North Korean Hackers Exploit Fake Job Interviews to Infect 30,000 PCs, Steal $10.7M in Crypto
NewsData.io · United States · Sep 21, 2026
North Korean-linked threat actors operating as 'WaterPlum' have weaponized the recruiting process by posing as employers on job boards, gig platforms, and social networks to trick software developers into running malicious code during fake technical interviews. The campaign — active across more than 100 countries from December 2025 through July 2026 — compromised at least 30,000 machines and drained over $10.7 million from roughly 7,000 cryptocurrency wallets. Beyond financial theft, compromised developer credentials can expose employers and clients to network intrusion and intellectual-property theft, making this a direct operational risk for staffing firms and technical recruiters placing contractor talent. Agencies are advised to verify contractor identities rigorously and treat anomalous recruitment details — mismatched skills, unusual payment requests, AI-assisted video calls — as security red flags, not merely hiring irregularities.
Related stories
California Governor Gavin Newsom signed a suite of new workplace AI laws prohibiting employers from relying solely on AI to fire workers, using AI to…
The EEOC under the Trump administration has pursued two recent enforcement actions reversing Biden-era positions on gender identity in the workplace…
Defense Secretary Pete Hegseth has ordered a halt to civilian tenured faculty appointments at U.S…
Arizona State Prison–Marana, operated by Management and Training Corporation (MTC), is set to reopen as an ICE immigration detention facility with…