green Pine Associated Corporation | Intelligence command, organizational lineage, and arms trading |
| 2016 | 2 | Cho Il-U; O Chong Ok | Named bureau directors and personal identifiers |
| 2017 | 1 | Kim Su-Kwang | Covert overseas intelligence posting |
| 2018 | 2 | Park Jin Hyok; Korea Expo Joint Venture | Named programmer and cyber front company |
| 2019 | 3 | Lazarus Group; Bluenoroff; Andariel | RGB-controlled cyber groups |
| 2023 | 3 | Technical Reconnaissance Bureau; 110th Research Center; Kimsuky | Cyber command structure, research unit, and espionage group |
| 2024 | 1 | Ri Chang Ho | Current RGB leadership and support to Russia |
| 2025 | 2 | Song Kum Hyok; Nam Chol Ung | IT-worker identity fraud, overseas revenue, and arms schemes |
Named RGB officials and operatives.
Roles and public attribution are reproduced from the reviewed structured source.
| Person | Listed | Public role | Public basis | FBI wanted |
|---|---|---|---|---|
| Kim Yong Chol | 2010 | RGB commander at the time of listing | Named with the RGB and Green Pine in the 2010 action; later public testimony linked him to the Sony attack attribution. | No page located |
| Cho Il-U | 2016 | Director, RGB Fifth Bureau | OFAC published bureau title, aliases, birth information, and passport identifier; the bureau mission was not explained. | No page located |
| O Chong Ok | 2016 | Director, RGB First Bureau | OFAC published bureau title, aliases, and birth information; the bureau mission was not explained. | No page located |
| Kim Su-Kwang | 2017 | RGB official | Treasury reported that he operated under RGB cover at a United Nations organization in Europe. | No page located |
| Park Jin Hyok | 2018 | RGB-linked programmer associated with Korea Expo/Lazarus | Treasury tied him to Sony, Bangladesh Bank, WannaCry, and other malicious cyberactivity. | Yes |
| Ri Chang Ho | 2024 | Director/head of the RGB | Treasury tied the RGB under his leadership to revenue for WMD programs and noted his presence with DPRK troops sent to Russia. | No page located |
| Song Kum Hyok | 2025 | Malicious actor associated with RGB-controlled Andariel | Treasury tied him to stolen U.S. identities and fraudulent IT-worker employment. | No page located |
| Nam Chol Ung | 2025 | RGB intelligence officer and representative in Dalian | Treasury tied him to overseas revenue generation and arms or weapons schemes dating back to at least 2013. | No page located |
Wanted persons and listed parents.
The status column preserves the individual-versus-parent distinction exactly.
| Person | FBI affiliation | Individual OFAC status | OFAC-listed parent | Public case |
|---|---|---|---|---|
| Jon Chang Hyok | RGB units; Lazarus/APT38 | No separate public entry located | Lazarus Group and Bluenoroff/APT38 | Alleged global cyberattacks and financial theft; also tied to malicious cryptocurrency applications. |
| Kim Il | RGB units; Lazarus/APT38 | No separate public entry located | Lazarus Group and Bluenoroff/APT38 | Alleged bank and cryptocurrency schemes, malicious applications, and the Marine Chain token offering. |
| Park Jin Hyok | RGB; Korea Expo; Lazarus/APT38 | Individually listed in 2018 | Lazarus Group and Bluenoroff/APT38 | Sony Pictures, Bangladesh Bank, WannaCry, and related computer intrusions and fraud. |
| Rim Jong Hyok | RGB Third Bureau; Andariel | No separate public entry located | Andariel | Maui ransomware against U.S. hospitals, laundering, and cyberespionage against U.S., South Korean, and other targets. |
A practical FOIA records map.
These are record categories to request—not claims that every category exists for every person.
- Final administrative recordsDesignation memoranda, decisions, and segregable factual findings.
- Exhibit and source listsExisting indexes, unclassified exhibits, and source inventories.
- Identity sheetsAliases, identifiers, posts, relationships, and organization records.
- Factual summariesFinished public-source or declassified findings tied to named operations.
- Archived list-change recordsAlias updates, name changes, party records, and change histories.
- Interagency and downgraded recordsFinal referrals, factual attachments, and declassified or public-source analysis.
Open the underlying record.
Sanctions findings and criminal allegations are attributed to the issuing agency; they are not independent findings by DMZ War.
Structured source SHA-256: 81cc2f4cd8d0d10a11ab8fedf761b1eb8de249bb1fff01128b2352472a3a3c00
