Binance tests staff monthly with fake phishing attacks

1 hour ago 1



Binance runs simulated phishing attacks against its employees every month to reduce social engineering risks. Summary Binance runs monthly phishing simulations to measure employee awareness and identify weak security habits early. Workers who fail receive training, while repeated severe failures can lower ratings and risk dismissal. Recruiter lures and fake conference invitations mirror scams already causing large losses across cryptocurrency firms. Chief security officer Jimmy Su said the exchange’s red team creates fake attacks to test whether staff recognise suspicious messages, links and requests. Employees who fail must complete follow-up training. Repeated failures can also affect performance ratings and may lead to dismissal. The programme targets human errors that attackers use to enter crypto companies. Binance has operated the drills for three to four years, according to Su. He said the company’s security habits had improved during that period. Binance reports 323 million registered users, while DefiLlama tracks about $137.5 billion in assets linked to the exchange. Binance ties phishing tests to staff reviews The red team uses methods that resemble real attacks. One test...

Read Entire Article