Close Menu
Crypto Breaking News
    Crypto Breaking News
    • News
      • Press Release
      • Featured
      • Events
      • Exchanges
      • Bitcoin
      • Ethereum
      • Solana
      • Ripple
      • Artificial Intelligence (AI)
      • Real World Assets (RWA)
      • Markets & Finance
      • Regulation & Policy
      • Press Releases by PR Newswire
      • News by CoinPedia
      • News by Coincu
      • News by Blockchain Wire
    • Crypto
      • Companies
      • Events
      • Partners
      • Buy Crypto
      • Timers
    • Advertise
      • Submit a Press Release
      • Logos
      • About
      • Services
    • Offers
      • Marketing Services
      • Wallets & Tools
    • Account
    • Video
    • Contact
    Submit PR
    Crypto Breaking News
    Crypto News Exchanges

    Binance Details Staff Phishing Campaigns to Counter Social Engineering

    26 July 2026
    FacebookTwitterLinkedInCopy Link
    News Feed
    Google NewsRSS
    Binance Details Staff Phishing Campaigns To Counter Social Engineering
    Binance Details Staff Phishing Campaigns To Counter Social Engineering

    Binance says it has been running internal, simulated phishing attacks against its own staff for several years—testing how well employees resist social engineering attempts and tying repeat failures to remediation training and performance consequences. The exchange’s chief security officer, Jimmy Su, described the program as a way to measure whether “security hygiene” is improving inside a growing organization.

    Su told Cointelegraph that Binance’s internal red team performs phishing simulations on a monthly basis. Employees who fail receive remediation training, while continued poor performance can affect their performance review ratings and, in extreme cases, lead to dismissal.

    Key takeaways

    • Binance conducts monthly phishing simulations via an internal red team, according to its chief security officer Jimmy Su.
    • Failed phishing tests are followed by remediation training, aiming to improve employees’ security habits over time.
    • Results can influence performance reviews; repeated failures may lower ratings to the point that employment risk increases.
    • Su says Binance has run these simulated attacks for roughly three to four years, with security hygiene improving compared with earlier stages.
    • The described tactics reflect broader industry risk: social engineering continues to be a major driver of crypto security incidents.

    How Binance tests resistance to social engineering

    Binance’s approach centers on realism: the red team acts as an attacker to probe the company’s human layer, not just technical controls. Su said the simulations are designed to show whether employees have become more vigilant over time, adding that the program has been running for about three to four years.

    “We do phishing attacks on our own employees on a monthly basis just so we understand if our security hygiene is improving,” Su told Cointelegraph. The goal, he said, is to spot weaknesses early—before malicious actors can exploit them in real incidents.

    “The ones that have failed it, we will do remediation training.”

    Su also said that early on, security hygiene “left a lot to be desired.” But after continuing the internal testing for a sustained period, Binance has seen meaningful improvement. That long-running cadence matters because human error is rarely solved through a one-time training session; it often requires repeated exposure, feedback, and accountability.

    Escalating accountability: training and performance reviews

    Binance’s internal program isn’t only about education—it’s also about incentives. Su stated that employees are encouraged to perform well because simulation results are reflected in performance reviews.

    “If someone repeatedly fails the phishing-simulation attack, that will negatively impact their rating. That’s the incentive to be vigilant.”

    He added that repeated, severe failures could cause a person’s rating to “bottom out,” which could ultimately lead to dismissal. While exact thresholds or timelines were not specified, the direction is clear: Binance treats recurring susceptibility to phishing as a measurable risk rather than a purely training-based issue.

    For employees and managers, this changes the information security conversation. Instead of treating phishing defenses as optional training, the simulations become part of how the organization assesses readiness—suggesting a shift toward continuous security evaluation.

    The tactics: recruiter lures and Zoom-style schemes

    Su described at least one scenario used in the red team’s simulations: the team poses as job recruiters. That reflects a common pattern in real-world phishing—using credible context and urgency to lower an employee’s guard, especially when the target might be inclined to respond to hiring-related messages.

    He also referenced well-known social engineering techniques that have circulated widely in the crypto ecosystem, including “Zoom meeting attacks,” in which attackers try to get victims to install malware disguised as a meeting update. These attacks often begin with a lure such as a fake job opportunity, and they can also use other hooks like proposed funding or partnerships.

    The Binance description aligns with incidents seen across the sector. Earlier coverage cited by Cointelegraph notes that AMLBot estimated that 65% of crypto security incidents in 2025 were driven by social engineering. Separately, a major hack suffered by Drift Protocol in April was described as following a long-term social engineering campaign.

    One example of the “Zoom client” pattern occurred in September 2025, when a major Venus Protocol user reportedly lost around $13 million after a malicious Zoom client compromised their computer and granted an attacker control over their account. Venus paused the protocol and used an emergency governance vote to recover the assets, later returning positions worth $11.4 million to the victim, according to the related Cointelegraph reporting referenced in the original article.

