Threat Intelligence
Japan Reports North Korean Hackers Stole Seven Thousand Crypto Wallet Records
According to reporting from crypto.news on September 18, 2026, Japan's National Police Agency disclosed that a North Korea-linked hacking group named WaterPlum compromised more than 30,000 devices across over 100 countries and regions. The campaign targeted developers through fraudulent recruitment schemes and harvested information from over 7,000 cryptocurrency wallets, while investigators also noted an attempted infiltration at exchange bitFlyer. These claims are not officially confirmed.

Global Campaign Overview and Multi-Agency Investigation
Recent intelligence disclosures from law enforcement authorities indicate a widespread cyber espionage and financial theft operation orchestrated by a threat collective identified as WaterPlum. The reporting outlines that this group successfully infected tens of thousands of individual computers across numerous international jurisdictions, extending their reach into more than one hundred countries and territories. Investigators from multiple global agencies collaborated to trace the digital footprints of these malicious activities, establishing connections between the infrastructure utilized in the attacks and state-backed entities operating from foreign territories. The sheer scale of the compromised hardware underscores the systemic vulnerabilities present in contemporary remote development workflows and collaborative engineering environments.
Furthermore, the collaborative analysis conducted by the Japanese authorities alongside international partners revealed specific operational mechanisms tied to foreign currency generation schemes. The published findings suggest that these activities form part of a broader strategy designed to bypass international economic restrictions through digital asset accumulation and remote employment fraud. While these assertions provide valuable visibility into sophisticated threat actor methodologies, external observers must recognize that the details originate from law enforcement assessments rather than conclusive judicial determinations. Industry participants are advised to analyze these operational patterns carefully to enhance their internal security posture against similarly structured cyber intrusions.
Exploitation of Developer Recruitment and Malicious Tooling
The reported attack vector heavily relied on social engineering campaigns targeting software engineers, web designers, and blockchain developers through fake employment opportunities. Attackers posed as legitimate artificial intelligence, cryptocurrency, and digital asset enterprises to lure unsuspecting professionals into downloading malicious code repositories. During technical interviews and coding assessments, candidates were instructed to execute specific software programs or retrieve collaborative development files that concealed advanced information-stealing malware. This calculated approach bypassed traditional perimeter defenses by exploiting the inherent trust developers place in standard recruitment processes and collaborative coding platforms.
Once installed on a target device, the deployed malware families extracted sensitive user credentials, browser data, clipboard contents, and crucially, cryptocurrency wallet private keys and seed phrases. The unauthorized access allowed operators to continuously monitor affected systems, execute lateral movements, and drain digital assets into designated holding addresses. Security researchers have repeatedly warned about the proliferation of these deceptive hiring practices within the technology sector, noting that standard background checks often fail to detect sophisticated remote identity masking. Organizations operating within the Web3 ecosystem face heightened exposure due to the decentralized nature of their engineering teams and reliance on freelance contractors.
Domestic Laptop Farms and Remote Workforce Deception
Japanese investigators reported uncovering and dismantling a domestic laptop farm operation that enabled overseas operatives to remotely manage employment contracts while masking their geographic origins. Local facilitators maintained active computers within their residences, allowing remote workers to interface with domestic and international crowdsourcing platforms as if they were physically present. This setup facilitated the evasion of standard geographic verification measures implemented by technology companies seeking to hire verified domestic talent. The proceeds generated through these fraudulent contracts were subsequently routed through complex financial networks, including cryptocurrency transfers designed to obscure the final destination of the funds.
Similar operational structures have faced judicial scrutiny in multiple international jurisdictions, highlighting the global scale of remote employment fraud linked to state-sponsored actors. Facilitators who maintain these proxy devices often assist in laundering digital assets and managing localized bank accounts to bypass regulatory controls. Law enforcement agencies continue to target these intermediary networks through asset seizures and forfeiture actions aimed at disrupting the financial incentives driving the recruitment schemes. Corporations are consequently urged to implement rigorous device posture checks and verify that employee network locations align with declared residential addresses to mitigate similar threats.
Targeting of Crypto Exchanges and Mitigation Measures
The reported investigation highlighted a specific incident involving an attempted infiltration at cryptocurrency exchange bitFlyer, where a suspicious applicant submitted fraudulent credentials for an engineering role. The candidate utilized various proxy services and virtual private networks to disguise their connection while interacting with the platform's recruitment portal. During the remote interview process, the applicant exhibited behavioral anomalies, including evasive answers to technical inquiries and background audio interference, which prompted platform security personnel to halt the hiring process. Security teams at other prominent digital asset exchanges have reported encountering comparable tactics, emphasizing the persistent nature of targeted recruitment attempts against critical infrastructure providers.
In response to these findings, industry regulators and law enforcement bodies have issued comprehensive guidance advising digital asset firms to strengthen their internal hiring protocols. Recommended countermeasures include conducting mandatory video verifications with high-fidelity camera settings, performing rigorous technical cross-examinations, and cross-referencing applicant metadata against known threat intelligence databases. Exchanges and Web3 protocols must treat human resources as a critical cyber defense perimeter rather than a purely administrative function. By adopting these enhanced defensive postures, organizations can significantly reduce the likelihood of unauthorized personnel gaining access to proprietary codebases and production systems.
Conclusion and Reported Security Findings
In conclusion, the reporting from international law enforcement agencies establishes that the WaterPlum threat group and associated operatives have engaged in extensive cyberattacks and fraudulent recruitment schemes affecting thousands of cryptocurrency wallets and device owners globally. While these findings—including the specific involvement of North Korean state-linked entities and the scale of the compromised assets—remain not officially confirmed by independent judicial adjudications, they underscore severe vulnerabilities within remote developer onboarding. The primary entities affected include software developers, Web3 organizations, and prominent cryptocurrency exchanges such as bitFlyer that face targeted infiltration attempts.
Going forward, what changes now is the immediate adoption of heightened verification standards across the digital asset industry, shifting recruitment security into a frontline defensive priority. The next action for all crypto-exchanges, blockchain foundations, and technology employers is to conduct an immediate audit of existing remote contractor credentials, scrutinize proxy usage during hiring, and implement robust endpoint protection on all developer workstations. Stakeholders must carefully distinguish between established law enforcement observations and unverified operational details while maintaining maximum vigilance against ongoing social engineering threats.
Cexvia conclusion
Comprehensive Assessment of Reported Infiltration Risks
Japanese and international law enforcement agencies reported that the WaterPlum hacking collective harvested thousands of digital asset wallet records and deployed sophisticated malware through fake technical interviews and fraudulent recruitment campaigns. This intelligence, which remains not officially confirmed by independent judicial verdicts, impacts software developers and digital asset organizations worldwide who face persistent social engineering threats.
- Risk meaning
- The reported infiltration demonstrates how threat actors leverage legitimate collaboration platforms, code repositories, and remote work environments to compromise sensitive infrastructure and extract private keys.
- User action
- Developers and digital asset entities should immediately audit recruitment pipelines, enforce strict verification protocols for remote contractors, and inspect all downloaded software packages.

