Japan’s National Police Agency (NPA), the FBI, and law enforcement from Australia and Germany have exposed the North Korean-backed cybercrime group WaterPlum. According to officials, from December 2025 through July 2026, the group infected over 30,000 devices across more than 100 countries and regions with malware, stealing data from more than 7,000 crypto wallets.

Fake Job Listings Used to Target IT Pros

The hackers posed as employers, using fake job postings to go after IT specialists. During the application process and phony 'interviews,' victims were delivered malware that let attackers access their devices and swipe crypto wallet data.

Global Scale of the Attack

Law enforcement says WaterPlum operated on a global scale: between 12.2025 and 07.2026, more than 30,000 devices in 100+ countries and regions were compromised. The stolen data affected over 7,000 crypto wallets. This was a data heist—attackers grabbed wallet info, not the actual coins.

Who’s Investigating WaterPlum

Japan’s NPA, the FBI, and authorities from Australia and Germany teamed up to uncover WaterPlum’s operations. The group is linked to North Korea, pointing to a well-organized, social engineering-heavy campaign using fake job offers to lure victims.