In May 2025, a suspected North Korean IT worker applied directly through Japanese cryptocurrency exchange bitFlyer, Inc.’s recruitment form for an engineering position, using a forged résumé and another person’s identity. Investigators later found that the application shared IP addresses with infrastructure used by WaterPlum, the group publicly attributed to fake job offers targeting developers.
- Japanese cryptocurrency exchange bitFlyer blocks a fraudulent engineering applicant linked to North Korean cyber espionage group WaterPlum.
- The WaterPlum campaign compromised 30,000 devices across 100 countries and funneled $10.71 million in cryptocurrency to North Korea.
- International agencies dismantle domestic laptop farms established to disguise foreign state-sponsored operative locations during remote hiring interviews.
The Japan National Police Agency (NPA) and FBI assess that WaterPlum actors and some North Korean IT workers operate under the 313 General Bureau of the Munitions Industry Department, a unit subordinate to the Central Committee of the Workers’ Party of Korea. The advisory also says some WaterPlum actors operate as North Korean IT workers.
The assessment appears in a joint advisory issued September 18, 2026, by Japan’s NPA and National Cybersecurity Office, the FBI, the U.S. Department of Defense Cyber Crime Center (DC3), ASD’s Australian Cyber Security Centre, and Germany’s BND and BfV.
The Job Applicant
The bitFlyer applicant’s résumé described a European university education and work experience across Europe and Asia, alongside programming, blockchain, cryptocurrency, and cloud skills. During the video interview, he said he was born in Malaysia and lived in Finland.
Officials said his English did not match the claimed academic and professional background and that he could not explain most of the skills listed on his résumé. The applicant reached the recruitment process through VPN and proxy services.
Have a development worth tracking?
Share product launches, funding announcements, partnerships, research findings and market developments with The Grey Terminal's readership.
→ Submit a Press ReleaseJapanese reporting on the investigation said he wanted remote work and cryptocurrency payment and was unwilling to relocate. The reporting also described repeated glances at another monitor and voices in the background. The English-language advisory separately lists those behaviors among observations from interviews with suspected North Korean IT workers.
bitFlyer did not hire the applicant and suffered no damage from the attempt.
The IP Trail
The joint advisory says WaterPlum actors and some North Korean IT workers used the same IP addresses when accessing laptop farms, using crowdsourcing services, and applying for positions at a Japanese cryptocurrency exchange.
WaterPlum, also known as Contagious Interview, approached developers by posing as recruiters for artificial-intelligence, cryptocurrency, and non-fungible-token companies, as well as recruiting services. Targets were given coding tests or other tasks that could deliver malware to their computers.
Japan’s Laptop Farm
The investigation also uncovered what Japanese authorities described as the first laptop farm they had identified, investigated, and dismantled in Japan.
A local enabler placed computers at a residence in Japan. North Korean IT workers operating from abroad remotely controlled the machines so employers and online platforms could see Japanese network connections.
Japanese authorities said several hundred million yen in cryptocurrency was sent to locations outside Japan through the IT-worker activity. That money is separate from the cryptocurrency attributed to WaterPlum’s hacking campaign.
The Wider Campaign
WaterPlum’s wider campaign ran from around December 2025 through July 2026, when authorities said it exploited at least 30,000 devices in more than 100 countries.
The group also exfiltrated funds or account credentials from more than 7,000 cryptocurrency wallets. Authorities said ¥1.7 billion, equivalent to about $10.71 million, in cryptocurrency assets was transferred to North Korea.
That figure does not mean 7,000 wallets were emptied. The official account refers to funds or account credentials taken from more than 7,000 wallets and the subsequent transfer of cryptocurrency assets.
For companies hiring remote technical workers, the investigation turns the hiring desk into part of the security perimeter. The person offering the job may be part of the intrusion, while the person applying for it may be trying to get inside the company.
Activate Terminal Layer
Structural analysis of the systems, pressures, and stakeholders behind this story.





