North Korean hackers steal over ten million dollars using fake job offers.

The joint warning was issued under a “public attribution” framework, through which governments publicly identify suspected cyberattackers or state-linked organizations in an effort to expose, condemn and deter further attacks.
Japanese authorities said North Korean IT workers operating from North Korea, China and Russia used false identities to obtain remote programming and other jobs; hundreds of millions of yen had been transferred to North Korea through these schemes in recent years.
Investigators found that the malware could give the hackers remote control of computers in Japan, which were then used in operations to generate foreign currency.
North Korean hackers stole at least $10.7 million in cryptocurrency through a massive fake job scheme between December 2025 and July 2026. Bleeping Computer reported that the WaterPlum hacking group compromised over 30,000 devices across 100 countries by posing as recruiters and companies in artificial intelligence, cryptocurrency, and NFT sectors.
The attackers targeted software developers and IT professionals with fraudulent coding tests and interview files that installed malware on their computers. Japan Times reported that investigators traced the operation to Bureau 313, a North Korean government unit that uses remote workers and false identities to earn foreign currency for the regime.
WaterPlum posed as legitimate tech companies and job recruiters to lure victims. Crypto Intelligence reported that hackers sent fake coding tests and interview files that contained malware. Once developers opened these files, the malware infected their computers and gave attackers remote access.
The attackers then stole cryptocurrency wallet credentials from the compromised devices. The campaign affected more than 7,000 wallets worldwide. Grafa noted that victims worked across software development, IT, and other technical sectors in over 100 countries and regions.
Investigators linked WaterPlum to Bureau 313 of North Korea's Munitions Industry Department. Japan Times reported that North Korean IT workers operated from North Korea, China, and Russia using false identities to obtain legitimate remote programming jobs. These workers earned foreign currency that was sent back to the regime.
Hundreds of millions of yen have been transferred to North Korea through these remote worker schemes in recent years. The hackers also used compromised Japanese computers to conduct further cyberattacks and generate additional foreign currency for the government.
Crypto News reported that Japan's National Police Agency, along with the United States, Australia, and Germany, issued a joint public warning attributing the attacks to North Korea. This 'public attribution' framework aims to expose state-linked cyberattackers and deter future attacks.
The coordinated statement marked a rare moment of international cooperation in naming a cyberattacker. By publicly identifying WaterPlum and its government ties, the agencies signaled that such operations carry consequences and attempted to raise awareness among tech workers about the scam tactics.
Publishers
22
Articles
21
Reach
43