---
title: "Fake job interviews infected 30,000 devices, FB… | Firevault"
url: https://fire-vault.com/news/waterplum-contagious-interview-30000-devices-2026
description: "A joint FBI-led advisory says North Korean WaterPlum actors used fake technical interviews and coding tests to infect at least 30,000 devices in more than 100…"
lang: en-GB
---

Breaking News Updated as information becomes available

News · Threat Analysis · 25 September 2026 · Breaking

# Fake job interviews infected 30,000 devices, FBI-led advisory says

A joint FBI-led advisory says North Korean WaterPlum actors used fake technical interviews and coding tests to infect at least 30,000 devices in more than 100 countries.

Image: Mark Fermor (https://fire-vault.com/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor CTO, CMO & Founder, Firevault

5 min read

Share

Share on LinkedIn: https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fwaterplum-contagious-interview-30000-devices-2026
Share on X: https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fwaterplum-contagious-interview-30000-devices-2026&text=Fake%20job%20interviews%20infected%2030%2C000%20devices%2C%20FBI-led%20advisory%20says%0A%0AA%20joint%20FBI-led%20advisory%20says%20North%20Korean%20WaterPlum%20actors%20used%20fake%20technical%20interviews%20and%20coding%20tests%20to%20infect%20at%20least%2030%2C000%20devices%20in%20more%20than%20100%20countries.
Share on Facebook: https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fwaterplum-contagious-interview-30000-devices-2026

Image: A fake technical job interview on a developer laptop sends malicious code towards a workstation while a physically disconnected data store remains protected (https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fwaterplum-contagious-interview-2026.jpg)

A fake technical job interview on a developer laptop sends malicious code towards a workstation while a physically disconnected data store remains protected

Why it matters

## What this means for organisations holding critical data

## What the agencies reported

A joint advisory published on 18 September by cyber and intelligence agencies in Japan, the United States, Australia and Germany says a North Korean-linked campaign has infected at least 30,000 devices in more than 100 countries.

The agencies call the group WaterPlum. Security researchers more commonly track the activity as Contagious Interview. According to the advisory, the actors pose as recruiters or prospective employers, often impersonating legitimate artificial intelligence, cryptocurrency and NFT businesses. They approach software developers and other IT professionals through social media, job sites, gig-work platforms and freelance marketplaces.

The figures are official assessments rather than independently audited totals. The advisory says the campaign has stolen funds or account credentials from more than 7,000 cryptocurrency wallets and transferred ¥1.7 billion, approximately US$10.71 million, in cryptocurrency assets to North Korea.

## The interview is the delivery mechanism

The initial approach is designed to look like ordinary recruitment. During a video interview or coding assessment, the candidate is asked to download a project, repair a supposed conferencing fault or run code from a developer platform or repository.

The advisory names malicious npm packages, GitHub or Bitbucket repositories and Visual Studio Code projects as delivery routes. Malware families linked to the activity include BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle.

Once executed, the malware can create persistent remote access, steal browser credentials and cryptocurrency information, capture clipboard or keystroke data, take screenshots and collect identity documents (https://fire-vault.com/oss-for-identity-documents). A compromised developer machine can also become a route into the organisation that employs that person.

That wider risk matters. This is not only a cryptocurrency theft campaign. The advisory warns that successful infections can create opportunities for espionage, intellectual property (https://fire-vault.com/oss-for-intellectual-property) theft and lateral movement through corporate systems.

## The laptop-farm connection

The same advisory connects WaterPlum infrastructure with North Korean IT workers who obtain legitimate-looking remote contracts using false or borrowed identities.

A laptop farm is a collection of employer-issued computers physically hosted by an enabler and remotely operated from another country. Japan says it identified and dismantled its first domestic laptop farm. The FBI says it continues to identify and prosecute US-based facilitators.

The Japanese National Police Agency and FBI assess that WaterPlum actors and some North Korean IT workers operate under the 313 General Bureau of North Korea's Munitions Industry Department. That wording is an intelligence assessment, not a judicial finding.

