North Korean 'WaterPlum' hackers stole $10.5M from job seekers across 100 countries
FBI, Pentagon and police in Japan, Australia and Germany detail a crypto-theft scheme that infected 30,000 devices by posing as recruiters.
What to know
- Joint FBI/Pentagon/Japan/Australia/Germany advisory identifies WaterPlum as a North Korean group that infected 30,000+ devices in 100+ countries between December 2025 and July 2026.
- Hackers posed as AI or blockchain company recruiters, tricking job applicants into downloading malware (BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, StoatWaffle) during fake interviews.
- Total theft exceeds $10.5 million (about ¥1.7 billion), drawn from roughly 7,000 compromised cryptocurrency wallets.
- The scheme is linked to North Korea's broader IT-worker infiltration operation; Japanese police disrupted a domestic laptop farm for the first time and found shared IP infrastructure between WaterPlum and North Korean IT workers.
WaterPlum North Korean hacking groupFBI U.S. law enforcement agencyJapan National Police Agency Japanese law enforcementNorth Korean IT worker scheme operatives Related North Korean actors
How it unfolded 3 developments, newest first · click a bar or a number to jump articlesposts
-
3
Japan's NPA ties WaterPlum to ¥1.7 billion in thefts, laptop farm bust
Japan Times and Japan's National Police Agency report the WaterPlum campaign stole about ¥1.7 billion, and Japanese officials say they disrupted, for the first time, a domestic laptop farm run by a Japanese national used to funnel several hundred million yen abroad.
“North Korean hackers were responsible for stealing about ¥1.7 billion in a cyberattack spanning more than 100 countries, including Japan, the National Police Force has said.”
— Japan Times (Mastodon post) -
first by Japan Times, 5d ago · also The Japan Times
-
T
North Korean hackers were responsible for stealing about ¥1.7 billion in a cyberattack spanning more than 100 countries, including Japan, the National Police Force has said. https://www. japantimes.co.jp/news/2026/09/ 19/japan/crime-legal/north-korean-hackers-crypto-thefts-japan/?utm_medium=Social&utm_source=mastodon # japan # crimelegal #…
2 more of the top 3 · 4 posts in this stretch
-
So, they can use that against vulnerable people, because they’re looking for work, to do heinous things to the government for money?
-
B
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea. https://www. bleepingcomputer.com/news/secu…
-
-
2
PCMag details FBI alert figures on infected PCs
PCMag's coverage of the FBI alert specifies that WaterPlum exploited at least 30,000 PCs in over 100 countries, primarily targeting web designers, engineers, and cryptocurrency, blockchain and Web3 specialists.
“From around December 2025 through July 2026, WaterPlum exploited at least 30,000 PCs in over 100 countries (including Japan and the United States)…”
— FBI advisory -
FBI: This North Korean Group Infected 30,000 PCs To Steal Crypto https://www. pcmag.com/news/fbi-this-north- korean-group-infected-30000-pcs-to-steal-crypto?utm_source=flipboard&utm_medium=activitypub Posted into Software News and Reviews @ software-news-and-reviews-PCMag
1 more of the top 2 · 2 posts in this stretch
-
P
A suspected North Korean hacking group has been blamed for infecting 30,000 PCs across the globe in an effort to steal cryptocurrency from unsuspecting users. https://www. pcmag.com/news/fbi-this-north- korean-group-infected-30000-pcs-to-steal-crypto
-
-
1
FBI, Pentagon and allied police issue joint WaterPlum advisory
The FBI and Defense Department, with Japan's National Police Agency and agencies in Australia and Germany, published an advisory saying WaterPlum infected at least 30,000 devices in 100+ countries between December 2025 and July 2026, stealing funds or credentials from about 7,000 crypto wallets and more than $10.5 million total.
“victimizing individual IT professionals in Japan, the United States, Europe, and other countries…”
— FBI advisory -
first by Yahoo, 4d ago · also Tom's Hardware
-
-
background
Incident responders uncover related $12M crypto theft campaign — In April, security incident responders found a similar campaign using the same malware strains, in which hackers stole up to $12 million from blockchain developers contacted by fake recruiters on LinkedIn.
-
background
WaterPlum begins mass infection campaign — Starting around December 2025, WaterPlum hackers began infecting devices belonging to web designers, engineers and cryptocurrency specialists by posing as recruiters for AI or blockchain companies and instructing applicants to download malicious files.
Also covered reported alongside — the timeline has no entry for these yet
-
first by inc.com, 4d ago · also BleepingComputer, Quartz
2 more headlines
- North Korean WaterPlum hackers infected 30,000 devices worldwide BleepingComputer · 4d ago
- North Korean hackers infected 30,000 devices worldwide by posing as tech recruiters Quartz · 2d ago
-
first by The Record from Recorded Future News, 5d ago · also The Record
and 1 smaller piece
What people are saying 1 voices from 1 site · best of 6 · verbatim
- Sep 22
-
S
# NorthKorea infects thousands of devices worldwide through fake job offers https://www. the-independent.com/tech/secur ity/north-korea-hackers-waterplum-crypto-b3054513.html