NewsLayer.com

Japan, US, Australia and Germany Attribute Crypto Thefts to North Korea’s WaterPlum Group

Japan’s National Police Agency joined the United States, Australia and Germany on September 18 to publicly attribute a sweeping campaign of crypto thefts to WaterPlum, a North Korea-backed cyber group also known as Contagious Interview.…

CryptoRank

Publisher

Sep 19, 2026 at 12:39 AM UTC · 2 min de lectura

Japan, US, Australia and Germany Attribute Crypto Thefts to North Korea’s WaterPlum Group
Image via CryptoRank
Traduciendo…

Japan’s National Police Agency joined the United States, Australia and Germany on September 18 to publicly attribute a sweeping campaign of crypto thefts to WaterPlum, a North Korea-backed cyber group also known as Contagious Interview. The joint advisory says the group infected at least 30,000 machines across more than 100 countries, stole around 7,000 crypto wallet records and moved at least about 1.7 billion yen in digital assets, according to the official announcement.

A Coordinated Four-Nation Attribution

The statement was issued jointly by Japan, the United States, Australia and Germany, and places WaterPlum under the command of the 313th General Bureau of the Korean Workers’ Party Central Committee’s Military Industry Department. The NPA said the findings came from information supplied by private companies and from investigations by its Kanto Regional Police Bureau cyber division and prefectural police. By naming the group and its command structure, the four governments are warning IT engineers and companies worldwide to harden their defenses against a campaign that has run for months.

The Scale of the WaterPlum Campaign

WaterPlum targets IT engineers with fake job offers, a technique the advisory ties to the Contagious Interview scheme, to deliver malware and drain crypto wallets. The NPA estimates at least 30,000 machines were infected across more than 100 countries and regions including Japan, with around 7,000 wallet records stolen and at least about 1.7 billion yen — roughly $11.5 million — moved in crypto assets. The disclosure fits a longer pattern of North Korean cyber operations that have already compromised 1,640 companies across 57 countries.

Article Intelligence

Topics

Sponsored

Ad
House — Advertise on NewsLayer
NewsLayerLearn more

NewsLayer Premium

Unlock deeper intelligence.

Ad-free reading, exclusive research, and real-time onchain insights.

Go Premium