Japan’s National Police Agency joined the United States, Australia and Germany on September 18 to publicly attribute a sweeping campaign of crypto thefts to WaterPlum, a North Korea-backed cyber group also known as Contagious Interview. The joint advisory says the group infected at least 30,000 machines across more than 100 countries, stole around 7,000 crypto wallet records and moved at least about 1.7 billion yen in digital assets, according to the official announcement .
A Coordinated Four-Nation Attribution
The statement was issued jointly by Japan, the United States, Australia and Germany, and places WaterPlum under the command of the 313th General Bureau of the Korean Workers’ Party Central Committee’s Military Industry Department. The NPA said the findings came from information supplied by private companies and from investigations by its Kanto Regional Police Bureau cyber division and prefectural police. By naming the group and its command structure, the four governments are warning IT engineers and companies worldwide to harden their defenses against a campaign that has run for months.
The Scale of the WaterPlum Campaign
WaterPlum targets IT engineers with fake job offers, a technique the advisory ties to the Contagious Interview scheme, to deliver malware and drain crypto wallets. The NPA estimates at least 30,000 machines were infected across more than 100 countries and regions including Japan, with around 7,000 wallet records stolen and at least about 1.7 billion yen — roughly $11.5 million — moved in crypto assets. The disclosure fits a longer pattern of North Korean cyber operations that have already compromised 1,640 companies across 57 countries .
Laptop Farms and North Korean IT Workers
The advisory also details how North Korean IT workers earn foreign currency for the regime. Japanese police said they identified for the first time domestic “laptop farms” remotely operated by North Korean IT workers, which sent hundreds of millions of yen overseas, including crypto. A Japanese crypto exchange separately reported receiving job applications from North Korean IT workers for engineer roles and detected the activity during interviews. The warning follows other recent North Korean crypto activity, including Lazarus-linked Bitcoin sales tracked on Hyperliquid .
Why the Attribution Matters
The joint announcement marks a rare, coordinated public naming of a North Korean cyber group by four governments, and it frames crypto theft as a national-security and economic threat rather than isolated crime. For exchanges, wallets and developers, the practical takeaway is to treat unsolicited job offers and recruitment messages as a security risk, and to screen remote hires carefully. The NPA urged IT engineers and private companies to review the advisory and strengthen their security measures.


