LAW enforcement and intelligence agencies from Japan, the United States, Australia and Germany have attributed a long-running fake recruitment operation to a North Korean group known as WaterPlum, also called Contagious Interview. According to their joint advisory, the group impersonated AI, cryptocurrency and NFT companies, and also used legitimate recruitment services to approach software developers and other IT specialists.
From December 2025 to July 2026, it infected at least 30,000 devices in more than 100 countries, primarily targeting web designers, engineers and cryptocurrency, blockchain and web3 specialists. More than 7,000 cryptocurrency wallets reportedly lost funds or credentials, while the agencies estimate that about $10.71 million reached North Korea.
The operation also overlaps with North Korea’s wider IT-worker scheme. Japan’s National Police Agency and the FBI assess that WaterPlum operators and some North Korean IT workers answer to the 313 General Bureau of the Munitions Industry Department. Laptop farms, often operated from an accomplice’s home, allow workers in North Korea to control devices and conceal their location while taking paid jobs.
Japan has confirmed its first dismantling of such a facility, where authorities say several hundred million Japanese yen in cryptocurrency was transferred overseas. The FBI is separately identifying and prosecuting US-based facilitators.
The advisory describes warning signs including implausible CVs, weak language skills, reluctance to meet in person, cryptocurrency payment requests, second-screen prompting and unexplained video problems. WaterPlum operators also allegedly used AI face-swapping during interviews and translation or text-to-speech tools. Compromised developers could provide access to employers’ networks, while stolen information has been used for extortion, personal-data theft and access to trade secrets.