Cybersecurity threats are no longer limited to malware exploiting software vulnerabilities or attackers breaking through internet facing systems.
Organizations are increasingly facing a different type of risk: legitimate people, devices, credentials, and remote work infrastructure being manipulated to create trusted access.
The recent dismantling of a North Korean laptop farm in Japan highlights this evolving threat.
Japanese authorities, working alongside organizations from the United States, Australia, and Germany, have detailed a broader North Korean cyber ecosystem involving fraudulent IT employment, fake recruitment operations, malware distribution, cryptocurrency theft, and remote access to systems through seemingly legitimate infrastructure.
The joint advisory identified the North Korean cyber actor WaterPlum, also known as Contagious Interview, as part of this activity. Authorities said the group infected at least 30,000 devices across more than 100 countries and obtained funds or credentials from more than 7,000 cryptocurrency wallets between December 2025 and July 2026. The advisory attributed approximately 1.7 billion Japanese yen, equivalent to about $10.71 million, in cryptocurrency transfers to North Korea.
The incident provides an important lesson for businesses: identity, recruitment, endpoint security, and third party risk are now deeply connected.
What Is a Laptop Farm?
A laptop farm is an arrangement in which multiple computers are physically hosted at a location controlled by an intermediary while being remotely operated by workers located elsewhere.
In the North Korean IT worker ecosystem, this arrangement can make an overseas operator appear to be working from the country where the computer is physically located.
U.S. authorities have previously documented cases in which company issued laptops were shipped to U.S. based facilitators and then made accessible to North Korean IT workers overseas. The arrangement allowed the remote workers to appear to employers as domestic employees while accessing corporate systems through devices physically located in the United States.
Japan’s recent investigation demonstrates that this type of infrastructure is not limited to the United States.
The Japanese National Police Agency reported the discovery and shutdown of a domestic laptop farm connected to North Korean IT worker activity. Japanese authorities also reported that significant amounts of money had moved through the network.
The Threat Is Bigger Than Employment Fraud
At first glance, fraudulent remote employment may appear primarily to be a human resources or compliance problem.
It is much more significant than that.
When a fraudulent worker successfully obtains employment, the individual may receive:
- A corporate laptop
- Corporate email access
- VPN credentials
- Access to internal applications
- Source code repositories
- Cloud services
- Customer information
- Development environments
- Collaboration platforms
- Privileged credentials
This creates a potential insider risk without requiring an attacker to exploit a traditional software vulnerability.
The FBI has warned that North Korean IT workers have used fraudulent identities to obtain employment and gain access to company networks. Authorities have also documented cases involving theft of sensitive company information and data extortion.
The security challenge is therefore not simply identifying malicious software.
It is determining whether the person, identity, device, location, and access associated with an employee are actually consistent with one another.
The Fake Recruitment Connection
The WaterPlum activity adds another layer to the threat.
According to the international advisory, WaterPlum actors have posed as prospective employers and targeted software developers and IT professionals with attractive job opportunities.
The group has impersonated or presented itself as organizations associated with artificial intelligence, cryptocurrency, and NFT technologies.
Job candidates were then exposed to malicious content during the recruitment process.
This creates a dangerous reversal of the traditional employment security model.
Normally, companies worry about malicious applicants attempting to enter their organizations.
In this campaign, attackers can instead impersonate companies and target legitimate professionals.
The recruitment process itself becomes the attack surface.
Technical Assessments Can Become an Attack Vector
Technical assessments are commonly used to evaluate software engineers and developers.
Candidates may be asked to download:
- Coding assignments
- Development projects
- Software packages
- Documentation
- Test environments
- Configuration files
- Collaboration tools
Attackers can abuse this trust by presenting malicious content as part of a legitimate recruitment process.
The current WaterPlum advisory describes attacks against developers, web designers, cryptocurrency specialists, blockchain professionals, and other IT workers.
This means organizations and professionals need to treat recruitment related digital interactions with the same caution applied to other forms of untrusted content.
Why Developers Are Attractive Targets
Developers frequently have access to highly valuable resources.
A developer’s workstation may contain:
- Source code
- API credentials
- Cloud access tokens
- SSH keys
- Database credentials
- Package manager credentials
- CI/CD access
- Cryptocurrency wallets
- Internal documentation
- Customer information
Compromising one developer can therefore provide an attacker with significantly more than access to a single endpoint.
It may create a pathway toward development infrastructure and enterprise systems.
This is particularly important for organizations operating large software development environments.
The Growing Risk of Trusted Access
Traditional security models often focus on preventing unauthorized users from entering an organization.
Modern attacks increasingly exploit another opportunity:
Make the attacker appear authorized.
A fraudulent employee may possess legitimate credentials.
A compromised laptop may be a genuine company issued device.
A remote connection may originate from a trusted residential network.
A third party staffing company may appear legitimate.
An email address may look authentic.
Individually, each signal can appear normal.
The risk becomes visible when organizations correlate all of them.
Identity Verification Must Go Beyond Documents
Organizations should strengthen identity verification throughout the employee lifecycle.
This includes more than checking an identity document during recruitment.
