The Day the Application Form Became an Attack Surface: Japan's Joint Attribution and the Unverified Boundary of Identity

A Seven-Agency Joint Attribution
On September 18, 2026, Japan's National Police Agency, together with the National Cyber Office (NCO), the US Federal Bureau of Investigation (FBI), the US Department of Defense Cyber Crime Center (DC3), the Australian Signals Directorate and Australian Cyber Security Centre (ASD/ACSC), Germany's Federal Intelligence Service (BND) and Federal Office for the Protection of the Constitution (BfV), published an advisory on the North Korea–linked threat group WaterPlum, also tracked as Contagious Interview. Japan's Ministry of Foreign Affairs framed the release as a public attribution. The NPA and FBI assess that both WaterPlum's cyber operations and part of the DPRK IT worker revenue-generation activity are directed by Bureau 313 of the Munitions Industry Department of the Workers' Party of Korea Central Committee. The scale is substantial: between roughly December 2025 and July 2026, more than 30,000 devices across over 100 countries and territories, including Japan, were infected with malware, and information on more than 7,000 crypto wallets was stolen. At least approximately JPY 1.7 billion (about USD 10.71 million at 159 yen to the dollar) in crypto assets was confirmed to have been transferred into wallets controlled by the group.
Recruitment Is the Entry Point
What deserves attention is that the entry point is consistently recruitment. WaterPlum impersonates AI, crypto and NFT companies as well as staffing services, approaching software developers through social media, online job boards, gig-work platforms and freelance marketplaces with attractive offers. Under the pretext of a technical interview or a coding assignment, targets are induced to open repositories containing malicious programs. Through malicious NPM packages and booby-trapped VS Code projects, the group compromises endpoints and exfiltrates browser-stored credentials, keystroke logs, crypto wallet private keys and seed phrases, and images of identity documents such as driver's licenses and passports. Those stolen identity images can then be reused by other DPRK IT workers to impersonate real people when applying for jobs. A compromised individual's device also becomes an entry point into their employer's network.
Japan's First Laptop Farm and the bitFlyer Case
Two Japan-specific findings stand out. First, police identified and dismantled a "laptop farm" in Japan for the first time — PCs installed in the residence of a domestic enabler and operated remotely by DPRK IT workers. Those workers misused identity document images supplied by the enabler to win contract work, designated the enabler's bank account for payment, and remitted several hundred million yen equivalent overseas. Second, the advisory disclosed by name an application submitted in May 2025 to an engineering role at bitFlyer. The applicant attached a résumé impersonating another person and applied directly rather than through an intermediary, accessed the application form via multiple VPN services, and listed a free email address as the contact point. The résumé claimed a European university degree, work history across European and Asian cities, and deep expertise across more than ten technical domains. In the online interview, explanations of origin and residence lacked specificity, answers about listed skills remained abstract, the applicant declined to relocate to Japan, and insisted on receiving salary in crypto. The applicant repeatedly checked another monitor, and other people's voices were audible in the background. bitFlyer noticed the irregularities, responded appropriately, and neither hired the applicant nor suffered damage.
IP Addresses Linked the Two Activities
The most consequential finding is this: the IP addresses used by WaterPlum's attackers, those used by DPRK IT workers to connect to laptop farms and crowdsourcing services, and those used by the bitFlyer applicant all matched. This indicates that cyber intrusion and employment fraud — seemingly distinct activities — are run from the same operational infrastructure. For companies, this means that external attacks, job applications and outsourcing vendors must be treated defensively as one continuous attack surface rather than three separate concerns. The NPA asks organizations that outsource work to assume that DPRK IT workers may be involved in subcontracting chains, to establish contractual provisions accordingly, and to minimize the information and privileges granted to external parties. The advisory also states plainly that knowingly paying, or providing identity documents to, DPRK-linked individuals may constitute a violation of domestic law or DPRK sanctions. Notably, NTT Security Japan and bitFlyer are credited as contributors to the advisory itself.
[Business Development Insights]
- The hiring process is now the front line of the security perimeter. Most organizations impose rigorous KYC on customers while accepting self-declared résumés from prospective employees with almost no verification — and that asymmetry is exactly what is being exploited. Financial institutions and Web3 firms should embed, as standing procedures within recruitment operations rather than within the security function, checks on whether the application's source IP is consistent with the stated place of residence, verification that contact phone numbers are live, specific probing questions on claimed skills, and personal questions about hometown or local climate. Insistence on fully remote work and on crypto-denominated compensation, and requests to remit to accounts not in the applicant's own name, are each flagged as warning signals in their own right.
