313SEC A.I CyberSecurity Scoring
313SEC
Company Information
Website:https://www.313sec.com
Employees number:3
Number of followers:36
NAICS:5415
Industry Type:IT Services and IT Consulting
Homepage:313sec.com
313SEC Risk Score (AI oriented)
Between 650 and 699
313SECIT Services and IT Consulting
Updated:
22/09/2026
22/09/2026
664/1000
Weak
B
313SEC Global Score (TPRM)
xxxx
313SECIT Services and IT Consulting
Score locked

313SECWeak
Current Score
664B (WEAK)
01000
2 incidents
-51.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
665
SEPTEMBER 2026
708
Cyber Attack
18 Sep 2026 • 313SEC
313 General Bureau of the Munitions Industry Department: International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data
North Korean Hackers Target Job Seekers in Global Cyberespionage and Crypto Theft Scheme
664
CRITICAL-44
3131789748656
North Korean Hackers Target Job Seekers in Global Cyberespionage and Crypto Theft Scheme
U.S. and allied government agencies issued a joint warning on Friday, exposing a sophisticated cyber campaign by North Korean hackers known as WaterPlum (or Contagious Interview) who are infiltrating the networks of tens of thousands of job seekers worldwide. Operating under the 313 General Bureau of the Munitions Industry Department, the group poses as legitimate employers, particularly in AI, cryptocurrency, and NFT sectors, to deceive software developers and IT professionals into downloading malware.
The hackers often impersonate recruiters or use third-party hiring platforms, while some members also work as North Korean IT workers, developing web systems for corporate clients. This dual approach allows them to blend in with legitimate operations while siphoning sensitive data and cryptocurrency. According to the alert issued by agencies in Japan, Australia, Germany, the FBI, and the U.S. Department of Defense’s Cyber Crime Center WaterPlum has compromised over 30,000 devices across 100+ countries, with primary targets in Japan, the U.S., and Europe.
The group’s activities have enabled the theft of nearly $11 million in cryptocurrency from over 7,000 wallets, with funds funneled back to North Korea to support broader cyber operations. Investigations revealed significant overlap between WaterPlum and North Korean IT workers, including shared infrastructure, such as IP addresses used for laptop farms and cloud services.
Authorities have made progress in disrupting the network, including Japan’s first successful dismantling of a laptop farm linked to the group, which facilitated the transfer of hundreds of millions of yen in crypto to foreign accounts. The FBI continues to pursue U.S.-based enablers providing support to North Korean IT workers. The warning coincides with a UN sanctions report exposing thousands of North Korean nationals employed globally in tech and other industries, further highlighting the regime’s reliance on cybercrime for revenue.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
AUGUST 2026
707
JULY 2026
706
JUNE 2026
704
MAY 2026
703
APRIL 2026
701
MARCH 2026
700
FEBRUARY 2026
698
JANUARY 2026
696
DECEMBER 2025
752
Cyber Attack
01 Dec 2025 • 313SEC
313 General Bureau: North Korean Attackers Hit 30,000 Devices and Steal $10.7m
North Korea’s WaterPlum Group Steals $10.7M in Crypto via Fake Job Scams
693
CRITICAL-59
3131790087037
North Korea’s WaterPlum Group Steals $10.7M in Crypto via Fake Job Scams
A joint advisory by Japan’s National Police Agency (NPA), the FBI, Australia’s ACSC, Germany’s BND and BfV, and the U.S. Defense Department’s Cyber Crime Center reveals that North Korea’s WaterPlum (aka Contagious Interview) hacking group compromised 30,000 devices across 100+ countries between December 2025 and July 2026, siphoning funds from 7,000+ cryptocurrency wallets and funneling $10.7 million (JPY 1.7 billion) to Pyongyang.
The group, linked to North Korea’s 313 General Bureau under the Munitions Industry Department, targeted web designers, engineers, and Web3/cryptocurrency specialists through fake job interviews. Posing as employers from AI, crypto, or NFT firms, WaterPlum actors recruited victims via social media, job boards, and freelance platforms, tricking them into downloading malicious NPM packages (e.g., BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, StoatWaffel) during technical assessments.
StoatWaffel, a key malware strain, was embedded in blockchain-themed Visual Studio Code projects, executing automatically when victims opened the files. Once infected, devices were hijacked with remote access trojans and infostealers, harvesting browser credentials, keystrokes, wallet private keys, seed phrases, and ID documents. The attacks also provided a foothold into victims’ employers.
The advisory highlights overlap between WaterPlum and North Korea’s IT worker scheme, with some hackers doubling as fraudulent freelancers. Both groups used the same IP addresses to access laptop farms remote setups where North Korean operatives control employment devices using stolen identities and virtual private servers. Japanese authorities dismantled a laptop farm for the first time, uncovering evidence of hundreds of millions of yen moved abroad, including crypto.
Some North Korean IT workers turned destructive after hiring, with incidents including extortion, source code leaks, and website defacements. The advisory notes that one worker published a company’s proprietary code after a payment dispute, while another took a client’s site offline.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
NOVEMBER 2025
752
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for 313SEC ??
What was 313SEC's A.I Rankiteo Cyber Score in September 2026 ??
What was 313SEC's A.I Rankiteo Cyber Score in August 2026 ??
What was 313SEC's A.I Rankiteo Cyber Score in July 2026 ??
What was 313SEC's A.I Rankiteo Cyber Score in June 2026 ??
What was 313SEC's A.I Rankiteo Cyber Score in May 2026 ??
What was 313SEC's A.I Rankiteo Cyber Score in April 2026 ??
What was 313SEC's A.I Rankiteo Cyber Score in March 2026 ??
What was 313SEC's A.I Rankiteo Cyber Score in February 2026 ??
What was 313SEC's A.I Rankiteo Cyber Score in January 2026 ??
What was 313SEC's A.I Rankiteo Cyber Score in December 2025 ??
What was 313SEC's A.I Rankiteo Cyber Score in November 2025 ??
What is the average per-incident point impact on 313SEC's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with 313SEC ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view 313SEC's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?