{
  "id": 8403142,
  "title": "North Korean hackers behind crypto thefts across 100 countries, including Japan",
  "url": "https://urgent.news/2026/09/19/north-korean-hackers-behind-crypto-thefts-across-100-countries",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-19T02:48:00.000Z",
  "source": {
    "name": "Japan Times",
    "slug": "japan-times",
    "url": "https://www.japantimes.co.jp/news/2026/09/19/japan/crime-legal/north-korean-hackers-crypto-thefts-japan/"
  },
  "original_language": "en",
  "account": "A North Korean hacking group, known as WaterPlum, orchestrated a cyberattack affecting over 100 countries, including Japan, resulting in the theft of approximately ¥1.7 billion worth of cryptocurrency. The criminal operation, which spanned between December of the previous year and July of this year, involved infecting more than 30,000 devices with malware. This malware was designed to steal login credentials for around 7,000 cryptocurrency accounts.\n\nThe National Police Agency (NPA) of Japan, along with seven organizations from four countries, including the U.S. Federal Bureau of Investigation (FBI), released a warning document attributed to the WaterPlum group. This document aimed to deter future cyberattacks by exposing the identities of those responsible.\n\nWaterPlum employed a tactic of posing as corporate headhunters to lure IT professionals into downloading malware disguised as technical assessments. The stolen credentials were then used to transfer cryptocurrency from compromised accounts. Most of the stolen cryptocurrency is believed to have originated from these compromised accounts.\n\nThe report also revealed that North Korean IT workers living in North Korea, China, and Russia were earning foreign currency by taking on remote programming jobs under false identities. This illicit activity contributed to the transfer of hundreds of millions of yen to North Korea in recent years. These operations were supported by individuals residing in Japan, who provided the necessary computers, servers, identification documents, and financial accounts.\n\nJapanese authorities successfully dismantled the WaterPlum network through their investigation. The IP addresses used by WaterPlum during the cyberattack were found to match those utilized in the cryptocurrency-earning activities and job applications. Both WaterPlum and some North Korean IT workers are believed to operate under the 313 General Bureau of the Munitions Industry Department, responsible for weapons development and IT strategy under the Central Committee of the Workers Party of Korea.",
  "summary": "The North Korean group, called WaterPlum, infected more than 30,000 devices with malware between December last year and July this year.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}