A North Korean hacking group is using job ads to harvest sensitive information from unsuspecting applicants from more than 100 countries, authorities warn.

The group, known as “WaterPlum”, infiltrated at least 30,000 devices stealing $US10.71 million ($15.25 million) worth of cryptocurrency from 7,000 accounts.

Cybersecurity officials from the US, Japan, Germany and Australia issued a joint statement saying the group was targeting individual IT professionals.

What happened?

Between December 2025 and July this year, members of WaterPlum presented as an employer advertising fake roles specifically for software developers and IT professionals.

They would instruct applicants to download files for software alternatives to video conferencing apps such as Zoom to conduct interviews.

Authorities said members of the group also operated as North Korean IT workers at companies.

They would use artificial intelligence (AI) face-swapping software when beginning online interviews for roles, and then ask to disable their camera “because of network issues”.

FBI says North Korea stole $US1.5b in crypto

A $US1.5 billion heist on leading cryptocurrency exchange Bybit is the work of North Korean state-sponsored hackers, according to the FBI.

It was discovered after Japanese authorities were able to identify a “laptop farm”, which obscures someone’s real location, and found evidence WaterPlum had transferred millions in cryptocurrency to places outside Japan.

Those who were a part of the laptop farm were often located in North Korea, China and Russia, with a small number in Africa and south-east Asia.

University of Melbourne’s Andrew Cullen, who specialises in cybersecurity and AI, said these were two of the main types of scams run by the group.

He said he had seen reports of fake North Korean employees for the last three to four years but it has been accelerating.

“I don’t think anybody in the West has a particularly strong grasp on exactly how long this has been happening,” Dr Cullen said.

He said it was difficult to understand the scale of the problem, especially as it related to workers infiltrating companies, because that information was rarely disclosed.

“It’s really hard for governments and cybersecurity organisations to try and collect this large-scale data to show how much of a problem it is across the economy,” he said.

Authorities said the group had also been able to access ID images, passwords and other sensitive data from thousands of people that could be used for extortion.

They also said the group operated under the 313 General Bureau of the Munitions Industry Department, subordinate to the Central Committee of the Workers’ Party of Korea.

What does it mean?

Dr Cullen said hacks of this nature were likely to become more prevalent because of rogue AI agents and AI tools that enable hackers to work faster with a larger scope.

How AI agents swarmed another company

Tens of thousands of messages from hundreds of rogue OpenAI agents reveal how the self-described “collective” coordinated the attack on AI infrastructure company Hugging Face.

According to the Royal United Services Institute (RUSI), an independent security think tank in the UK, AI was being used to speed-up the process of ransomware operations.

Dr Cullen described ransomware as when someone is locked out of their systems, and is then charged a ransom for access to their own data.

“So, instead of a hacker who is on the other side having a conversation about the extortion, that can be farmed out to an AI system,” he said.

“Or an AI system can be used to help those who are doing these kind of hacks sound more natural, talk to more people, keep track of what they’re doing more efficiently.”

What are some countermeasures?

Dr Cullen said cybersecurity could sound big and scary, but there were simple principles that could help protect someone’s data and security.

These included changing passwords regularly, keeping devices updated, and avoiding suspicious links and software.

He also said employers should meet physically with remote staff to verify their identities.

“These are all the basic cybersecurity messages that we’ve had for the last 10 years,” he said.

Dr Cullen said this was because hackers had not improved but the volume and speed of them have increased.

Outside of increasing funding to cybersecurity, Dr Cullen said governments could also set rules that made hacking people in Australia less attractive.

He highlighted setting specific legislation that stopped companies paying bribes to ransomware groups.

“So there’s a real job for the government to make sure they’re setting the legislation so that Australians aren’t targeted,” he said.