North Korean hackers linked to a group known as WaterPlum have infected more than 30,000 devices across the globe, and the victims are not just large corporations. Small and medium-sized businesses are firmly in the crosshairs. If you run a business with fewer than 500 employees and assume state-sponsored hackers have bigger targets to worry about, this campaign should change your thinking.
Who Are the WaterPlum Hackers and Why Should SMBs Care?
WaterPlum is a North Korean state-linked threat group that has been running sophisticated cyberattacks with a very specific goal: stealing credentials and financial data that can be monetised quickly. Unlike some nation-state actors who focus on espionage against governments, WaterPlum operates more like an organised criminal enterprise. They use infostealer malware — software designed to quietly harvest usernames, passwords, session tokens, and payment details from infected machines — and then sell or exploit that data for financial gain.
The reason this matters to SMBs is straightforward. Large enterprises have dedicated security teams, endpoint detection software, and rapid incident response. Smaller businesses often do not. That makes them easier to infect, easier to extract data from, and less likely to notice something has gone wrong until the damage is done. WaterPlum knows this. Many of the 30,000 infected devices belong to businesses that would never have expected to be a target.
How the Infection Spreads and What Gets Stolen
The WaterPlum campaign has relied heavily on social engineering and trojanised software — legitimate-looking applications that carry hidden malware. Employees at targeted businesses were tricked into downloading what appeared to be productivity tools, job-related documents, or software updates. Once installed, the malware runs silently in the background, collecting everything stored in browsers, password managers, and communication apps.
What gets stolen in these attacks is particularly damaging for businesses. Saved login credentials for cloud platforms, accounting software, email accounts, and internal tools end up bundled into what the cybersecurity industry calls infostealer logs. These logs are then sold on dark web markets or private Telegram channels, often within hours of the infection. By the time your IT team notices unusual activity, your credentials may already be in the hands of a buyer who is actively testing them against your systems.
This is precisely why monitoring what appears in those dumps matters just as much as preventing the infection itself. Detection speed is everything.
The Credential Exposure Risk Your Business Might Already Have
Here is something many business owners do not realise. Even if your own devices were never directly infected by WaterPlum, your credentials could still be compromised. Employees reuse passwords. They log into business accounts from personal devices. A contractor or supplier who was infected could expose login details that grant access to shared systems you both use.
Breachrr monitors breach databases, infostealer dumps, dark web markets, public code repositories, and domain infrastructure specifically to catch this kind of exposure before it becomes a breach. When a new dump surfaces containing credentials tied to your business domain, you need to know about it immediately — not weeks later when an attacker has already moved through your systems.
The WaterPlum campaign is a clear reminder that credential theft at scale is not a future threat. It is happening now, and the stolen data has a very short shelf life before someone puts it to use.
What to Do Right Now If You Run an SMB
The most important first step is knowing whether your business is already exposed. Do not assume you would have noticed. Infostealer infections are designed to be invisible, and credential dumps circulate on parts of the internet most business owners never see.
Reset passwords for any accounts where staff have access to sensitive systems, enforce multi-factor authentication wherever possible, and make sure employees understand the risk of downloading software from unverified sources. These are not new recommendations, but they become urgent when a campaign of this scale is actively harvesting credentials from businesses like yours.
North Korean hackers and groups like WaterPlum are not going away, and they will keep refining their methods. The businesses that stay ahead of them are the ones that treat credential monitoring as an ongoing process, not a one-time checkbox. Run a free audit at breachrr.com/audit to find out what is already exposed under your business domain — it takes minutes and could save you significantly more.
Want to see if your company is exposed?