International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data
At a glance
- Severity
- Medium
- Used in attacks
- No flaws named
- Industries
- Government
- Reported by
- 1 outlet
Get our latest cybersecurity news first on Google.
North Korean hackers are infiltrating tens of thousands of job seekers’ computer networks by posing as prospective employers, such as artificial intelligence firms, to steal sensitive information and millions of dollars worth of cryptocurrency, U.S. and allied governments warned Friday.
The security agencies behind the alert, attributed the group, known as WaterPlum or Contagious Interview, as operating under the 313 General Bureau of the Munitions Industry Department subordinate to the Central Committee of the Workers Party of Korea. The efforts dovetail with those of North Korean IT workers.
“WaterPlum actors pose as prospective employers to target software developers and IT professionals worldwide under the pretext of attractive job opportunities,” the agencies wrote. “They often impersonate legitimate Artificial Intelligence (AI), cryptocurrency, or Non-Fungible Token (NFT) companies and have also used recruiting services.”
Additionally, “Some WaterPlum actors also operate as North Korean IT workers performing web system design and development tasks on corporate web systems for clients,” read the alert from agencies in Japan, Australia and Germany, alongside the FBI and the Department of Defense’s Cyber Crime Center.
They’ve used the stolen information to fuel other operations, and the overlap between WaterPlum and North Korean IT workers is substantial, the agencies said.
“WaterPlum actors and North Korean IT Workers used the same IP addresses when accessing laptop farms, using cloud-sourcing services, and applying for positions at the Japanese cryptocurrency exchange,” they wrote.
Collectively, WaterPlum has infected more than 30,000 devices in more than 100 countries, targeting IT professionals in Japan, the United States, Europe and other nations. Its operations have transferred the equivalent of nearly $11 million of cryptocurrency from over 7,000 crypto wallets to North Korea, according to the alert.
The law enforcement agencies said they have had some success tackling the group, but are seeking further cooperation and released details in the alert about WaterPlum’s tactics, techniques and procedures.
“For the first time in Japan, authorities successfully identified, investigated, and dismantled a ‘laptop farm’ operated by an enabler in Japan,” the alert reads. “Japanese authorities obtained evidence this cyber actor group transferred several hundred million Japanese yen in cryptocurrency to foreign locations outside of Japan. The FBI continues to identify and prosecute US-based actors providing illicit facilitation services to North Korean IT workers.”
The warning comes as the Multilateral Sanctions Monitoring Team, an international panel overseeing UN sanctions against North Korea, released a report exposing thousands of North Korean nationals employed in industries around the world.
Latest Podcasts
Government
CISA promotes a fresh way to deter cyberattackers: Lie to them
What’s next for CISA's CDM program that gives cybersecurity tools to federal agencies
Supreme Court denies Trump request to allow USPS mail ballot changes
Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal
Technology
Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems
European parliament members call for slowdown of Serbia’s EU entry over spyware use
The G7 tells industry to hurry up and prep for post-quantum encryption
FCC proposes public scorecard to rate telecoms on anti-robocall efforts
Threats
Cisco alerts customers to second actively exploited zero-day in as many days
Cisco warns customers of actively exploited zero-day in email gateways
Five alleged leaders of Black Axe’s operations in South Africa extradited to US
GitLab's critical flaw is already drawing internet-wide probes
Policy
Reproduced in full under licence from CyberScoop. © CyberScoop. Written by Tim Starks.
Coverage
One outlet has carried this so far.
2026-09-18 15:48 UTC
Related stories
- TigerByte Cyber Emerges From Stealth With $3 Million in Funding
SecurityWeek · 2026-09-19
- North Korean WaterPlum hackers infected 30,000 devices worldwide
BleepingComputer · 2026-09-19
- Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
The Hacker News · 2026-09-19
- SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
The Hacker News · 2026-09-19
- Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
The Hacker News · 2026-09-19