Japan just raided the first North Korean laptop farm on its soil.
The United States, Japan, Germany, and Australia published a joint report on the WaterPlum campaign, and the picture is ugly for anyone who still treats a mailed laptop as proof of a person. Facilitators collect employer hardware, stack it in apartments and offices, then hand remote control to operators who never sat in your interview. If your cybersecurity program starts after the box ships, you already lost the identity fight.

Facilitators Beat Background Checks
Laptop farms are a staffing product. A recruiter presents a polished contractor. You mail a company notebook to an address that matches the resume. A local cutout plugs it in, keeps it online, and tunnels the session to operators working for Pyongyang. Payroll hits a mule account. The regime gets hard currency. You get commits from a keyboard you never met.
Japanese police taking down a farm makes the scheme physical. You can picture the shelf, the power strips, the labeled machines with your asset tags still on the lids. Until a raid hits local news, a lot of teams file DPRK IT workers under resume fraud and move on. Hardware you issued, sitting in a closet you do not own, is an asset-control failure with a payroll feed attached.
HR is not built for this. Background checks grind on name, tax ID, and LinkedIn tenure. Video interviews prove a face can talk. A face on a call is cheap. The serial number in the same room as that face is the control you actually need.
This is a bad look for companies that brag about zero trust and then treat a shipping confirmation as an identity signal.
The same week, Malwarebytes mapped more than 100 fake AI subscription shops built from a $249 toolkit. The sites lean on a genuine Google sign-in screen, then bill people up to $2,000 a year for unverified tools wearing names that sound like real products. The chrome is authentic. The merchant is not. Users trust the Google prompt the same way hiring managers trust a corporate laptop checking in from “home.”

Cybersecurity Ignores the Shipping Label
Most cyber security stacks hunt the noisy stuff. Brute-force against the VPN. Odd user-agents. Fresh malware hashes. A farm session is quiet on purpose. The device is yours. The certificates are valid. The user passed SSO. Threat detection that keys on failed logins will file this under healthy remote work.
Your firewall sees an expected endpoint. Threat-protection agents report a healthy posture. Defense in depth looks complete on the architecture slide while every tool stares at a laptop doing exactly what you asked, from a closet you do not own.
WaterPlum is a business process that rents your hardware as the jump box. Once the machine is on the farm, every repo clone, every admin ticket, every production change looks like insider activity because, on paper, it is. Your logs will show a good employee. Your finance system will show a good contractor. The only ugly record is the ship-to address, and security rarely gets that feed.
If you wait for incident response to discover the farm, you are reconstructing months of privileged work from a device you cheerfully mailed out.
Presence Checks Belong in Hiring
You do not need a new platform for this. You need a few ugly checks that hiring and IT already have the data for.
Start today.
- Reconcile ship-to addresses against claimed home addresses for every remote machine issued in the last 24 months. Clusters at one residential or commercial site are the farm signature.
- Pull VPN, MDM, and SSO logs for devices that stay online twenty hours a day with input patterns that never match the time zone on the offer letter.
- Freeze standing privileged access for contractors until someone you trust has seen the person and the serial number together, or an equivalent attested process for truly remote markets.
- Watch payroll and tax forms for mule patterns: new bank accounts, repeated addresses across “unrelated” hires, contractors who refuse camera-on standups while the laptop is supposedly at home.
- Treat a suspected farm as a combined insider and external-access case. Revoke certs, rotate secrets the account touched, and preserve a disk image if you can recover the hardware.
Ongoing security hardening belongs in the hiring loop, not a quarterly audit. Bind device serials to identity proofing. Require periodic live presence checks for roles that can push code or change identity policy. Give security the same ship-to feed HR already has. If two “employees” route through one public IP and one street address, that is a case.
Stop mailing admin-capable laptops to addresses you have never verified. First-week access should be a jailed workspace. Production credentials wait until presence is proven. That is slower hiring. It is also how you keep a warehouse of keyboards out of your tenant.
WaterPlum will not be the last brand on this model. The farm works because you already paid for the laptop, the license, and the trust.
Cut the trust at the dock.
Sources
- Japan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme
- Scammers use genuine Google sign-ins to sell costly, unverified AI subscriptions
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
