THE TELL

The recruiter on your screen had someone else's face

Four governments just confirmed it: fake job interviews at AI and crypto companies infected 30,000 devices in more than 100 countries — and the interviewer's face was swapped by software.

A joint advisory from Japanese, US, Australian and German authorities describes a hiring process that looks completely normal from the applicant's side. A recruiter from an AI, crypto or NFT company reaches out, often through a recruiting or freelance platform. There's a video call. There's a coding test. You're asked to download a project, or to troubleshoot a video-conferencing glitch, or just to run the code they sent you.

That's the whole attack. The group is called WaterPlum, and according to the advisory it infected at least 30,000 devices in more than 100 countries between December 2025 and July 2026, pulled funds or account credentials out of more than 7,000 cryptocurrency wallets, and moved 1.7 billion Japanese yen — about $10.71 million — in crypto to North Korea. Investigators say the actors used AI face-swapping software during the online interviews, then switched their cameras off and blamed the network.

What it means

Here is the part that changes how you should read this. The money was not the only thing they took. The advisory says WaterPlum actors steal browser credentials, clipboard contents, keystrokes, private keys and seed phrases, documents, and screenshots — and that North Korean IT workers then reuse identity documents stolen in those attacks to impersonate the victims and get jobs. So a developer who lost $400 from a wallet in March may find that his passport scan is now working a remote contract somewhere, under his name.

You are not just robbed. You are recycled.
Share this

And it doesn't stop at your laptop. The agencies say attackers may pivot from an infected computer into the networks of that person's employer or clients, turning a stolen wallet into intellectual property theft and espionage. That is why a candidate running a stranger's code at home is a corporate problem: the door they opened wasn't theirs alone. The FBI and Japanese police assess that WaterPlum actors and some North Korean IT workers operate under the country's 313 General Bureau, part of the Munitions Industry Department responsible for weapons research and production.

Who it matters to

Anyone job-hunting in tech right now, especially juniors — the ones most likely to say yes to a coding test at midnight, most likely to run a repo without reading it, and least able to lose the first couple of thousand sitting in a wallet. Also freelancers who take work through platforms, because that's one of the routes the advisory names. And every small company hiring remote developers: the advisory tells them to verify applicants' identity, location and qualifications, and to give new hires access only to what the job actually needs.

What's next

Japan's National Police Agency says it identified, investigated and dismantled a North Korean IT-worker "laptop farm" in the country for the first time, finding evidence that several hundred million yen had been transferred abroad. Whether more farms surface elsewhere — and whether the $10.71 million figure grows in the next advisory — is the thing to watch. No date for a follow-up report was given.

One detail to hold on to

The trick that made this work wasn't the malware. It was the camera turning off with an apology about bad internet — the single most normal thing that happens on a video call. Five malware families are named in the advisory: BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, StoatWaffle. None of them mattered until someone clicked out of politeness.

Sources: Bleeping Computer, September 19, 2026 — reporting on a joint advisory by Japanese, US, Australian and German authorities.

Why we ran this8/10

Четыре страны официально подтвердили: под видом собеседований в ИИ- и крипто-компаниях северокорейцы заразили 30 тысяч устройств в 100 странах, вычистили 7 тысяч кошельков на $10,7 млн — и использовали ИИ-подмену лица прямо во время видеозвонков, а потом крали документы жертв, чтобы устраиваться на работу от их имени.

Written by THE TELL’s AI newsroom. how we work  ·  corrections

Share
← All stories← Loudoun County cut property taxes 30%. I…Next: A chatbot made up the intelligence. The pl… →
Everyone reports what happened

We send what it means — the part that gets left out: who it hits, what breaks next, and why the obvious reading is wrong. One letter, only when something actually shifts.

No spam. Leave in one click.

Prefer to follow instead? Telegram X