Available evidence describes formal criminal offences including organised crime, human trafficking, sexual exploitation, drug and arms trafficking, corruption and bribery, fraud, counterfeit currency, murder, assault, kidnapping, robbery, theft, smuggling, extortion, forgery, money laundering, and terrorist financing. The evidence does not provide a reliable national rate or regional comparison for these offences. Human trafficking risks particularly affect women and girls from North Korea who may face forced marriage, sexual exploitation, forced labour, or domestic servitude in China, as well as people who are returned to North Korea. These China-side offences are separate from the risks faced inside North Korea but can affect people during flight and return. United Nations reporting also describes forced labour in detention, labour-training centres, mass mobilisation, and overseas work as serious exploitation and safety concerns. State-related abuses, including arbitrary arrest, ill-treatment, unfair proceedings, imprisonment, forced labour, and enforced disappearance, should not be confused with ordinary street-crime statistics. The Ministry of Social Security handles general public-security functions, while the Ministry of State Security deals with state, border, and political-security matters; public security institutions, prosecutors, and courts also have formal roles. In practice, access to these bodies is selective and monitored, and evidence describes detention without a warrant or clear explanation, limited access to lawyers or interpreters, and delayed or refused contact with family. Foreign visitors normally travel with an organised tour, guide, or host and should request police contact through that person if an incident occurs. Independent hotlines, ombuds services, secure witness protection, and an independent victim-support system have not been reliably established in the available evidence. Consular assistance is limited; Sweden acts as protecting power for some countries, but access to detainees can be delayed or denied, and remote help is difficult when internet and mobile access are restricted. Visitors should follow local instructions, avoid unauthorised travel outside Pyongyang, pass checkpoints and identity checks as required, and obtain permission before photographing military sites or protected buildings. Hotel rooms may be monitored, phones and storage devices may be searched, GPS and satellite phones are illegal, and international SIM cards and network access are heavily restricted. External cybercrime risks linked to North Korean state-connected actors include identity fraud, remote information-technology worker schemes, spearphishing, malware, ransomware, cryptocurrency theft, and money laundering; businesses exposed to these risks should use identity checks, least-privilege access, endpoint protection, wallet controls, and their own national cyber or financial reporting channels. North Korean law formally recognises categories such as detention, house arrest, and confinement to an area for young people, while official reporting states that people under 18 should not receive the death penalty or life imprisonment, although independent verification is limited.
Crime in North Korea
Crime in North Korea is difficult to measure because the country does not publish reliable national crime statistics and independent reporting is severely limited. The main safety risks include state detention, border and communication offences, human trafficking, cybercrime, and strict enforcement of movement, media, photography, and religious rules. For foreign visitors, avoiding detention and maintaining a consular emergency plan generally matter more than ordinary theft risks.
Tip
Treat travel to North Korea as a detention-avoidance problem as well as an ordinary safety matter. Use an organised itinerary, follow the guide or host precisely, avoid unauthorised photography and communication, and arrange realistic consular contacts before departure. Businesses exposed to North Korea-linked cyber activity should apply strict identity, access, endpoint, and cryptocurrency controls.