## What developers and employers should do

Developers should not run unfamiliar interview code on the same machine that holds employer access, personal data or cryptocurrency credentials. Unknown projects should be inspected before execution and, where testing is necessary, opened only in an isolated sandbox or virtual machine.

The advisory highlights suspicious commands and obfuscated scripts, including use of `curl`, `base64`, `mshta`, `Invoke-WebRequest` and hidden execution. A command containing one of these terms is not automatically malicious, but a recruiter who asks a candidate to run code they cannot explain should be treated as a serious warning sign.

Employers should verify remote applicants beyond identity documents and a short video call. The agencies recommend checking whether the applicant's network location broadly matches their claimed residence, testing detailed knowledge behind unusually broad CV claims, verifying qualifications and investigating payment requests involving cryptocurrency or accounts in another person's name.

Access must remain limited to what a contractor needs. If an identity or subcontracting concern emerges, revoke accounts and active sessions promptly rather than waiting for the investigation to finish.

## If a machine may be infected

The advisory says to disconnect the affected device from the internet immediately. Removal of the detected malware is not enough, because information may already have been stolen and other persistence may remain.

Cryptocurrency assets should be moved to a new wallet created on a separate clean device, with the new seed phrase stored offline. Essential data should be recovered carefully before a full operating-system reset, and organisations should use endpoint monitoring to look for related behaviour elsewhere.

## The Firevault view

The most important lesson is the trust boundary. A coding task can turn a developer's everyday workstation into an attacker-controlled foothold, and that workstation often holds access to source code, credentials, shared drives and recovery systems.

Detection and recruitment checks reduce the likelihood of compromise, but they do not answer the recovery question: what remains trustworthy after the machine and its connected identity have been exposed?

Critical recovery data held in Offline Secure Storage (https://fire-vault.com/offline-secure-storage)® is physically disconnected when it is not being used. Malware on a developer endpoint cannot browse, encrypt or exfiltrate a copy for which no network path exists. Organisations should keep the recovery copy outside the reach of developer tools, cloud identities and remote administration, then test that it can be restored without trusting the compromised estate.

## Sources

- Joint FBI, NPA, NCO, DC3, ACSC, BND and BfV advisory: WaterPlum and Contagious Interview, 18 September 2026: https://www.ic3.gov/CSA/2026/260918.pdf
- Australian Cyber Security Centre publication of the joint advisory: https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/north-korean-waterplum-commonly-referred-to-as-contagious-interview-cyber-actor-group-targeting-it-professionals
- Palo Alto Networks Unit 42: Contagious Interview and Wagemole, 21 November 2023: https://unit42.paloaltonetworks.com/two-campaigns-by-north-korea-bad-actors-target-job-hunters/
- Zscaler ThreatLabz: technical analysis of North Korean remote-worker activity: https://www.zscaler.com/blogs/security-research/pyongyang-your-payroll-rise-north-korean-remote-workers-west

Sources

## Where this reporting comes from

01

**Original report**Primary coverage referenced in this analysis View original article (https://www.ic3.gov/CSA/2026/260918.pdf)

About the author

### Mark Fermor

Mark Fermor on LinkedIn (https://www.linkedin.com/in/mfermor)

CTO, CMO & Founder

Founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

## Controls an auditor can physically verify

Firevault gives you physical separation, named custody and evidenced access, so compliance claims about isolation and control are things you can show, not just assert.

Get started: https://fire-vault.com/get-started
Talk to the team: https://fire-vault.com/demo

**Custody**Named, access-controlled hardware in a Firevault Bunker

**Evidence**Access windows and retrieval events are recorded

**Separation**Physical isolation that satisfies offline copy requirements

**Jurisdiction**Stored where your regulatory position requires

Related Reading

## You may also find these useful

Threat Analysis

### Blockchain dead drops surge 440% as North Korea and Iran hide malware on public ledgers

Chainalysis research shows malicious blockchain writes rising from 2.06 to 11.1 a day in under a year, with state-linked groups now behind most new activity. Attackers are using ledgers that cannot be taken down to keep compromised machines connected.

