
Binance says it has been running internal, simulated phishing attacks against its own staff for several years—testing how well employees resist social engineering attempts and tying repeat failures to remediation training and performance consequences. The exchange’s chief security officer, Jimmy Su, described the program as a way to measure whether “security hygiene” is improving inside a growing organization.
Su told Cointelegraph that Binance’s internal red team performs phishing simulations on a monthly basis. Employees who fail receive remediation training, while continued poor performance can affect their performance review ratings and, in extreme cases, lead to dismissal.
Key takeaways
- Binance conducts monthly phishing simulations via an internal red team, according to its chief security officer Jimmy Su.
- Failed phishing tests are followed by remediation training, aiming to improve employees’ security habits over time.
- Results can influence performance reviews; repeated failures may lower ratings to the point that employment risk increases.
- Su says Binance has run these simulated attacks for roughly three to four years, with security hygiene improving compared with earlier stages.
- The described tactics reflect broader industry risk: social engineering continues to be a major driver of crypto security incidents.
How Binance tests resistance to social engineering
Binance’s approach centers on realism: the red team acts as an attacker to probe the company’s human layer, not just technical controls. Su said the simulations are designed to show whether employees have become more vigilant over time, adding that the program has been running for about three to four years.
“We do phishing attacks on our own employees on a monthly basis just so we understand if our security hygiene is improving,” Su told Cointelegraph. The goal, he said, is to spot weaknesses early—before malicious actors can exploit them in real incidents.
“The ones that have failed it, we will do remediation training.”
Su also said that early on, security hygiene “left a lot to be desired.” But after continuing the internal testing for a sustained period, Binance has seen meaningful improvement. That long-running cadence matters because human error is rarely solved through a one-time training session; it often requires repeated exposure, feedback, and accountability.
Escalating accountability: training and performance reviews
Binance’s internal program isn’t only about education—it’s also about incentives. Su stated that employees are encouraged to perform well because simulation results are reflected in performance reviews.
“If someone repeatedly fails the phishing-simulation attack, that will negatively impact their rating. That’s the incentive to be vigilant.”
He added that repeated, severe failures could cause a person’s rating to “bottom out,” which could ultimately lead to dismissal. While exact thresholds or timelines were not specified, the direction is clear: Binance treats recurring susceptibility to phishing as a measurable risk rather than a purely training-based issue.
For employees and managers, this changes the information security conversation. Instead of treating phishing defenses as optional training, the simulations become part of how the organization assesses readiness—suggesting a shift toward continuous security evaluation.
The tactics: recruiter lures and Zoom-style schemes
Su described at least one scenario used in the red team’s simulations: the team poses as job recruiters. That reflects a common pattern in real-world phishing—using credible context and urgency to lower an employee’s guard, especially when the target might be inclined to respond to hiring-related messages.
He also referenced well-known social engineering techniques that have circulated widely in the crypto ecosystem, including “Zoom meeting attacks,” in which attackers try to get victims to install malware disguised as a meeting update. These attacks often begin with a lure such as a fake job opportunity, and they can also use other hooks like proposed funding or partnerships.
The Binance description aligns with incidents seen across the sector. Earlier coverage cited by Cointelegraph notes that AMLBot estimated that 65% of crypto security incidents in 2025 were driven by social engineering. Separately, a major hack suffered by Drift Protocol in April was described as following a long-term social engineering campaign.
One example of the “Zoom client” pattern occurred in September 2025, when a major Venus Protocol user reportedly lost around $13 million after a malicious Zoom client compromised their computer and granted an attacker control over their account. Venus paused the protocol and used an emergency governance vote to recover the assets, later returning positions worth $11.4 million to the victim, according to the related Cointelegraph reporting referenced in the original article.
Why internal phishing testing is becoming standard in crypto
Binance’s public discussion of internal simulated phishing comes at a time when social engineering is widely recognized as a persistent—and often underestimated—attack surface in digital-asset businesses. The reason these programs can matter is that even sophisticated security stacks cannot fully prevent compromise if employees can be tricked into revealing access, installing malware, or granting approvals.
Binance is also operating at a scale where human processes can become especially important. The exchange says it has 323 million registered users, and DefiLlama estimates Binance holds $137.7 billion in assets. In environments this large, attackers have strong incentives to focus on the easiest pathway to access—often the human decision layer.
Su indicated that Binance has treated phishing resilience as an ongoing operational discipline rather than a compliance box. He described scenarios that include collecting personal information through seemingly benign interactions, such as offering free conference invites as a way to see how many targets would share details.
That emphasis on varied lures is an important point for investors and operators watching the sector: attackers adapt, and defensive training must adapt too. Simulations that only teach one “shape” of attack can become outdated quickly, while programs that rotate scenarios help test whether employees can recognize patterns rather than memorize scripts.
What readers should watch next is whether other major exchanges and custody platforms adopt similar accountability-driven simulation programs—and, crucially, whether regulators and internal auditors begin to treat phishing resistance testing as a measurable control rather than a general training activity.
https://www.cryptobreaking.com/binance-details-staff-phishing-campaigns/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=Binance%20Details%20Staff%20Phishing%20Campaigns%20to%20Counter%20Social%20Engineering%20
Comments
Post a Comment