Close Menu
Crypto Breaking News
    Crypto Breaking News
    • News
      • Press Release
      • Featured
      • Events
      • Exchanges
      • Bitcoin
      • Ethereum
      • Solana
      • Ripple
      • Artificial Intelligence (AI)
      • Real World Assets (RWA)
      • Markets & Finance
      • Regulation & Policy
      • Press Releases by PR Newswire
      • News by CoinPedia
      • News by Coincu
      • News by Blockchain Wire
    • Crypto
      • Companies
      • Events
      • Partners
      • Buy Crypto
      • Timers
    • Advertise
      • Submit a Press Release
      • Logos
      • About
      • Services
    • Offers
      • Marketing Services
      • Wallets & Tools
    • Account
    • Video
    • Contact
    Submit PR
    Crypto Breaking News
    Crypto News Exchanges

    Binance Details Staff Phishing Campaigns to Counter Social Engineering

    17 seconds ago
    FacebookTwitterLinkedInCopy Link
    News Feed
    Google NewsRSS
    Binance Details Staff Phishing Campaigns To Counter Social Engineering
    Binance Details Staff Phishing Campaigns To Counter Social Engineering

    Binance says it has been running internal, simulated phishing attacks against its own staff for several years—testing how well employees resist social engineering attempts and tying repeat failures to remediation training and performance consequences. The exchange’s chief security officer, Jimmy Su, described the program as a way to measure whether “security hygiene” is improving inside a growing organization.

    Su told Cointelegraph that Binance’s internal red team performs phishing simulations on a monthly basis. Employees who fail receive remediation training, while continued poor performance can affect their performance review ratings and, in extreme cases, lead to dismissal.

    Key takeaways

    • Binance conducts monthly phishing simulations via an internal red team, according to its chief security officer Jimmy Su.
    • Failed phishing tests are followed by remediation training, aiming to improve employees’ security habits over time.
    • Results can influence performance reviews; repeated failures may lower ratings to the point that employment risk increases.
    • Su says Binance has run these simulated attacks for roughly three to four years, with security hygiene improving compared with earlier stages.
    • The described tactics reflect broader industry risk: social engineering continues to be a major driver of crypto security incidents.

    How Binance tests resistance to social engineering

    Binance’s approach centers on realism: the red team acts as an attacker to probe the company’s human layer, not just technical controls. Su said the simulations are designed to show whether employees have become more vigilant over time, adding that the program has been running for about three to four years.

    “We do phishing attacks on our own employees on a monthly basis just so we understand if our security hygiene is improving,” Su told Cointelegraph. The goal, he said, is to spot weaknesses early—before malicious actors can exploit them in real incidents.

    “The ones that have failed it, we will do remediation training.”

    Su also said that early on, security hygiene “left a lot to be desired.” But after continuing the internal testing for a sustained period, Binance has seen meaningful improvement. That long-running cadence matters because human error is rarely solved through a one-time training session; it often requires repeated exposure, feedback, and accountability.

    Escalating accountability: training and performance reviews

    Binance’s internal program isn’t only about education—it’s also about incentives. Su stated that employees are encouraged to perform well because simulation results are reflected in performance reviews.

    “If someone repeatedly fails the phishing-simulation attack, that will negatively impact their rating. That’s the incentive to be vigilant.”

    He added that repeated, severe failures could cause a person’s rating to “bottom out,” which could ultimately lead to dismissal. While exact thresholds or timelines were not specified, the direction is clear: Binance treats recurring susceptibility to phishing as a measurable risk rather than a purely training-based issue.

    For employees and managers, this changes the information security conversation. Instead of treating phishing defenses as optional training, the simulations become part of how the organization assesses readiness—suggesting a shift toward continuous security evaluation.

    The tactics: recruiter lures and Zoom-style schemes

    Su described at least one scenario used in the red team’s simulations: the team poses as job recruiters. That reflects a common pattern in real-world phishing—using credible context and urgency to lower an employee’s guard, especially when the target might be inclined to respond to hiring-related messages.

    He also referenced well-known social engineering techniques that have circulated widely in the crypto ecosystem, including “Zoom meeting attacks,” in which attackers try to get victims to install malware disguised as a meeting update. These attacks often begin with a lure such as a fake job opportunity, and they can also use other hooks like proposed funding or partnerships.

    The Binance description aligns with incidents seen across the sector. Earlier coverage cited by Cointelegraph notes that AMLBot estimated that 65% of crypto security incidents in 2025 were driven by social engineering. Separately, a major hack suffered by Drift Protocol in April was described as following a long-term social engineering campaign.

    One example of the “Zoom client” pattern occurred in September 2025, when a major Venus Protocol user reportedly lost around $13 million after a malicious Zoom client compromised their computer and granted an attacker control over their account. Venus paused the protocol and used an emergency governance vote to recover the assets, later returning positions worth $11.4 million to the victim, according to the related Cointelegraph reporting referenced in the original article.

