What the advisory says
On 18 September 2026 the FBI and the U.S. Defense Department, together with Japan's National Police Agency and law enforcement in Australia and Germany, published a joint advisory on "WaterPlum", a North Korean cyber group also known as "Contagious Interview". According to The Record, between December 2025 and July 2026 the group infected at least 30,000 devices across 100 countries, took funds or credentials from about 7,000 cryptocurrency wallets, and stole more than $10.5 million. Some outlets convert Japanese police's yen figure to roughly $10.7 million; the difference is exchange-rate rounding, not a disagreement about the scale.
The method is mundane, and that is the point. Operators pose as AI or blockchain companies, approach web designers, engineers and crypto specialists through social media, gig sites and freelance portals, and ask them to download files during a fake interview. Japanese police found the BeaverTail, InvisibleFerret, OtterCookie, OtterCandy and StoatWaffle malware families on victim machines, typically alongside infostealers and remote-management tools. The Record also reports that Japanese authorities disrupted a domestic laptop farm used to help North Korean operatives obtain tech jobs under spoofed identities.
Australia's part is institutional. The Australian Cyber Security Centre's alert on cyber.gov.au lists the Australian Signals Directorate's ACSC among the issuing bodies, alongside Japan's police and National Cybersecurity Office, the FBI, the Defense Cyber Crime Center, and Germany's BND and BfV. The full technical advisory is hosted by the FBI's IC3.
The strongest case for tougher rules
The case for regulatory escalation is not frivolous. The victims are individuals, not firms with security teams. They are job seekers who are, by definition, motivated to comply with a recruiter's requests. The lure works because platforms let anyone register as a recruiter, and the proceeds fund a state. If contact happens on LinkedIn-style networks and freelance marketplaces, a regulator could reasonably ask why those intermediaries carry no duty to verify employer accounts, and why an applicant should bear the whole risk.
Why a mandate is the wrong first tool
The evidence in this advisory points elsewhere. What moved this from an anecdote to an attributed, named campaign was cross-border law-enforcement and intelligence cooperation: four countries pooling indicators, malware family names and victim data, and one country physically shutting down a laptop farm. That is attribution capacity, and no platform licensing regime would have produced it.
A verification mandate also has a poor fit with the threat. The attackers adapt cheaply, and the advisory itself describes other North Korean actors using identity documents stolen from victims. A rule requiring platforms to verify employer identity would be tested against exactly those stolen credentials. Compliance costs would fall hardest on small freelance marketplaces and legitimate startups in Australia's own tech sector, while the adversary, which ignores the law, would keep operating. Speech and openness costs follow as well: mandatory identity checks for anyone posting a job push toward the kind of gatekeeping that an open internet economy has avoided.
The defences that work are unglamorous and largely technical. The Cyber Express summary of the advisory lists them: run untrusted interview code only in a virtual machine, treat commands using curl, base64 or PowerShell with suspicion, open unfamiliar projects in Visual Studio Code's Restricted Mode, and after any infection assume every credential is compromised and rotate wallets from a clean device. These are cheap and repeatable, and they can be taught.
A parallel from the AI-security debate
The EFF's 17 September submission to lawmakers on AI-lab security makes an argument that transfers directly. It says: "Minimum safety requirements specific only to current AI technologies are likely to become obsolete; legal standards tied to well-established cybersecurity best practices are far more likely to stand the test of time." The EFF was writing about AI labs, not North Korea, but the logic is the same. A rule aimed at today's lure, whether a fake AI start-up or a fake blockchain firm, will be out of date when the recruiter persona changes. A standard anchored to sandboxing, logging and credential hygiene will not.
What Australian policy should do
First, turn the advisory into audience-specific guidance. The people most at risk are freelancers, contractors and early-career developers, and they do not read joint advisories. The ACSC is well placed to publish a short, plain-language version for them, and to work with universities and coding bootcamps.
Second, invest in the cooperation channel that produced this result. The lesson of WaterPlum is that the useful state capability is attribution and disruption, which depends on trusted information-sharing with partners such as Japan, Germany and the United States. Funding and legal certainty for that sharing beat new obligations on private intermediaries.
Third, keep any platform measure voluntary and outcome-based at first. Encourage reporting channels, fast takedown of accounts tied to published indicators, and warnings when a recruiter asks a candidate to run code. If evidence later shows voluntary measures failing, a targeted duty can be considered with a proper regulatory impact assessment.
The bottom line
WaterPlum is a real and well-documented theft campaign, and its victims deserve better protection. But the record from this advisory supports investing in attribution, disruption and practical hygiene, not in new verification mandates that the attackers can defeat with stolen identities and that would burden the legitimate open-hiring economy.