日本の警察庁や国家サイバー統括室などは、2026年9月18日に共同で発表を行いました。発表によると、北朝鮮に関係するハッカー集団「ウオータープラム」が、日本を含む100以上の国や地域のIT技術者を標的にサイバー攻撃を行いました。彼らは少なくとも17億円に相当する暗号資産のデータを盗み取り、北朝鮮へ不正に送金していたとされています。
Japan's National Police Agency and the National Cyber Security Office issued a joint announcement on September 18, 2026. According to the announcement, "Water Plum," a cyberattack group linked to North Korea, targeted IT engineers in more than 100 countries and regions, including Japan. They allegedly stole cryptocurrency data worth at least 1.7 billion yen and illegally transferred the funds to North Korea.
さらに、北朝鮮側が日本国内にいる支援者のパソコンなどの端末を遠隔操作し、外貨を獲得しようとする新たな手口も明らかになりました。この方法により、日本国内のネットワークを悪用して資金を集めていたとみられています。
Furthermore, a new method was revealed in which North Korea remotely controlled devices such as computers belonging to supporters within Japan to acquire foreign currency. This method is believed to have exploited domestic networks in Japan to gather funds.
今回の公表は、サイバー攻撃を行った国や組織を特定して非難することで、今後の攻撃を防ぐ「パブリック・アトリビューション(PA)」と呼ばれる取り組みです。日本だけでなく、アメリカ、オーストラリア、ドイツの政府機関と合同でこの情報を明らかにしました。
This public disclosure is an initiative known as "Public Attribution (PA)," which aims to deter future attacks by identifying and condemning the countries or organizations responsible for cyberattacks. Japan revealed this information in cooperation with government agencies from the United States, Australia, and Germany.
警察庁などは、今回の組織的なサイバー攻撃において、朝鮮労働党中央委員会の「軍需工業部門」が中心となって計画や実行を主導したと分析しています。
The National Police Agency and other authorities analyze that the "Military-Industrial Department" of the Central Committee of the Workers' Party of Korea played a central role in planning and executing this organized cyberattack.