North Korean Hackers Hit 30,000 Devices in Fake Tech Recruiter Scheme
NewsData.io · United States · Sep 19, 2026
The FBI's Honolulu field office and international partners have issued a joint advisory warning that North Korean cyber group WaterPlum (Contagious Interview) is impersonating legitimate tech recruiters on hiring platforms to target IT professionals in the U.S., Japan, and Europe. The campaign has infected over 30,000 devices across 100+ countries, stolen credentials from 7,000 crypto wallets, and netted approximately $10.71 million. Separately, North Korean IT workers continue to use fabricated identities to land remote tech jobs — a tactic that directly implicates recruiting and staffing platforms as infiltration vectors. Staffing firms and tech recruiters should review candidate verification protocols and flag unsolicited developer outreach originating from AI, NFT, or crypto-adjacent personas.
Related stories
The FBI is investigating a claimed breach of its public recruiting portal, FBIJobs.gov, after cybercriminal group ShinyHunters alleged it stole 2–3…
FBI Drops Automatic Hiring Ban for Applicants with Past Prostitution Encounters Amid Recruitment Challenges
Medium impactThe FBI is moving away from a categorical disqualification of applicants who have had sexual encounters with prostitutes, opting instead for a more…
The FBI is investigating how a North Korean national was hired to work for an unnamed U.S…
California Governor Gavin Newsom signed a suite of new workplace AI laws prohibiting employers from relying solely on AI to fire workers, using AI to…