North Korean Hackers Exploit Fake Job Interviews to Infect 30,000 PCs, Steal $10.7M in Crypto

NewsData.io · United States · Sep 21, 2026

North Korean-linked threat actors operating as 'WaterPlum' have weaponized the recruiting process by posing as employers on job boards, gig platforms, and social networks to trick software developers into running malicious code during fake technical interviews. The campaign — active across more than 100 countries from December 2025 through July 2026 — compromised at least 30,000 machines and drained over $10.7 million from roughly 7,000 cryptocurrency wallets. Beyond financial theft, compromised developer credentials can expose employers and clients to network intrusion and intellectual-property theft, making this a direct operational risk for staffing firms and technical recruiters placing contractor talent. Agencies are advised to verify contractor identities rigorously and treat anomalous recruitment details — mismatched skills, unusual payment requests, AI-assisted video calls — as security red flags, not merely hiring irregularities.

IC3cybersecurityrecruiting fraudtechnology staffingfreelance platformscryptocurrency

Related stories