Seven agencies, one alert: what the 18 September joint notice on North Korea's 'WaterPlum' says about 30,000 compromised PCs, 7,000 crypto wallets and fake job interviews
On 18 September 2026 Japan's National Police Agency and National Cybersecurity Office, with the FBI, the US Department of Defense Cyber Crime Center, Australia's ACSC and Germany's BND and BfV, published a joint alert on the North Korean actor group called WaterPlum, also known as Contagious Interview. The alert states that from around December 2025 to July 2026 the group compromised at least 30,000 PCs in over 100 countries and moved funds or credentials from over 7,000 cryptocurrency wallets, at least 1.7 billion yen. This article documents the alert's figures, the tactics it names and its countermeasures.

A security alert signed by seven agencies from four countries is a document with numbers in it, and the numbers are what make it worth reading rather than summarising. On 18 September 2026 the National Police Agency of Japan published, in English, an "Alert to Countries, Companies, and Other Entities Regarding North Korean 'WaterPlum' Cyber Actor Group and North Korean IT Workers." The alert is co-issued with Japan's National Cybersecurity Office, the US Federal Bureau of Investigation, the US Department of Defense Cyber Crime Center, the Australian Signals Directorate's Australian Cyber Security Centre, and Germany's Federal Intelligence Service and Federal Office for the Protection of the Constitution. Jiji Press reported the NPA's statement the same day. This article records what the alert states, in its own terms, and where it stops.
🎧 Audio edition — the full article read aloud, 8 minutes, MP3: north-korea-waterplum-joint-alert-2026-09-audio-EN.mp3
The scale, as the NPA states it
The first section of the alert is titled "NPA Information on Scale of Malicious Activity." It gives a period and four figures. The period: "From around December 2025 through July 2026." The figures: the group compromised "at least 30,000 PCs in over 100 countries"; the targets were, in the alert's description, web designers and cryptocurrency specialists; the attackers "transferred funds or account credentials from over 7,000 cryptocurrency wallets"; and the amount stolen was "at least 1.7 billion JPY (10.71 million USD)."
Each of these is a floor, not an estimate of the total: "at least" and "over" are the alert's own qualifiers. The alert does not state how the 7,000 wallets are distributed across the 100 countries, or how the yen figure was computed from assets in different currencies. We do not fill those gaps.
The method: an interview that installs software
The alert's account of the method is specific enough to be recognisable. The actors pose as employers on social media and job platforms. Candidates are invited to what appears to be a technical interview, and during that interview they are required to download files. The files are malicious. In the alert's framing, the victim is not tricked into visiting a website; the victim is asked, as a job applicant, to run code as part of a test, and does.
This is why the group's other name is "Contagious Interview," and why the target profile is web designers and cryptocurrency specialists: these are people for whom downloading a project and running it is an ordinary step in a hiring process.
The malware named in the alert
The alert names five malware families: BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle. Of the last it says: "StoatWaffle is a modular Node.js malware family combining a malware loader, credential harvesting components." Remote-access trojans establish persistence on the compromised machine. The alert also describes an enabling layer: people who operate "laptop farms," managing devices remotely on the actors' behalf, which connects the WaterPlum activity to the alert's second subject, North Korean IT workers who obtain remote employment under false identities.
The alert does not publish indicators of compromise in the section we read, and this article does not reconstruct them from other sources.
The countermeasures the agencies recommend
The alert closes with practical guidance, and it is written for the people most likely to be targeted rather than for security teams. The recommendations, as listed: avoid executing untrusted code, and use a sandbox for unknown scripts; be cautious of suspicious command strings, and the alert names three, "curl," "base64" and "-enc"; disconnect an infected device immediately; reset the operating system completely after a compromise rather than cleaning selectively; deploy endpoint detection and response tools; and open Visual Studio Code projects only in "Restricted Mode," the editor's setting that prevents a downloaded project from running code automatically on open.
The last recommendation is the most concrete, because it addresses the exact step the attack depends on: a candidate opens a supplied project in a code editor, and the editor, if not restricted, executes what the project tells it to.
Why this document is relevant to a crypto reader
Wallet theft by malware is not a market event, and this article does not connect the alert to any price. The alert matters for a different reason. It is an official, multi-agency statement that at least 7,000 wallets lost funds or credentials in eight months through one method, and that the method selects its victims by their profession rather than by their wallet balance. Self-custody moves the whole burden of endpoint security onto the holder. A private key on a machine that has just run an "interview" project is exposed to exactly the method the alert describes.
Readers who want the basics of wallet types, seed phrases and what a compromised endpoint can and cannot reach will find them in the Kripto Akadémia. Our Market Observation page carries sourced, timestamped market data and nothing else. Longer readings of official documents are collected in The Analyst Room, and the people behind these readings are introduced on the About page.
What the alert does not say
It does not attribute the 1.7 billion yen to particular exchanges or particular assets. It does not state whether any funds were recovered. It gives a period that ends in July 2026, and it does not say whether the campaign continues in the same form after that date, only that the agencies are issuing the alert now. And it names a group and a state, but the evidentiary basis for the attribution is not set out in the public alert; the seven agencies state it as their finding.
Sources
National Police Agency of Japan, with the National Cybersecurity Office of Japan, the FBI, the US Department of Defense Cyber Crime Center, ASD's ACSC, BND and BfV, "Alert to Countries, Companies, and Other Entities Regarding North Korean 'WaterPlum' Cyber Actor Group and North Korean IT Workers," 18 September 2026, cyber.go.jp/pdf/news/press/alert_en_wp.pdf. Jiji Press via nippon.com, "N. Korean Hacker Group behind Crypto Thefts across 100 Countries," Tokyo, 18 September 2026 (secondary). CyberScoop, "International security agencies warn about North Korean hackers targeting job seekers" (secondary).
Educational content. Not investment advice. This article describes an official security alert; it contains no instruction to buy, sell or hold any asset.
Continue on DAI
Explore Topics
Written by
DAI Research Desk
Content creator and writer sharing insights and stories.


