{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-linkedin-recruiter-lure-at-wallet-vendor-ginco-led-to-308m-dmm-bitcoin-t"},"incident":{"title":"LinkedIn recruiter lure at wallet vendor Ginco led to $308M DMM Bitcoin theft","date":"2024-05","date_precision":"month","victim_org":"DMM Bitcoin, via wallet software vendor Ginco","sector":"Cryptocurrency","country":"Japan","primary_vector":"Fake Job Offer / Recruitment Lure","secondary_vectors":["Vendor / Supply Chain Impersonation"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported in the joint FBI, DC3 and NPA advisory.","outcomes":["Cryptocurrency Theft","Supply Chain Compromise"],"loss_usd":308000000,"loss_note":"4,502.9 BTC, valued at approximately $308 million in the joint FBI/DC3/NPA advisory; Japanese reporting at the time cited roughly $305 million. DMM Bitcoin subsequently wound down, transferring assets to SBI VC Trade.","records_affected":null,"threat_actor":"TraderTraitor (DPRK), per FBI, DC3 and Japan's National Police Agency","summary":"Japanese exchange DMM Bitcoin lost 4,502.9 BTC, about $308 million, in late May 2024. A joint advisory from the FBI, DoD Cyber Crime Center and Japan's National Police Agency traced the intrusion to March 2024, when a North Korean operative posing as a recruiter on LinkedIn contacted an employee of Ginco, the wallet software vendor DMM relied on. The theft was attributed to the TraderTraitor cluster.","how_it_worked":"The recruiter pretext delivered a malicious Python script hosted on GitHub, framed as a pre-employment coding assessment. The Ginco employee copied the script into their own GitHub account to work on it, which handed the attacker access to session cookie data. Using those session cookies the attacker impersonated the employee and compromised Ginco's unencrypted internal communications system. From there they waited: in late May a DMM Bitcoin employee submitted a legitimate transaction request through Ginco's system, and the attacker altered it in flight so that the withdrawal, which carried valid authorisation from DMM's side, sent 4,502.9 BTC to attacker-controlled addresses.","lessons":"Take-home coding tasks must be isolated from corporate identity and never touched by an account with production session access, and transaction requests should be verified against an independent channel between exchange and custody vendor before signing.","confidence":"Confirmed","sources":[{"title":"FBI, DC3, and NPA Identification of North Korean Cyber Actors, Tracked as TraderTraitor, Responsible for Theft of $308 Million USD from Bitcoin.DMM.com","url":"https://www.fbi.gov/news/press-releases/fbi-dc3-and-npa-identification-of-north-korean-cyber-actors-tracked-as-tradertraitor-responsible-for-theft-of-308-million-from-bitcoindmmcom","publisher":"Federal Bureau of Investigation"},{"title":"FBI reveals North Korea used LinkedIn to steal $305 million from Japan's DMM Bitcoin","url":"https://cryptoslate.com/fbi-reveals-north-korea-used-linkedin-to-steal-305-million-from-japans-dmm-bitcoin/","publisher":"CryptoSlate"}],"entry_type":"incident","slug":"2024-linkedin-recruiter-lure-at-wallet-vendor-ginco-led-to-308m-dmm-bitcoin-t","year":2024,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-linkedin-recruiter-lure-at-wallet-vendor-ginco-led-to-308m-dmm-bitcoin-t"}}