Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
iC3

iC3 Vendor Cyber Rating & Cyber Score

ic3.ca

At iC3 it is our mission to help business leaders reach their full potential. We aim to help people and their businesses flourish. We accomplish this by improving staff performance, increasing client loyalty, and maximizing effective business partnerships.


iC3 A.I CyberSecurity Scoring

iC3
Company Information
Website:https://ic3.ca
Employees number:18
Number of followers:1,017
NAICS:5416
Industry Type:Business Consulting and Services
Homepage:ic3.ca
iC3 Risk Score (AI oriented)
Between 650 and 699
logo
iC3Business Consulting and Services
Updated:
19/09/2026
689/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
iC3 Global Score (TPRM)
xxxx
logo
iC3Business Consulting and Services
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

iC3Weak
Current Score
689B (WEAK)
01000
1 incidents
-59 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
749Before Incident
Cyber Attack
19 Sep 2026iC3
IC3: North Korean WaterPlum Hackers Target IT Professionals With Fake Job Interviews to Steal Crypto

North Korean Hackers Infect 30,000 Devices in Global Cyberespionage Campaign

690After Incident
CRITICAL-59
IC31789813437
North Korean Hackers Infect 30,000 Devices in Global Cyberespionage Campaign North Korean threat actors, tracked as WaterPlum (also known as Contagious Interview), have compromised at least 30,000 devices across over 100 countries by exploiting job recruitment schemes targeting software developers, IT professionals, and cryptocurrency specialists. The campaign, active in recent months, has resulted in the theft of $10.71 million (JPY 1.7 billion) from over 7,000 cryptocurrency wallets, according to reports from the IC3 (Internet Crime Complaint Center). ### Attack Methodology WaterPlum operators engage victims through social media, job portals, freelance platforms, and recruitment services, posing as legitimate AI, blockchain, or NFT companies. The attackers lure targets with fake job interviews, often requesting coding assignments or troubleshooting tasks under the guise of technical evaluations. Malicious files disguised as necessary tools for development or video conferencing are hosted on code repositories and collaboration platforms, making them appear credible to tech-savvy victims. In some cases, attackers used AI face-swapping software during interviews, later disabling video feeds to avoid detection. ### Malware Arsenal The campaign deploys multiple malware strains, including: - BeaverTail – JavaScript-based malware hidden in npm packages. - InvisibleFerret – A Python backdoor for remote access. - OtterCookie – A remote access Trojan (RAT) and infostealer that exfiltrates sensitive data. - StoatWaffle – Malicious Visual Studio Code projects that execute code via configuration files (e.g., `.vscode/tasks.json`). Once installed, the malware harvests browser credentials, cryptocurrency wallet keys, seed phrases, screenshots, keystrokes, and sensitive files, enabling further compromise of victims’ employers, clients, or projects. ### Broader Implications Authorities link WaterPlum to DPRK IT-worker schemes, where North Korean operatives use laptop farms and virtual private servers (VPS) to obscure their locations, secure overseas contracts, and launder illicit earnings. Japanese investigators found overlapping IP addresses between WaterPlum and suspected North Korean IT workers accessing crowdsourcing platforms. The stolen credentials and access tokens pose risks of corporate espionage, intellectual property theft, lateral movement within networks, and extortion. Security experts warn that compromised developers could inadvertently grant attackers access to enterprise systems, customer data, and ongoing projects.
INCIDENT DETAILS -
TYPE
Cyberespionage, Cryptocurrency Theft, Malware Deployment
MOTIVATION
Financial GainEspionageIntellectual Property Theft
IMPACT
Financial Loss: $10.71 million (JPY 1.7 billion)Browser CredentialsCryptocurrency Wallet KeysSeed PhrasesScreenshotsKeystrokesSensitive FilesSystems Affected: 30,000+ devices across 100+ countriesOperational Impact: Risk of Corporate Espionage, Lateral Movement in Networks, ExtortionIdentity Theft Risk: High (Personally Identifiable Information, Cryptocurrency Wallet Access)Payment Information Risk: High (Cryptocurrency Wallet Compromise)
DATA BREACH
Browser CredentialsCryptocurrency Wallet KeysSeed PhrasesScreenshotsKeystrokesSensitive FilesSensitivity Of Data: High (Personally Identifiable Information, Financial Data, Intellectual Property)Data Exfiltration: YesPersonally Identifiable Information: Yes (Browser Credentials, Cryptocurrency Wallet Access)
AUGUST 2026
749Before Incident
JULY 2026
749Before Incident
JUNE 2026
749Before Incident
MAY 2026
749Before Incident
APRIL 2026
749Before Incident
MARCH 2026
749Before Incident
FEBRUARY 2026
749Before Incident
JANUARY 2026
749Before Incident
DECEMBER 2025
749Before Incident
NOVEMBER 2025
749Before Incident
OCTOBER 2025
749Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for iC3 ?
?
What was iC3's A.I Rankiteo Cyber Score in August 2026 ?
?
What was iC3's A.I Rankiteo Cyber Score in July 2026 ?
?
What was iC3's A.I Rankiteo Cyber Score in June 2026 ?
?
What was iC3's A.I Rankiteo Cyber Score in May 2026 ?
?
What was iC3's A.I Rankiteo Cyber Score in April 2026 ?
?
What was iC3's A.I Rankiteo Cyber Score in March 2026 ?
?
What was iC3's A.I Rankiteo Cyber Score in February 2026 ?
?
What was iC3's A.I Rankiteo Cyber Score in January 2026 ?
?
What was iC3's A.I Rankiteo Cyber Score in December 2025 ?
?
What was iC3's A.I Rankiteo Cyber Score in November 2025 ?
?
What was iC3's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on iC3's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with iC3 ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view iC3's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?