Security teams should consider:
- Identity consistency across recruitment platforms
- Verification of employment history
- Verification of physical location
- Device delivery address validation
- Background screening
- Consistency between identity and technical activity
- Authentication behavior
- Login geography
- Device characteristics
- Time zone patterns
- Unusual remote access activity
- Third party staffing practices
The FBI specifically recommends stronger due diligence for employees and contractors and has warned organizations about the risks associated with third party IT staffing arrangements.
Third Party Staffing Can Create Additional Risk
Many organizations use staffing agencies, outsourcing providers, contractors, and technology partners to expand their engineering teams.
These relationships can create additional security dependencies.
If the organization does not directly control the recruitment process, it may have less visibility into:
- Identity verification
- Background screening
- Employment history
- Device handling
- Geographic location
- Contractor onboarding
- Credential provisioning
- Access termination
The FBI has specifically highlighted third party staffing as an area that organizations should scrutinize because companies may be removed from parts of the direct hiring process.
Vendor risk management should therefore include workforce integrity and identity assurance.
Endpoint Security Is Still Critical
Even when an employee has been legitimately hired, their device remains an important security boundary.
Organizations should implement endpoint controls that can identify:
- Unauthorized remote access software
- Unexpected administrative activity
- Suspicious processes
- Unusual authentication behavior
- Configuration changes
- Malware
- Data exfiltration
- Unusual network connections
- Abnormal session activity
Endpoint detection and response should work together with identity and access monitoring.
A device that appears trustworthy should not automatically receive unrestricted access.
Zero Trust Becomes More Important
The laptop farm model reinforces an important Zero Trust principle:
Trust should not be based solely on where a device appears to be located.
An IP address or geographic location is only one security signal.
Organizations should continuously evaluate:
Who is accessing the system?
What device are they using?
Where is the device?
What application are they accessing?
What behavior is occurring?
Does the access match the person’s normal activity?
Does the requested access make sense for the employee’s role?
This approach reduces dependence on a single indicator such as a trusted IP address.
Protecting Source Code and Intellectual Property
The potential impact of fraudulent IT workers extends beyond financial loss.
Developers can have access to highly sensitive intellectual property.
This may include:
- Proprietary software
- Product roadmaps
- Algorithms
- AI models
- Customer databases
- Infrastructure configurations
- Security architecture
- Internal APIs
- Build pipelines
Organizations should therefore apply strong access controls to development environments.
Recommended measures include:
- Least privilege access
- Strong MFA
- Privileged access management
- Repository access monitoring
- Secret scanning
- Source code monitoring
- Network segmentation
- Device compliance checks
- Just in time access
- Continuous authentication
Cryptocurrency Organizations Face Additional Exposure
The WaterPlum campaign specifically targeted cryptocurrency and blockchain professionals, while authorities reported the compromise of more than 7,000 cryptocurrency wallets.
Organizations operating in the cryptocurrency ecosystem should therefore consider security across both corporate infrastructure and digital asset environments.
Security programs should include:
- Wallet security
- Key management
- Transaction monitoring
- Developer workstation protection
- API security
- Cloud security
- Identity management
- Code repository protection
- Smart contract security
- Incident response
High value transactions should receive additional authorization and verification.
AI and Web3 Companies Should Be Especially Vigilant
The campaign’s use of fake organizations associated with AI, cryptocurrency, and NFT technologies demonstrates how attackers can exploit industries where remote hiring and specialized technical talent are common.
Technology companies should carefully validate recruitment communications and technical assessments.
Candidates should also verify that a recruiter, company, domain, repository, and technical assignment are legitimate before installing unfamiliar software or executing code.
Industries That Should Strengthen Their Defenses
Financial Services and Banking
Financial institutions employ large technology teams and provide access to sensitive financial systems and customer information.
COE Security can help financial organizations strengthen identity security, endpoint protection, privileged access management, application security, threat detection, and continuous monitoring.
Healthcare and Life Sciences
Healthcare organizations increasingly depend on developers, contractors, cloud services, and third party technology providers.
COE Security can help protect sensitive healthcare environments through identity assessments, endpoint security reviews, application penetration testing, cloud security assessments, data governance, and compliance programs.
Retail and E-commerce
Retail businesses rely heavily on software development, payment systems, customer platforms, APIs, and third party technology providers.
COE Security can help assess applications, APIs, cloud environments, developer access, identity controls, and digital supply chain risks.
Manufacturing and Industrial Organizations
Manufacturers increasingly depend on connected software environments, cloud platforms, engineering applications, and external technology providers.
COE Security can help evaluate network security, application security, identity controls, cloud infrastructure, connected environments, and third party risks.
Government and Public Sector
Government organizations often manage highly sensitive systems and depend on contractors and technology providers.
COE Security can help strengthen identity management, application security, cloud security, network protection, monitoring, penetration testing, and compliance readiness.
Technology and SaaS Companies
Technology and SaaS organizations are particularly dependent on software developers, contractors, remote teams, source code repositories, APIs, and cloud infrastructure.
COE Security can help these organizations conduct application and API penetration testing, cloud assessments, source code security reviews, identity assessments, supply chain security assessments, and continuous threat monitoring.