    Why internal phishing testing is becoming standard in crypto

    Binance’s public discussion of internal simulated phishing comes at a time when social engineering is widely recognized as a persistent—and often underestimated—attack surface in digital-asset businesses. The reason these programs can matter is that even sophisticated security stacks cannot fully prevent compromise if employees can be tricked into revealing access, installing malware, or granting approvals.

    Binance is also operating at a scale where human processes can become especially important. The exchange says it has 323 million registered users, and DefiLlama estimates Binance holds $137.7 billion in assets. In environments this large, attackers have strong incentives to focus on the easiest pathway to access—often the human decision layer.

    Su indicated that Binance has treated phishing resilience as an ongoing operational discipline rather than a compliance box. He described scenarios that include collecting personal information through seemingly benign interactions, such as offering free conference invites as a way to see how many targets would share details.

    That emphasis on varied lures is an important point for investors and operators watching the sector: attackers adapt, and defensive training must adapt too. Simulations that only teach one “shape” of attack can become outdated quickly, while programs that rotate scenarios help test whether employees can recognize patterns rather than memorize scripts.

    What readers should watch next is whether other major exchanges and custody platforms adopt similar accountability-driven simulation programs—and, crucially, whether regulators and internal auditors begin to treat phishing resistance testing as a measurable control rather than a general training activity.

    Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

    Crypto Breaking News
    • Website
    • Facebook
    • X (Twitter)
    • Pinterest
    • Instagram
    • Tumblr
    • LinkedIn

    The Crypto Breaking News editorial team curates the latest news, updates, and insights from the global cryptocurrency and blockchain industry.

    Related Posts

    Binance Runs Monthly “red Team” Tests On Staff To Thwart Hackers

    Binance Runs Monthly “Red Team” Tests on Staff to Thwart Hackers

    1 hour ago
    Clarity Act Faces November Timeline As Election Politics Slow Senate Progress

    Clarity Act Faces November Timeline as Election Politics Slow Senate Progress

    8 hours ago
    Eu Adds Htx To Russia Sanctions Package Expands Crypto Crackdown

    EU Adds HTX to Russia Sanctions Package, Expands Crypto Crackdown

    9 hours ago
    Wisdom Group Advised To Refile Us Charter Application Under Genius Act

    Wisdom Group Advised to Refile US Charter Application Under GENIUS Act

    9 hours ago
    Dango’s Perp Dex Shuts Down After Nearly Four Months In Operation

    Dango’s Perp DEX Shuts Down After Nearly Four Months in Operation

    17 hours ago
    Ethereum Etfs Break 5-Day Inflow Streak With Weekly Outflows

    Ethereum ETFs Break 5-Day Inflow Streak With Weekly Outflows

    19 hours ago

    Search Crypto News

    Featured Crypto News

    Win 3 Free Ga Passes To Bitcoin Asia 2026 In Hong Kong With Cryptobreaking

    Win 3 Free GA Passes to Bitcoin Asia 2026 in Hong Kong With CryptoBreaking

    24 July 2026
    8 Ai Youtube Channels To Follow In 2026

    8 Best AI YouTube Channels to Follow

    20 July 2026

    Latest News

    • Binance Details Staff Phishing Campaigns to Counter Social Engineering
    • Binance Runs Monthly “Red Team” Tests on Staff to Thwart Hackers
    • Clarity Act Faces November Timeline as Election Politics Slow Senate Progress
    • EU Adds HTX to Russia Sanctions Package, Expands Crypto Crackdown
    • Wisdom Group Advised to Refile US Charter Application Under GENIUS Act
    • Dango’s Perp DEX Shuts Down After Nearly Four Months in Operation
    • Ethereum ETFs Break 5-Day Inflow Streak With Weekly Outflows
    • EU Extends Belarus Crypto Ownership Ban to All MiCA Firms From Aug. 25
    • Poolin Files for Chapter 11 as $52M Plan Moves Ahead for Texas Mining Sites
    • Ripple Starts RLUSD Mint for Institutional Access

    Join 20,000+ Crypto Followers

    • Facebook2.4K
    • Twitter4.5K
    • Instagram7.2K
    • LinkedIn4.3K
    • Telegram55
    • Threads1000
    eToro Crypto 300x300
    AVATRADE

    About Crypto Breaking News

    About Crypto Breaking News

    Crypto Breaking News is a fast-growing digital media platform focused on the latest developments in cryptocurrency, blockchain, and Web3 technologies. Our goal is to provide fast, reliable, and insightful content that helps our readers stay ahead in the ever-evolving digital asset space.

    Web3 Digital L.L.C-FZ
    License Number: 2527596
    📞 +971 50 449 2025
    ✉️ info@cryptobreaking.com
    📍Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates

    FacebookX (Twitter)InstagramPinterestYouTubeTumblrBlueskyLinkedInRedditTikTokTelegramThreadsRSS

    Links

    • Crypto News
    • Submit a Press Release
    • Advertise
    • Contact Us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • Stocks Breaking News

    advertising

    Tangem 300x300
    © 2026 CryptoBreaking.com | All rights reserved | Powered by Web3 Digital & Osom One

    Type above and press Enter to search. Press Esc to cancel.

    Change Location
    Find awesome listings near you!