- Exposure is not confined to one's own hiring; it extends across the entire outsourcing and subcontracting chain. The advisory documents that when DPRK IT workers are involved in a vendor's partners or subcontractors, the ultimate client can suffer harm — including one case where source code was published online amid a payment dispute, and another where a website the worker helped build was later defaced. These are procurement governance failures more than technical breaches. Prohibitions on unapproved subcontracting, minimization of credentials and access granted to vendors, and procedures for immediate account and session revocation upon suspicion should be codified at the procurement-policy level. The higher a firm's reliance on outsourced development, the higher the priority.
- Companies that disclose near-miss incidents become part of the defensive infrastructure. bitFlyer was named as a target and simultaneously credited as a contributor to the advisory. Because the tradecraft was published in detail, peer firms in Japan can now implement the same detection signals in their own hiring pipelines. For Japanese crypto and Web3 operators, establishing an information-sharing channel with authorities in advance is not a cost but an investment in sector-wide resilience. Given that this release was framed as a public attribution — a diplomatic instrument — the pathway from private-sector reporting to state-level response is becoming institutionalized, which is worth recognizing at the executive level.
[Sources]
National Police Agency / National Cyber Office, advisory on the North Korea–linked threat group WaterPlum and on DPRK IT worker activity in Japan, the US and Europe (September 18, 2026) https://www.npa.go.jp/bureau/cyber/pdf/20260918_j.pdf NADA NEWS, "DPRK IT Worker Applied to bitFlyer Engineering Role — NPA Discloses Link to Hacker Group" (September 18, 2026) https://www.nadanews.com/368724/ INTERNET Watch, coverage of the NPA/NCO advisory on WaterPlum tradecraft (September 18, 2026) https://internet.watch.impress.co.jp/docs/news/2142320.html CoinPost, "Seven Agencies Across Japan, US, Australia and Germany Disclose JPY 1.7 Billion Crypto Theft by DPRK Hackers 'WaterPlum'" (September 18, 2026) https://coinpost.jp/?p=738590 JinaCoin, "DPRK Hackers 'WaterPlum' Stole Information on 7,000 Crypto Wallets — NPA Disclosure" (September 19, 2026) https://jinacoin.ne.jp/north-korea-waterplum-20260919/ NOVAIST, "North Korea–Linked 'WaterPlum' Infected Over 30,000 Devices Across 100-Plus Countries; At Least JPY 1.7 Billion in Controlled Wallets" (September 18, 2026) https://novaist.jp/articles/waterplum-north-korea-warning/ National Police Agency, advisory to companies and partner nations on DPRK IT workers (July 31, 2026) https://www.npa.go.jp/bureau/security/northkorea_IT/NK_IT_202607.html National Police Agency, advisory to companies on DPRK IT workers (March 26, 2024) https://www.npa.go.jp/bureau/security/northkorea_IT/NK_it.pdf
Akihisa Ishida
Cabinet Inc. Founder CEO
Disclaimer
This report has been prepared solely for informational purposes regarding crypto assets and related markets, and is not intended to recommend, solicit, or offer the purchase, sale, holding, or any other transaction of any specific crypto asset. It does not constitute investment advice, investment solicitation, or the sale or intermediation of financial products as defined under the Financial Instruments and Exchange Act or any other applicable laws and regulations, nor does it constitute tax, legal, or accounting advice.
The information contained in this report is based on sources believed to be reliable at the time of preparation; however, we make no representation or warranty, express or implied, as to its accuracy, completeness, timeliness, or usefulness. Crypto assets are subject to significant price volatility and may result in the loss of principal or other financial losses. Any investment decision shall be made solely at the user's own discretion and responsibility, and we accept no liability whatsoever for any damages arising out of or in connection with the use of this report.
Blockchain Business Consultation
From idea-stage brainstorming and technical validation (PoC) to implementation and operations, Cabinet provides end-to-end business development consulting. Start with a free consultation today.
Sign Up for Newsletter
Beyond the content of this report, we will deliver the latest industry information and exclusive reports by email.

