North Korean Hackers Drain $10.71M in Crypto via Fake Job Interviews
A coordinated cyber-espionage campaign linked to North Korea compromised more than 30,000 devices across over 100 countries and drained at least $10.71 million from more than 7,000 cryptocurrency wallets, according to a joint advisory issued by law enforcement agencies in the United States, Japan, Australia, and Germany.
The operation, tracked internationally as WaterPlum and also known as Contagious Interview, used fake job interviews and bogus coding tests to lure web designers, engineers, and blockchain specialists into downloading malware. The stolen funds ultimately flowed to Pyongyang, authorities said.
Japan's National Police Agency led the analysis behind the advisory. The FBI and cybersecurity agencies from the other participating countries contributed intelligence gathered over months of investigation.
The campaign ran from late 2025 through July 2026, according to investigators. Attackers posed as recruiters from legitimate-sounding AI, cryptocurrency, and NFT companies, approaching targets through social media, job boards, freelance platforms, and gig-work sites.