📰 Key Summary
North Korean hackers have compromised devices across more than 100 countries and regions worldwide by posing as online job interviewers, tricking job seekers into running malware to steal cryptocurrency. Japanese authorities report that North Korean actors gained access to over 30,000 devices globally between late 2025 and July 2026, targeting tech industry workers, with the campaign resulting in over $10 million in stolen cryptocurrency. See the original article for full details.
💬 JudyAI Lab Take
North Korean hackers posing as job interviewers have compromised roughly 30,000 devices across more than 100 countries, stealing over $10 million in cryptocurrency — a clear sign that supply-chain-style attacks have moved beyond corporate systems and onto job seekers’ personal devices.
This incident points to a trend AI builders should pay attention to: attackers aren’t just targeting servers or wallet contracts anymore — they’re exploiting “human trust” as the entry point, using fake interview processes to trick targets into running malware themselves. As AI tools drive down the cost of producing phishing scripts, fake resumes, and fake company websites, social engineering attacks are scaling up faster too. For developers, this means your local dev environment itself is an attack surface — any unverified executable or script can be an entry point, not just a matter of leaked API keys.
Next time you get a “take-home assignment” or “technical test” that asks you to run code locally, verify the source and behavior in an isolated environment or VM before executing it.
📅 Original Article Info
- Published: 2026-09-19T00:05
- Source: https://asia.nikkei.com/spotlight/society/crime/north-korean-hackers-disguise-cyberattacks-as-job-interviews-with-ai