Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-19 · updated: 2026-09-19 · tags: [incident, defence] · confidence: high · severity: critical · affected_sectors: [defence] · au_impact: true

The FBI, the US Department of Defense, Japan's National Police Agency, the ACSC and German authorities issued a joint advisory on 18 September attributing the "WaterPlum" campaign — widely tracked as Contagious Interview — to North Korean actors, and for the first time put figures to the intrusion. Between December 2025 and July 2026 the campaign infected at least 30,000 devices in more than 100 countries and stole funds or account credentials from over 7,000 cryptocurrency wallets, transferring 1.7 billion Japanese yen — about US$10.71 million — of cryptocurrency assets to the DPRK. Victims are recruited through social media, online job and gig-work platforms and freelance marketplaces, often under the cover of an AI, cryptocurrency or NFT company, and asked to download and execute files during virtual interviews or coding assignments; the loaders install infostealers and remote-access trojans, and the NPA and FBI assess that WaterPlum actors and some North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department. Japanese police recovered BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle variants from victim devices, dismantled a "laptop farm" operated by an enabler in Japan — the first such case in the country — and found stolen identity documents being reused by other North Korean operatives to obtain employment elsewhere. The advisory names individual IT professionals in Japan, the United States, Europe and other countries as the victim population.

Attribute Detail
Sector Defence
Date 2026-09-19
Source The Record
Reliability Tier 2