The FBI and Japan's National Police Agency warned of a North Korea-linked hacking campaign that infected over 30,000 devices across more than 100 countries between December 2025 and July 2026, stealing credentials from 7,000 crypto wallets and netting $10.71 million in digital assets.
The joint announcement identified the campaign as WaterPlum, naming it after the attackers' method of impersonating recruiters at cryptocurrency, AI and non-fungible token firms to distribute malware. Victims received emails appearing to come from major companies in those sectors, according to the agencies. The attackers sent recruiting emails to targets in industries with known high salaries and rapid hiring cycles.

The infection vector relied on phishing emails designed to appear as employment offers. Recipients who opened attachments or clicked links downloaded malware that gave attackers access to crypto wallet credentials stored on infected machines. The campaign's geographic spread across more than 100 countries shows attackers used volume tactics rather than targeted reconnaissance of individual targets.

The $10.71 million figure represents funds transferred from compromised wallets to attacker-controlled addresses. The NPA and FBI did not specify which blockchain networks were affected or whether victims recovered any stolen funds. Wallet compromise at this scale typically results from malware that harvests private keys or seed phrases rather than exchange-account credentials alone.
North Korea has conducted cryptocurrency theft operations since at least 2017, with previous campaigns targeting exchange infrastructure and individual holders. The WaterPlum campaign used social engineering through recruiter impersonation in the crypto and AI sectors. The FBI and NPA have shared threat indicators and signatures to help device manufacturers and security vendors detect and remove the malware.
The 30,000-device infection count dwarfs most publicly disclosed ransomware campaigns. By comparison, the NotPetya outbreak in 2017 infected approximately 10,000 networks globally before remediation. The credential harvest of 7,000 wallets suggests a success rate of roughly 23 percent across devices carrying wallet data, though the agencies did not clarify whether all infected machines contained cryptocurrency holdings.
The number to watch is whether the stolen $10.71 million in digital assets remains consolidated in North Korea-linked addresses or begins moving through mixers and exchanges, an indicator of whether law enforcement or blockchain analytics firms can track or recover any portion of the theft.