Japan, US, Australia and Germany Attribute Crypto Thefts to North Korea’s WaterPlum Group
Japan’s National Police Agency joined the United States, Australia and Germany on September 18 to publicly attribute a sweeping campaign of crypto thefts to WaterPlum, a North Korea-backed cy
A
AnonymousCryptoCompass newsroom
September 19, 2026
3 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for bitcoin coverage.
Japan’s National Police Agency joined the United States, Australia and Germany on September 18 to publicly attribute a sweeping campaign of crypto thefts to WaterPlum, a North Korea-backed cyber group also known as Contagious Interview. The joint advisory says the group infected at least 30,000 machines across more than 100 countries, stole around 7,000 crypto wallet records and moved at least about 1.7 billion yen in digital assets, according to the official announcement.
A Coordinated Four-Nation Attribution
The statement was issued jointly by Japan, the United States, Australia and Germany, and places WaterPlum under the command of the 313th General Bureau of the Korean Workers’ Party Central Committee’s Military Industry Department. The NPA said the findings came from information supplied by private companies and from investigations by its Kanto Regional Police Bureau cyber division and prefectural police. By naming the group and its command structure, the four governments are warning IT engineers and companies worldwide to harden their defenses against a campaign that has run for months.
The Scale of the WaterPlum Campaign
WaterPlum targets IT engineers with fake job offers, a technique the advisory ties to the Contagious Interview scheme, to deliver malware and drain crypto wallets. The NPA estimates at least 30,000 machines were infected across more than 100 countries and regions including Japan, with around 7,000 wallet records stolen and at least about 1.7 billion yen — roughly $11.5 million — moved in crypto assets. The disclosure fits a longer pattern of North Korean cyber operations that have already compromised 1,640 companies across 57 countries.
Laptop Farms and North Korean IT Workers
The advisory also details how North Korean IT workers earn foreign currency for the regime. Japanese police said they identified for the first time domestic “laptop farms” remotely operated by North Korean IT workers, which sent hundreds of millions of yen overseas, including crypto. A Japanese crypto exchange separately reported receiving job applications from North Korean IT workers for engineer roles and detected the activity during interviews. The warning follows other recent North Korean crypto activity, including Lazarus-linked Bitcoin sales tracked on Hyperliquid.
Why the Attribution Matters
The joint announcement marks a rare, coordinated public naming of a North Korean cyber group by four governments, and it frames crypto theft as a national-security and economic threat rather than isolated crime. For exchanges, wallets and developers, the practical takeaway is to treat unsolicited job offers and recruitment messages as a security risk, and to screen remote hires carefully. The NPA urged IT engineers and private companies to review the advisory and strengthen their security measures.
The Bank of Japan raised its key rate by 25 basis points to 1.25 percent on Friday, September 18, 2026. That is the highest level in 31 years. Two days earlier, the US Federal Reserve had lif
If your hardware wallet is gone, your coins are almost never gone. Your holdings are still on the blockchain, exactly where they always were. The device never stored them; it only kept the ke
Solana climbed to its highest price in seven months on September 19, with SOL trading at $112.28 after a 10.75% single-day gain that pushed the token above the $110 level for the first time s