Japanese authorities and international partners continue to attribute large-scale cryptocurrency-related cyber activity to North Korean-linked actors. As of September 18–19, 2026, Japan’s National Police Agency (NPA), together with agencies from the United States, Australia, and Germany, publicly stated that the group known as WaterPlum compromised credentials for approximately 7,000 cryptocurrency wallets or accounts.

The campaign still affected more than 30,000 devices across over 100 countries and regions between roughly December 2025 and July 2026. Authorities reported that cryptocurrency valued at about ¥1.7 billion (approximately $10.7 million) was transferred to addresses linked to the group. This comparison underscores the cross-border scale of the activity documented in the joint warning.

Context from Official Statements

The key public findings come from a coordinated “public attribution” document released by seven organizations, including Japan’s NPA and National Cybersecurity Office, the U.S. FBI and Department of Defense Cyber Crime Center, and counterparts in Australia and Germany. The statements link WaterPlum (also referred to under the alias Contagious Interview) to North Korean entities and note the theft of wallet-related records alongside the movement of funds.

These disclosures form part of broader efforts to deter state-linked cyber activity through transparent attribution. Japanese officials separately confirmed related investigative actions, including the disruption of supporting networks.

It is essential to distinguish: official reporting focuses on the scale of compromised records, the volume of funds moved, the geographic reach, and the attribution to North Korean actors, whereas any description of techniques or processes is not included here.

Broader Impact and Response

These findings contribute to ongoing international cooperation against cyber-enabled theft targeting cryptocurrency users and professionals in the tech and blockchain sectors. The joint statements fuel discussions on the risks of state-sponsored cyber operations, the need for heightened vigilance among developers and crypto holders, and the value of multi-national information sharing.

Security agencies emphasize public awareness and defensive measures at a general level. Enforcement actions, including network disruptions in Japan, grow the record of responses to such campaigns.

As further updates from the involved agencies emerge, this case offers insight into the continuing challenges of cross-border cyber attribution and cryptocurrency-related financial crime. Official public reporting remains a primary channel for communicating the scale and impact.

This high-level summary draws exclusively from statements by Japan’s National Police Agency and the joint international advisory, along with contemporaneous coverage. No methods or technical details are described.

Leave a Reply

Your email address will not be published. Required fields are marked *

WP Twitter Auto Publish Powered By : XYZScripts.com