24 Sept 2026 3 min
https://fire-vault.com/news/blockchain-dead-drops-malware-surge-2026

Threat Analysis

### Scattered Spider Guilty Pleas: What the TfL Hack Confirms About Offline Recovery

Two Scattered Spider members have admitted the £39m TfL hack. Mark Fermor on identity blast radius and why offline recovery is the deciding layer.

22 Jun 2026 4 min
https://fire-vault.com/news/scattered-spider-tfl-guilty-plea-offline-recovery

Threat Analysis

### UK critical infrastructure hit by 200 cyber incidents in a year, NCSC warns

NCSC chief Richard Horne says the UK faced more than 200 nationally significant cyber incidents against critical infrastructure in a year, with about three-quarters tied to state actors.

20 Jun 2026 5 min
https://fire-vault.com/news/ncsc-uk-critical-infrastructure-incidents-double

Threat Analysis

### 24 billion credentials exposed in record infostealer leak

Cybernews researchers found an 8.3 TB Elasticsearch cluster holding 24 billion records, including plaintext passwords and login URLs harvested from infostealer logs.

19 Jun 2026 4 min
https://fire-vault.com/news/24-billion-credentials-infostealer-leak

Threat Analysis

### FortiBleed: 74,000 Fortinet firewalls leak plaintext credentials

Researchers say a Russian-speaking crew cracked nearly half the internet's Fortinet firewalls, exposing plaintext logins for Oracle, Chevron, Lenovo, FedEx, a NATO defence contractor and Fortinet itself.

18 Jun 2026 4 min
https://fire-vault.com/news/fortibleed-74000-fortinet-firewalls-credentials-exposed

Artificial Intelligence

### OpenAI agent hacked Australian government Medicare portal, prime minister reveals

An autonomous OpenAI agent gained unauthorised access to an Australian government Medicare statistics portal in June, accessing public and non-public files. The government says it was not told until September, and a forensic investigation is under way.

24 Sept 2026 4 min
https://fire-vault.com/news/openai-agent-medicare-portal-breach-australia-2026

## Suggested Reading

- What is Offline Secure Storage The foundation of physical disconnection: https://fire-vault.com/how-it-works/offline-secure-storage
- Why Offline Secure Storage The case for physical control: https://fire-vault.com/why-oss
- Ransomware Defence Hold gold copies offline: https://fire-vault.com/oss-for-ransomware-recovery
- Control Physical path control for IT and OT: https://fire-vault.com/solutions/control
- Knowledge Vault All articles, guides and whitepapers: https://fire-vault.com/learn/knowledge
- Book a Demo See Firevault in action: https://fire-vault.com/demo

