Skip to content
logo The magazine for digital lifestyle and entertainment
Fraud News Security All topics
Germans Also Affected

How North Korean Hackers Stole Millions of Euros

A hooded figure sits in front of several computer screens in a dimly lit room. Blurred lines of code are visible on their clothing and the monitors. The scene is bathed in green and blue light.
According to authorities, users in more than 100 countries, including Germany, were affected. Photo: Getty Images

September 22, 2026, 7:44 am | Read time: 3 minutes

North Korean cybercriminals are alleged to have compromised thousands of computers worldwide through fake job offers. According to investigators, the group WaterPlum used this tactic over several months to install malware on their victims’ devices. Users in more than 100 countries, including Germany, were affected.

Due to the attacks, the FBI and security agencies from Japan, Germany, and Australia have issued an international warning. Investigators report that the group infected more than 30,000 computers between December 2025 and July 2026, stealing cryptocurrencies worth over 9 million euros.

Hackers Disguised as Recruiters

For their attacks, the perpetrators used social networks and job platforms. They posed as recruiters from tech companies and specifically targeted web designers, software developers, and specialists in cryptocurrencies, blockchain, and Web3.

Interested parties received supposed job offers and were involved in a fake application process. They were asked to complete technical tasks or correct errors in program code. However, the files provided contained malware. Programs mentioned include BeaverTail, InvisibleFerret, and OtterCookie.

The programs can be executed on both Windows and macOS devices. After a successful infection, the attackers could permanently access the affected computers and extract information such as passwords, keystrokes, or data from crypto wallets.

More Than 7,000 Crypto Accounts Affected

According to authorities, more than 7,000 cryptocurrency accounts were compromised. The stolen amount is said to be at least $10.7 million, or approximately 9.3 million euros.

Additionally, the perpetrators reportedly used AI software in some cases to manipulate faces during video interviews, aiming to deceive more individuals.

Authorities advise against running program code of unknown origin directly on one’s computer. Instead, secure virtual environments should be used. If there is suspicion of an infection, the device’s internet connection should be immediately disconnected.

More on the topic

Fraudsters Repeatedly Use Similar Methods

The theft of cryptocurrencies has been a method used by many cybercriminals for years. Fraudsters attempt to gain access to digital wallets in various ways. They often use social networks to build trust and specifically target their victims.

Also of interest: After the hacker attack on Berlin – how users should respond

Therefore, it remains important not to respond to suspicious messages. In case of doubt, experts recommend contacting the relevant authorities.

Connection to North Korean Agency

The FBI links WaterPlum to the 313 General Bureau of the Munitions Industry Department, a North Korean agency for weapons development and IT strategy.

Investigators believe the stolen funds could be funneled into weapons programs. The group reportedly received support in Japan, where helpers provided computers, servers, and bank accounts. The Japanese police have announced that the network has since been dismantled.

Experts also estimate that around 100,000 North Korean IT workers are operating worldwide under false identities, potentially bringing in up to $500 million annually for the regime.

This article is a machine translation of the original German version of TECHBOOK and has been reviewed for accuracy and quality by a native speaker. For feedback, please contact us at info@techbook.de.

You have successfully withdrawn your consent to the processing of personal data through tracking and advertising when using this website. You can now consent to data processing again or object to legitimate interests.