FAULT LINES
Signals That Move Strategy
Tech Frontiers · Indo-Pacific · Cyber

North Korean WaterPlum Campaign Steals $10.5M From 7,000 Crypto Wallets Across 100 Countries

The FBI, DoD, Japan's National Police Agency, and law enforcement from Australia and Germany disclosed a North Korean cyber campaign called WaterPlum that infected at least 30,000 devices across 100 countries between December 2025 and July 2026, stealing $10.5 million in cryptocurrency and credentials from approximately 7,000 wallets.
AI synthesis, editor-reviewed · 1 source · September 18, 2026
Photo: The Record (Recorded Future)

North Korea's pivot from targeting individual cryptocurrency holders to embedding operatives inside tech firms signals a maturation of the IT worker scheme from opportunistic fraud to supply-chain infiltration. If WaterPlum victims hired at major blockchain or cloud-infrastructure firms retain access to their employer networks—the stated goal—the next phase is lateral movement into defense-contractor supply chains, which already rely heavily on third-party cloud services and blockchain-based verification systems.

WHY IT MATTERS

The scale and sophistication of WaterPlum exposes a structural gap in tech-sector hiring security that North Korea is weaponizing for dual effect: immediate cryptocurrency theft and long-term corporate network access through hired imposters.

The campaign's targeting of blockchain developers and IT workers at defense-adjacent firms means the threat model has shifted from external intrusion to insider placement—a vector that traditional perimeter defenses do not address. Japanese police disrupted a domestic laptop farm for the first time and traced several hundred million yen flowing out of Japan, suggesting the operation has moved from pure remote fraud to localized infrastructure, which raises the likelihood of law enforcement escalation and potential sanctions against North Korean financial networks.

WHAT THIS DOESN’T TELL US

Has the DoD identified which defense contractors or critical-infrastructure IT teams were among the 30,000 infected devices, or does the 100-country count remain opaque to sector-level attribution?

Sources: The Record (Recorded Future)
LinkedInX

Fault Lines

Strategic intelligence, synthesized daily — with a public track record. Every call graded against what actually happened.

Front page → Get the weekly brief →