North Korea’s WaterPlum hackers stole $10.7M in crypto, Japan and allies say

Analysis
The joint advisory marks a shift from private threat research to formal state attribution, with seven agencies naming WaterPlum and tying the operation to North Korea's 313 General Bureau of the Munitions Industry Department. The confirmed figure is roughly $10.71 million diverted, but the strategic significance lies in the method: fake recruiter personas targeting developers at AI, crypto, and NFT firms, which turns hiring pipelines into an attack surface for the whole industry. Because attribution is now public and multilateral, expect sanctions designations, developer-targeted security guidance, and pressure on recruitment platforms and wallets to flag these lures. The open questions are whether other agencies add their own attributions, whether stolen funds are traced and frozen, and whether the same tradecraft resurfaces under new aliases.

If you have any feedback or questions about this content, please contact us at crypto.news@kcex.com

The post North Korea’s WaterPlum hackers stole $10.7M in crypto, Japan and allies say appeared on BitcoinEthereumNews.com.

The National Police Agency of Japan, alongside the FBI and security agencies in Australia and Germany, have put a name to a North Korean group that pretended to be tech recruiters while stealing cryptocurrency from IT professionals globally. They diverted 1.7 billion yen (about $10.71 million) worth of assets to North Korea. The crew is called WaterPlum but uses “Contagious Interview” as an alias, and they targeted victims all over the globe, including Japan, the US, Europe, and beyond, according to a joint advisory the seven agencies released on Friday, September 18, 2026.  Seven agencies, one public attribution  The advisory has on it the names of seven agencies: Japan’s National Cybersecurity Office, the NPA, the FBI, the Department of Defense Cyber Crime Center, Australia’s ASD Cyber Security Centre, as well as Germany’s BND and BfV.  The announcement was made under a “public attribution” framework, a move aimed at deterring future attacks by exposing the state or group behind a malicious cyber-attack.   Based on the assessment of the NPA and FBI, WaterPlum’s hackers, alongside a group of North Korean IT workers, are under the command of the 313 General Bureau of the Munitions Industry Department, a unit under the auspices of the Central Committee of the Workers’ Party of Korea. That means the operation was part of a larger plan Pyongyang used to fund its weapons program. US intelligence agencies have leveled the same charge in the past during an episode of North Korean crypto theft, a charge the North Korean regime denies vehemently.  How North Korea’s fake job scheme worked The scheme worked this way: the hackers pretended to be hiring managers at AI firms, crypto ventures, and NFT startups, offering irresistible job offers to software developers. Applicants would then sit for technical interviews or complete coding assignments before being…

Disclaimer: The articles reposted on this website are sourced from public platforms and are for reference only. These articles do not represent the views or opinions of KCEX. All copyrights belong to the original authors. If you believe that any reposted article infringes upon the rights of a third party, please contact crypto.news@kcex.com for removal. KCEX makes no representations or warranties regarding the timeliness, accuracy, or completeness of reposted articles, and shall not be liable for any actions or decisions made based on such content. Reposted materials are for informational purposes only and do not constitute advice, endorsement, or basis for any commercial, financial, legal, and/or tax decisions.