Download Privacy Needle App

Type to search

Cybersecurity

Japan Dismantles First North Korean Laptop Farm Amid Global Cyber Advisory

Share

Japanese authorities have dismantled the first confirmed North Korean “laptop farm” in the country, as part of a broader international crackdown on a sophisticated cyber-enabled hiring scheme. A joint advisory issued by law enforcement and intelligence agencies from Japan, the United States, Australia, and Germany has detailed the operations of a threat group known as WaterPlum, also referred to as Contagious Interview.

The WaterPlum Campaign and Financial Impact

The WaterPlum campaign has targeted software developers and IT professionals by impersonating legitimate employers, often posing as companies in the artificial intelligence (AI), cryptocurrency, or NFT sectors. Between December 2025 and July 2026, the group infected at least 30,000 devices across more than 100 countries.

The primary targets included web designers, engineers, and specialists in blockchain and web3 technologies. Authorities estimate that approximately $10.71 million in funds or account credentials were stolen from more than 7,000 cryptocurrency wallets, with the proceeds ultimately reaching North Korea.

The Japanese National Police Agency and the FBI have assessed that WaterPlum operators and certain North Korean IT workers answer to the 313 General Bureau of the Munitions Industry Department, which operates under the Workers’ Party of Korea’s Central Committee.

The Use of Laptop Farms

The scheme relies heavily on the use of “laptop farms” to mask the true location of the operatives. These are physical locations, often at the residence of an accomplice, where multiple devices are set up and operated remotely by North Korean IT workers. This allows the workers to perform paid IT tasks while appearing to be located elsewhere.

In the recent Japanese operation, authorities confirmed the dismantling of one such farm. The document notes that Japanese authorities obtained evidence of the group transferring several hundred million Japanese yen in cryptocurrency to foreign locations outside of Japan.

AI and Social Engineering Tactics

To evade detection during the recruitment process, WaterPlum actors have employed various social engineering and AI-driven tactics. These include using AI face-swapping technology during initial video interviews and relying on text-to-speech tools or machine translation services to manage language barriers.

The advisory highlights several red flags that helped identify the operatives, including:

  • Applicants using VPNs and presenting highly inflated resumes claiming expertise across numerous programming languages and cloud services.
  • A reluctance to meet in person and a preference for being paid in cryptocurrency.
  • Unexplained video or audio artifacts, such as repeated freezes or background voices.
  • Applicants appearing to glance at secondary screens for answers during live video calls.

Beyond direct financial theft, the campaign presents a significant supply chain risk. A compromised developer provides WaterPlum with a potential pathway into their employer’s corporate network, which can be used to access trade secrets, personal information, or facilitate extortion.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.