North Korea Hackers Compromise 30,000 Computers and 7,000 Crypto Wallets

North Korea-linked hackers infected 30,000+ devices, compromised 7,000+ crypto wallets and stole at least $10.7 million, Japan and the US say.

18/09/2026 15:5610 min read

More than 30,000 computers across over 100 countries were infected by a hacking group tied to North Korea. Data from over 7,000 cryptocurrency wallets was also taken, Japan's National Police Agency and the FBI announced on Friday.

Between December 2025 and July 2026, the group's wallets received at least $10.71 million in digital currencies. The agencies refer to the group as WaterPlum, also known as Contagious Interview.

How Phony Recruiters Accessed 7,000 Crypto Wallets

WaterPlum presents itself as a recruiter for firms involved in artificial intelligence, cryptocurrency and non-fungible tokens. The group contacts developers through social media, job boards and freelance platforms.

“WaterPlum actors pose as prospective employers to target software developers and IT professionals worldwide under the pretext of attractive job opportunities,” Japan’s National Police Agency and the FBI said in the joint advisory.

Candidates are then asked to take a technical interview or complete a coding task. The group instructs them to download files from code-sharing websites. The excuse given is a broken video call or the test itself.

Those files contain malware. The software searches for browser passwords, screenshots and keystrokes. It also grabs the private keys that control a crypto wallet, the software individuals use to store digital money.

BeInCrypto reported in August about a researcher who spent 22 months inside the group’s servers. He identified 1,640 victims across 57 countries. Friday’s official figure is approximately 18 times higher.

Japan Shuts Down Its First Laptop Farm

Authorities also took down the nation’s first known laptop farm. Local aides kept the computers in their homes. North Korean workers based abroad controlled them remotely and pretended to be Japanese residents to secure freelance contracts.

Those workers sent several hundred million yen worth of cryptocurrency overseas, according to investigators. The same internet addresses connected the farm to the hackers.

“The NPA and the FBI assess both WaterPlum cyber actors and some North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department subordinate to the Central Committee of the Workers Party of Korea.”

In May 2025, one suspected North Korean used a stolen resume to apply for an engineering role at Japanese exchange bitFlyer. Interviewers noticed he refused to relocate and asked for payment in crypto. He appeared to read answers from another screen and was not hired.

Earlier operations used deepfake recruitment video calls to target senior staff. Investigators now advise engineers to run recruiter code inside a sandbox, a sealed test area isolated from actual files.

Share to

Disclaimer: this article comes from third-party media and is provided for reference only. It does not constitute investment advice. Crypto and other financial products carry significant price volatility risk, so please make your own decisions carefully.

Related articles