Practical Security Measures for Organizations
Organizations can reduce exposure to fraudulent remote worker and laptop farm schemes by implementing a combination of technical, operational, and governance controls.
Recruitment Security
Verify identities, employment histories, locations, references, and third party staffing arrangements.
Device Security
Require managed corporate devices, endpoint detection, device compliance checks, and restrictions on unauthorized remote access software.
Identity Security
Implement phishing resistant MFA, least privilege, privileged access management, and continuous authentication.
Network Security
Segment critical environments and monitor unusual remote connections and authentication patterns.
Data Security
Restrict access to sensitive source code, intellectual property, customer data, and production environments.
Developer Security
Protect repositories, CI/CD pipelines, package registries, API credentials, cloud accounts, and development environments.
Continuous Monitoring
Correlate identity, endpoint, network, and application telemetry to identify suspicious behavior.
Third Party Risk Management
Assess staffing agencies, contractors, outsourcing companies, and technology partners before granting access to enterprise systems.
Incident Response
Establish procedures for rapidly disabling suspicious accounts, isolating devices, rotating credentials, investigating access activity, and preserving evidence.
The Bigger Cybersecurity Lesson
The Japanese laptop farm investigation demonstrates that cybersecurity risk can enter an organization through legitimate business processes.
Hiring can become an attack surface.
Remote work can become an attack surface.
Contractor relationships can become an attack surface.
Developer environments can become an attack surface.
Even a company issued laptop can become part of an adversary’s infrastructure if identity and access controls are not sufficiently strong.
The solution is not to eliminate remote work or external contractors.
The solution is to build security controls that assume identities, devices, and access can be manipulated.
Organizations need visibility across the complete lifecycle:
Recruitment → Identity Verification → Device Provisioning → Access Management → Monitoring → Offboarding
Security must be present at every stage.
Conclusion
The dismantling of a North Korean laptop farm in Japan and the wider WaterPlum campaign demonstrate how modern cyber threats increasingly combine social engineering, identity fraud, remote work, malware, cryptocurrency theft, and legitimate enterprise access.
The threat is particularly significant because traditional perimeter defenses may not detect an attacker who is operating through an apparently legitimate employee identity and a company issued device.
Organizations should therefore expand their security programs beyond traditional network protection.
Identity verification, endpoint security, Zero Trust architecture, privileged access management, developer security, third party risk management, continuous monitoring, and strong incident response all play an important role in reducing exposure.
For businesses, the key question is no longer simply whether a device is connected to the corporate network.
It is whether the organization can confidently establish who is operating the device, where they are operating from, what they are accessing, and whether their behavior is consistent with legitimate business activity.
About COE Security
COE Security partners with organizations in financial services, healthcare, retail, manufacturing, and government to secure AI-powered systems and ensure compliance.
Our offerings include:
• AI-enhanced threat detection and real-time monitoring
• Data governance aligned with GDPR, HIPAA, and PCI DSS
• Secure model validation to guard against adversarial attacks
• Customized training to embed AI security best practices
• Penetration Testing (Mobile, Web, AI, Product, IoT, Network & Cloud)
• Secure Software Development Consulting (SSDLC)
• Customized CyberSecurity Services
• Follow COE Security on LinkedIn for ongoing insights into safe, compliant AI adoption.
In addition, COE Security helps organizations address identity-based threats, fraudulent remote worker risks, insider threats, and third party workforce security through:
• Identity and Access Management assessments
• Privileged access and least privilege reviews
• Endpoint and workstation security assessments
• Remote workforce security assessments
• Third party and contractor risk assessments
• Application, API, cloud, network, and infrastructure penetration testing
• Developer and source code security assessments
• Secure CI/CD and software development reviews
• Threat detection and continuous security monitoring
• Incident response and cyber resilience assessments
• AI security and adversarial testing
• Compliance assessments aligned with applicable regulatory and security requirements
For financial services and banking organizations, COE Security helps protect financial applications, customer information, privileged accounts, developer environments, and transaction infrastructure.
For healthcare and life sciences organizations, we help protect sensitive data, applications, cloud systems, identities, and third party integrations while supporting security and compliance requirements.
For retail and e-commerce organizations, we help secure payment applications, APIs, cloud environments, customer platforms, developer systems, and third party technology ecosystems.
For manufacturing and industrial organizations, we help assess connected infrastructure, enterprise applications, cloud environments, identity systems, and supplier related cybersecurity risks.
For government and public sector organizations, we help strengthen identity security, application security, network protection, cloud security, monitoring, penetration testing, and compliance programs.
For technology, SaaS, AI, cryptocurrency, and Web3 organizations, we help secure developer environments, source code repositories, APIs, cloud infrastructure, digital assets, CI/CD pipelines, and remote workforce ecosystems.
COE Security helps organizations build security into their people, processes, applications, infrastructure, and technology ecosystems so they can reduce cyber risk while maintaining compliance and operational resilience.
Follow COE Security on LinkedIn for ongoing insights into safe, compliant AI adoption, emerging cyber threats, identity security, AI security, and practical cybersecurity strategies to help your organization stay updated and cyber safe.
Click to read our LinkedIn feature article