Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallWaterPlum, also known as Contagious Interview, is a North Korean cyber actor that targets IT professionals and job seekers. The FBI’s 2026 cyber-alert index says the group infiltrates victims’ computer networks to collect sensitive information and steal cryptocurrency. The FBI reports victims in Japan, the United States, Europe and other countries. The threat goes beyond malicious messages or exposed servers: a job application, interview or legitimate employee account can become a route into a company’s systems.
What are WaterPlum and Contagious Interview?
WaterPlum is the name used in the FBI’s 2026 cyber-alert index for a North Korean actor also commonly called Contagious Interview. Its targeting of IT professionals makes job seekers and developers important parts of the threat picture, not just the organizations that employ them.
WaterPlum is also part of a wider North Korean operation. U.S. and allied government advisories describe North Korean IT workers obtaining remote jobs using fabricated identities, then abusing access to support espionage, data theft, extortion and revenue generation. That wider activity provides context, but it does not mean every fraudulent remote worker is WaterPlum or that every activity attributed to North Korean IT workers belongs to this one actor.
How fake IT-worker operations can reach company data
The risk can develop over several stages. Hiring gives a person access that a typical outside attacker would have to break in to obtain; later misuse of that access can expose data or enable additional criminal activity.
#1 Best Overall
1. Build a convincing identity
Operators may use stolen or synthetic identities, fraudulent credentials, reused phone numbers and email addresses, and AI-generated personas. Authorities also warn of face-swapping during interviews. A polished resume or successful video call alone therefore does not establish that the applicant is who they claim to be.
2. Get hired and obtain legitimate access
Once hired, a worker may receive a company laptop, accounts, source-code access, cloud permissions and payment channels. The access is legitimate; the deception lies in who is using it and what they do with it. FBI guidance flags multiple-country logins and changes to a worker’s address or payment platform as warning signs.
3. Collect credentials, code and other information
With access, a malicious insider can copy GitHub repositories to personal accounts, harvest credentials or browser session cookies, exfiltrate proprietary data, or introduce malware. The FBI has also reported North Korean IT workers using unlawful company-network access to extract sensitive information and facilitate cybercrime.
4. Extort or monetize what was taken
Stolen code and data may be held for ransom. Treasury has described virtual-currency exchanges being used to manage and remit contract proceeds, while the Justice Department has documented separate APT38 cryptocurrency thefts and laundering. These are related parts of a broader North Korean cyber-financing picture, not evidence that every fake-worker case involves cryptocurrency theft.
Recommended Free Tools
Rank #3
What the reported figures measure
Government reports describe different parts of North Korean cyber activity, across different periods and scopes. The figures below should not be added together: they measure distinct activity and are not presented as a single, comparable accounting.
| Reported figure | Source and scope |
|---|---|
| More than US$2.8 billion in cryptocurrency stolen since January 2024 | Australian Department of Foreign Affairs and Trade, 2026; a cumulative amount since January 2024. |
| US$300 million to US$800 million in revenue in 2024 | Australian Department of Foreign Affairs and Trade, 2026; an estimate for revenue during 2024. |
| More than 136 U.S. victim companies and more than US$2.2 million in revenue | U.S. Department of Justice, 2025; figures concerning the IT-worker activity described by DOJ. |
| Approximately US$37 million, US$100 million, US$138 million and US$107 million | U.S. Department of Justice, 2025; amounts from separate APT38 thefts in 2023, not totals attributed here to WaterPlum. |
How companies can detect and disrupt a fake-worker risk
Defenses need to cover the full employment lifecycle. Identity checks reduce the chance of fraudulent hiring; access controls and monitoring limit damage if an identity or account slips through.
Rank #4
Verify identity throughout hiring
- Compare the applicant’s resume, credentials, phone number, email address and address for inconsistencies or reuse.
- Recheck identity during interviews, onboarding and employment, particularly when contact, location or payment details change.
- Audit staffing and recruiting firms, and complete as much of the hiring process in person as practical.
- Treat AI-generated personas and possible face-swapping as reasons to use stronger, multi-step identity assurance—not as proof of fraud by themselves.
Limit what each account and device can do
- Apply least privilege to accounts, repositories, cloud services and payment workflows; grant only the access needed for the role.
- Restrict local administrator rights and block unapproved remote-desktop software.
- Protect source code and credentials, and watch for repository copies to personal accounts, unusual cloud transfers, credential access and suspicious browser-session activity.
Monitor for behavior that does not fit the role
- Investigate logins from multiple countries, unexpected changes in login geography, and unusual session behavior.
- Monitor endpoint software, cloud transfers, source-code repositories and account activity together; isolated signals may be harder to interpret.
- Review changes to addresses and payment platforms through a separate verification channel.
- Preserve relevant evidence and report suspected activity to the FBI’s Internet Crime Complaint Center.
What to do if you suspect a fraudulent remote worker
- Contain access: Follow your incident-response process to restrict or suspend affected accounts and sessions, and protect repositories, cloud resources and payment workflows.
- Preserve evidence: Retain relevant account, endpoint, repository, cloud-transfer and hiring records for investigation.
- Investigate the timeline: Correlate identity and payment changes with logins, session activity, code access, software installations and data transfers.
- Report suspected activity: The FBI advises reporting suspected North Korean IT-worker activity to its Internet Crime Complaint Center.
The core defensive question is not only whether an account passed authentication. It is whether the person behind it was verified, whether their access matches their work, and whether their activity remains consistent with that role.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.