Back to Knowledge Vault: https://fire-vault.com/learn/knowledge

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/news/waterplum-contagious-interview-30000-devices-2026#webpage",
    "url": "https://fire-vault.com/news/waterplum-contagious-interview-30000-devices-2026",
    "name": "Fake job interviews infected 30,000 devices, FB…",
    "description": "A joint FBI-led advisory says North Korean WaterPlum actors used fake technical interviews and coding tests to infect at least 30,000 devices in more than 100…",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fwaterplum-contagious-interview-2026.jpg"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/news/waterplum-contagious-interview-30000-devices-2026#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/news/waterplum-contagious-interview-30000-devices-2026#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Learn",
        "item": "https://fire-vault.com/learn"
      },
      {
        "@type": "ListItem",
        "position": 3,
        "name": "Knowledge Vault",
        "item": "https://fire-vault.com/learn/knowledge"
      },
      {
        "@type": "ListItem",
        "position": 4,
        "name": "Fake job interviews infected 30,000 devices, FBI-led advisory says",
        "item": "https://fire-vault.com/news/waterplum-contagious-interview-30000-devices-2026"
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "NewsArticle",
    "headline": "Fake job interviews infected 30,000 devices, FBI-led advisory says",
    "description": "A joint FBI-led advisory says North Korean WaterPlum actors used fake technical interviews and coding tests to infect at least 30,000 devices in more than 100 countries.",
    "url": "https://fire-vault.com/news/waterplum-contagious-interview-30000-devices-2026",
    "image": [
      {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fwaterplum-contagious-interview-2026.jpg",
        "width": 1200,
        "height": 1200
      },
      {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fwaterplum-contagious-interview-2026.jpg",
        "width": 1200,
        "height": 900
      },
      {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fwaterplum-contagious-interview-2026.jpg",
        "width": 1200,
        "height": 675
      }
    ],
    "thumbnailUrl": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fwaterplum-contagious-interview-2026.jpg",
    "author": {
      "@type": "Person",
      "name": "Mark Fermor",
      "jobTitle": "CTO, CMO & Founder",
      "worksFor": {
        "@id": "https://fire-vault.com/#organization"
      },
      "url": "https://fire-vault.com/why-oss/about"
    },
    "publisher": {
      "@type": "NewsMediaOrganization",
      "name": "Firevault",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 600,
        "height": 60
      }
    },
    "datePublished": "2026-09-25T07:55:00+00:00",
    "dateModified": "2026-09-25T07:52:44.514453+00:00",
    "mainEntityOfPage": {
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/waterplum-contagious-interview-30000-devices-2026"
    },
    "inLanguage": "en-GB",
    "articleSection": "Threat Analysis",
    "wordCount": 841,
    "keywords": "Fake, Threat Analysis, data breach, cyber security, offline secure storage, data protection, physical air gap",
    "articleBody": "## What the agencies reported A joint advisory published on 18 September by cyber and intelligence agencies in Japan, the United States, Australia and Germany says a North Korean-linked campaign has infected at least 30,000 devices in more than 100 countries. The agencies call the group WaterPlum. Security researchers more commonly track the activity as Contagious Interview. According to the advis",
    "dateline": "United Kingdom",
    "speakable": {
      "@type": "SpeakableSpecification",
      "cssSelector": [
        "h1",
        ".article-summary",
        "h2"
      ]
    },
    "isAccessibleForFree": true,
    "copyrightHolder": {
      "@id": "https://fire-vault.com/#organization"
    },
    "copyrightYear": 2026
  },
  {
    "@context": "https://schema.org",
    "@type": "FAQPage",
    "mainEntity": [
      {
        "@type": "Question",
        "name": "What is WaterPlum or Contagious Interview?",
        "acceptedAnswer": {
          "@type": "Answer",
          "text": "WaterPlum is the name used in a joint 2026 government advisory for a North Korean-linked cyber group more widely tracked by researchers as Contagious Interview. It targets developers and IT professionals with fake recruitment approaches and malicious coding tasks."
        }
      },
      {
        "@type": "Question",
        "name": "How does the fake job interview attack work?",
        "acceptedAnswer": {
          "@type": "Answer",
          "text": "The actor poses as a recruiter or employer and asks the candidate to download a project, complete a coding test or troubleshoot a supposed video-call problem. The supplied package or repository runs malware that can steal credentials, cryptocurrency information and other sensitive data."
        }
      },
      {
        "@type": "Question",
        "name": "How many devices did the campaign infect?",
        "acceptedAnswer": {
          "@type": "Answer",
          "text": "The joint advisory says at least 30,000 devices in more than 100 countries were infected and more than 7,000 cryptocurrency wallets had funds or credentials taken. These figures are official agency assessments and have not been independently audited."
        }
      },
      {
        "@type": "Question",
        "name": "What should a developer do after running suspicious interview code?",
        "acceptedAnswer": {
          "@type": "Answer",
          "text": "Disconnect the device from the internet, inform the employer or security team, assume credentials and sensitive data may have been exposed, rotate them from a separate clean device and investigate before rebuilding the operating system. Cryptocurrency should be moved to a new wallet created on another clean device."
        }
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  }
]
```