    Why internal phishing testing is becoming standard in crypto

    Binance’s public discussion of internal simulated phishing comes at a time when social engineering is widely recognized as a persistent—and often underestimated—attack surface in digital-asset businesses. The reason these programs can matter is that even sophisticated security stacks cannot fully prevent compromise if employees can be tricked into revealing access, installing malware, or granting approvals.

    Binance is also operating at a scale where human processes can become especially important. The exchange says it has 323 million registered users, and DefiLlama estimates Binance holds $137.7 billion in assets. In environments this large, attackers have strong incentives to focus on the easiest pathway to access—often the human decision layer.

    Su indicated that Binance has treated phishing resilience as an ongoing operational discipline rather than a compliance box. He described scenarios that include collecting personal information through seemingly benign interactions, such as offering free conference invites as a way to see how many targets would share details.

    That emphasis on varied lures is an important point for investors and operators watching the sector: attackers adapt, and defensive training must adapt too. Simulations that only teach one “shape” of attack can become outdated quickly, while programs that rotate scenarios help test whether employees can recognize patterns rather than memorize scripts.

    What readers should watch next is whether other major exchanges and custody platforms adopt similar accountability-driven simulation programs—and, crucially, whether regulators and internal auditors begin to treat phishing resistance testing as a measurable control rather than a general training activity.

    Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

    Crypto Breaking News
    • Website
    • Facebook
    • X (Twitter)
    • Pinterest
    • Instagram
    • Tumblr
    • LinkedIn

    The Crypto Breaking News editorial team curates the latest news, updates, and insights from the global cryptocurrency and blockchain industry.

    Related Posts

    Bernstein: Robinhood Chain Fees Could Reach $160m Annually By 2028

    Bernstein: Robinhood Chain fees could reach $160M annually by 2028

    20 minutes ago
    Cybercrime Boss Malone Lam Pleads Guilty In $245m Crypto Theft Case

    Cybercrime Boss Malone Lam Pleads Guilty in $245M Crypto Theft Case

    1 hour ago
    Malone Lam Pleads Guilty In $245m Crypto Theft Conspiracy Case

    Malone Lam Pleads Guilty in $245M Crypto Theft Conspiracy Case

    2 hours ago
    Circle To Acquire Tazapay To Expand Usdc Cross-Border Payments In The Us

    Circle to Acquire Tazapay to Expand USDC Cross-Border Payments in the US

    3 hours ago
    Mexico Probe Links Quadruple Homicide To Alleged Bitcoin Robbery Attempt

    Mexico Probe Links Quadruple Homicide to Alleged Bitcoin Robbery Attempt

    4 hours ago
    Company Pauses Bitcoin Purchases As It Repurchases $176m Of Strc

    Company Pauses Bitcoin Purchases as It Repurchases $176M of STRC

    5 hours ago

    Search Crypto News

    Featured Crypto News

    Exclusive Abu Dhabi F1 Hospitality Experience Now Available For Crypto Executives, Investors And Vip Guests

    Exclusive Abu Dhabi F1 Hospitality Experience Now Available for Crypto Executives, Investors and VIP Guests

    7 September 2026

    Latest News

    • Bernstein: Robinhood Chain fees could reach $160M annually by 2028
    • Cybercrime Boss Malone Lam Pleads Guilty in $245M Crypto Theft Case
    • Malone Lam Pleads Guilty in $245M Crypto Theft Conspiracy Case
    • Circle to Acquire Tazapay to Expand USDC Cross-Border Payments in the US
    • Mexico Probe Links Quadruple Homicide to Alleged Bitcoin Robbery Attempt
    • Company Pauses Bitcoin Purchases as It Repurchases $176M of STRC
    • Bitmine Acquires 28K ETH, Hits 97% of Treasury Accumulation Goal
    • Visa Adds On-Chain Credit for Its Expanding Stablecoin Card Program
    • Franklin Templeton Digital Asset Exec Appointed CEO at StablecoinX
    • Franklin Templeton Veteran Named Head of StablecoinX Digital Assets

    Join 20,000+ Crypto Followers

    • Facebook2.4K
    • Twitter4.5K
    • Instagram7.2K
    • LinkedIn4.3K
    • Telegram55
    • Threads1000
    AVATRADE
    eToro Crypto 300x300

    About Crypto Breaking News

    About Crypto Breaking News

    Crypto Breaking News is a fast-growing digital media platform focused on the latest developments in cryptocurrency, blockchain, and Web3 technologies. Our goal is to provide fast, reliable, and insightful content that helps our readers stay ahead in the ever-evolving digital asset space.

    Web3 Digital L.L.C-FZ
    License Number: 2527596
    📞 +971 50 449 2025
    ✉️ info@cryptobreaking.com
    📍Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates

    FacebookX (Twitter)InstagramPinterestYouTubeTumblrBlueskyLinkedInRedditTikTokTelegramThreadsRSS

    Links

    • Crypto News
    • Submit a Press Release
    • Advertise
    • Contact Us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • Stocks Breaking News

    advertising

    Bitpanda
    © 2026 CryptoBreaking.com | All rights reserved | Powered by Web3 Digital & Osom One

    Type above and press Enter to search. Press Esc to cancel.

    Change Location
    Find awesome listings near you!