{"id":35474,"date":"2026-07-26T06:20:57","date_gmt":"2026-07-26T06:20:57","guid":{"rendered":"https:\/\/bitunikey.com\/news\/binance-tests-staff-monthly-with-fake-phishing-attacks\/"},"modified":"2026-07-26T06:21:17","modified_gmt":"2026-07-26T06:21:17","slug":"binance-tests-staff-monthly-with-fake-phishing-attacks","status":"publish","type":"post","link":"https:\/\/bitunikey.com\/news\/binance-tests-staff-monthly-with-fake-phishing-attacks\/","title":{"rendered":"Binance tests staff monthly with fake phishing attacks"},"content":{"rendered":"<p><\/p>\n<div class=\"post-detail__content blocks\">\n<p class=\"is-style-lead\">Binance runs simulated phishing attacks against its employees every month to reduce social engineering risks.\u00a0<\/p>\n<div id=\"cn-block-summary-block_5a736389d4901f28ba5f16297368e55c\" class=\"cn-block-summary\">\n<div class=\"cn-block-summary__nav tabs\">\n        <span class=\"tabs__item is-selected\">Summary<\/span>\n    <\/div>\n<div class=\"cn-block-summary__content\">\n<ul class=\"wp-block-list\">\n<li>Binance runs monthly phishing simulations to measure employee awareness and identify weak security habits early.<\/li>\n<li>Workers who fail receive training, while repeated severe failures can lower ratings and risk dismissal.<\/li>\n<li>Recruiter lures and fake conference invitations mirror scams already causing large losses across cryptocurrency firms.<\/li>\n<\/ul><\/div>\n<\/div>\n<p><!-- .cn-block-summary --><\/p>\n<p>Chief security officer Jimmy Su said the exchange\u2019s red team creates fake attacks to test whether staff recognise suspicious messages, links and requests. Employees who fail must complete follow-up training. Repeated failures can also affect performance ratings and may lead to dismissal.<\/p>\n<p>The programme targets human errors that attackers use to enter crypto companies. Binance has operated the drills for three to four years, according to Su. He said the company\u2019s security habits had improved during that period. Binance reports 323 million registered users, while <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/defillama.com\/cex\/binance-cex\" target=\"_blank\" rel=\"nofollow\">DefiLlama<\/a> tracks about $137.5 billion in assets linked to the exchange.<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-x wp-block-embed-x\">\n<div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Binance Runs Fake Hacks on Its Own Staff Every Month: Here&#8217;s What They Keep Finding \u2014 <a rel=\"nofollow\" target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/t.co\/2SzRtjvjRW\">https:\/\/t.co\/2SzRtjvjRW<\/a><\/p>\n<p>\u2014 morosaki (@Morosaki) <a rel=\"nofollow\" target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/x.com\/Morosaki\/status\/2081221946352537858?ref_src=twsrc%5Etfw\">July 26, 2026<\/a><\/p><\/blockquote>\n<\/div>\n<\/figure>\n<p>    <!-- .cn-block-related-link --><\/p>\n<h2 class=\"wp-block-heading\"><strong>Binance ties phishing tests to staff reviews<\/strong><\/h2>\n<p>The red team uses methods that resemble real attacks. One test may present a fake recruiter offering a job. Another may promise free access to a conference and request personal details. The team records whether employees open the message, follow a link or share information that could expose company systems.<\/p>\n<p>Su said workers who fail receive remedial training. Repeated failure \u201cwill negatively impact their rating,\u201d he said. Severe cases may push a worker\u2019s rating to the lowest level and result in dismissal. The policy gives employees a direct work-related reason to verify unexpected messages before responding.<\/p>\n<p>Binance has described its red team as an internal group of ethical hackers that tests systems from an attacker\u2019s point of view. The exchange also works with external researchers through bug bounty programmes. Its security model covers technical weaknesses and employee behaviour because attackers may enter through trusted accounts or devices.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Social engineering drives crypto security cases<\/strong><\/h2>\n<p>The drills come as social engineering causes a large share of reported crypto losses. AMLBot reviewed more than 2,500 <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/blog.amlbot.com\/crypto-crime-report-2025-2026-insights-from-2-500-real-investigations\/\" target=\"_blank\" rel=\"nofollow\">investigations<\/a> and found that 65% of the cases it handled in 2025 began with social engineering rather than direct software exploits. Phishing represented 18% of its cases, while device compromise accounted for 13%.<\/p>\n<p>Attackers often spend days or months building trust before asking a target to open a file, approve a wallet request or run a command. This method can defeat technical controls when a worker has access to private keys, administrator accounts or internal systems. Stolen credentials can lead directly to liquid assets that move across blockchains within minutes.<\/p>\n<p>As crypto.news reported, the April 2026 attack on Drift Protocol drained about $285 million after attackers compromised an administrator key. Researchers linked the breach to social engineering and operational security failures rather than faulty smart contracts. The attacker changed market settings and withdrawal limits before removing assets across dozens of transactions.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Fake meetings and job offers remain common lures<\/strong><\/h2>\n<p>Su identified fake job interviews as one scenario used in Binance\u2019s tests. Real attackers use the same approach against developers, executives and investment teams. They may move a conversation from LinkedIn, Telegram or email into a video meeting, then claim that the victim\u2019s camera or microphone needs an update.<\/p>\n<p>North Korea-linked hackers have used compromised Telegram accounts and deepfake Zoom calls to contact crypto professionals. The attackers impersonated known contacts and asked victims to install files that claimed to fix audio problems. Those files instead delivered malware capable of accessing devices, browser data and crypto wallets.<\/p>\n<p>A Venus Protocol user lost about $13.5 million in September 2025 after approving a malicious transaction. Venus paused its lending platform and recovered the assets through an emergency governance process. The case showed how a user-level compromise can place assets at risk even when a protocol\u2019s contracts remain intact.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Frequent drills aim to reduce predictable errors<\/strong><\/h2>\n<p>Monthly simulations let Binance compare failure rates and update training when attackers change their methods. A single annual course may not prepare staff for new lures built around current events, trusted contacts or job offers. Frequent tests also show whether workers report suspicious messages instead of only deleting them.<\/p>\n<p>However, simulations cannot remove every risk. Attackers can hijack genuine accounts, copy earlier conversations and use artificial intelligence to create convincing audio, video and written messages. Firms still need access controls, transaction limits, device monitoring and fast incident response alongside employee training.<\/p>\n<p>Su said Binance\u2019s early security habits \u201cleft a lot to be desired,\u201d but repeated testing brought improvement. The exchange treats staff awareness as part of its wider defence system rather than a one-time compliance task. Employees still need to verify unusual requests through a separate channel before opening files, sharing information or approving transactions.<\/p>\n<p>    <!-- .cn-block-related-link --><\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Binance runs simulated phishing attacks against its employees every month to reduce social engineering risks.\u00a0 Summary Binance runs monthly phishing simulations to measure employee awareness and identify weak security habits&hellip;<\/p>\n","protected":false},"author":1,"featured_media":30584,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-35474","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cryptocurrency"],"_links":{"self":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/35474","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/comments?post=35474"}],"version-history":[{"count":1,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/35474\/revisions"}],"predecessor-version":[{"id":35475,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/posts\/35474\/revisions\/35475"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/media\/30584"}],"wp:attachment":[{"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/media?parent=35474"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/categories?post=35474"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bitunikey.com\/news\/wp-json\/wp\/v2\/tags?post=35474"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}