Advisory Ties Hacking Crew to North Korea Scheme
A seven‑agency advisory has tied the WaterPlum hacking crew to Pyongyang’s remote IT worker scheme, revealing that the same bureau is behind a series of fake job interviews that drained $11 million from 7,000 crypto wallets.
The advisory does not detail the exact recruitment method, but the operation appears to have lured victims with counterfeit job offers. Once engaged, the victims were instructed to transfer funds, leading to the collective loss of roughly $1,571 per wallet on average.
Financial Impact and Victim Profile
With 7,000 wallets compromised, the total theft reached $11 million. The scale of the breach underscores how low‑cost, high‑volume scams can generate substantial revenue for state‑linked cyber groups.
Although the advisory does not name the specific wallets, the uniform pattern of fake interviews suggests a coordinated effort rather than isolated phishing attempts.
Broader Implications for Crypto Security
The incident highlights the growing sophistication of North Korean cyber‑crime tactics, which now blend social engineering with traditional hacking tools. Regulators and industry participants are urged to tighten verification processes for remote IT positions and to monitor unusual fund movements linked to recruitment campaigns.
The case also reinforces the need for users to treat unsolicited job offers with skepticism, especially when crypto transfers are involved. Prompt reporting and collaboration with law‑enforcement agencies remain critical to mitigating future losses.
Market context
Market data reflects conditions at publication time and is not updated in real time.
Data captured at: Sep 24, 2026 06:19 (Tehran)
Likely market impact
| Segment | Outlook |
|---|---|
| Bitcoin | ▼ Negative |
| Ethereum | ● Neutral |
| Altcoins | ▼ Negative |
| Short term | ▼ Negative |
| Long term | ● Neutral |
Spot prices at publication
Fear & Greed Index
Source: Decrypt