NewsCryptoBinance Conducts Monthly Phishing Drills, Says Repeat Failures Can Affect Reviews or Jobs

Binance Conducts Monthly Phishing Drills, Says Repeat Failures Can Affect Reviews or Jobs

Author: LiveBitcoinNews·

Key Takeaways

  • •Binance conducts monthly phishing simulations to test employee responses to social engineering tactics.
  • •Employees who fail the exercises must complete remediation training, while repeated failures can affect performance ratings or lead to dismissal.
  • •Chief security officer Jimmy Su said the program began about three to four years ago and has improved employee security habits.
  • •AMLBot estimated that social engineering accounted for 65% of crypto security incidents in 2025.
  • •Binance reports more than 323 million registered users and an estimated $137.7 billion in assets.
Binance Conducts Monthly Phishing Drills, Says Repeat Failures Can Affect Reviews or Jobs

Binance has tied the results of internal phishing tests to employee performance reviews as the cryptocurrency exchange works to reduce risks from social engineering, a threat company executives describe as one of the digital asset industry’s most significant security challenges.

The exchange has tested its workforce against phishing attempts for several years. Monthly simulations are now a regular part of Binance’s employee security training program, and staff members who repeatedly fail the exercises may receive poor performance ratings or, in some cases, face dismissal. For large crypto platforms, employee credentials, internal communications, and access permissions can become targets because attackers may seek a path into systems that support customer accounts, trading infrastructure, compliance functions, or custody operations.

Fake Recruiters and Conference Invites Used in Monthly Tests

Binance chief security officer Jimmy Su said the company’s internal red team conducts simulated attacks every month. Red teams are ethical hacking groups that look for weaknesses before malicious actors can exploit them. Su said employees who are caught by the simulated scams are required to complete additional training designed to improve their security awareness.

According to Su, Binance launched the program about three to four years ago. In the early stages, many employees had difficulty recognizing phishing attempts. Since then, repeated testing and follow-up remediation have produced visible improvements in staff security habits, he said.

The monthly drills use several tactics commonly seen in real cyberattacks. Many of the campaigns focus less on technical vulnerabilities and more on human behavior, reflecting the way attackers often try to gain access to sensitive accounts or internal information. Security teams commonly treat these exercises as a way to measure whether staff can identify suspicious requests before a real attacker can turn a message, meeting invite, or recruitment pitch into an entry point.

In one type of test, fake job recruiters contact employees and attempt to obtain confidential information. In another, fraudulent conference invitations are sent to staff members in an effort to persuade them to disclose personal details.

Employees who fail the tests must complete mandatory remediation training. Repeated failures can lower an employee’s performance rating and may eventually lead to dismissal. Results from each exercise are included in employee performance reviews. Su said repeated mistakes can move an employee’s rating to the lowest level, and continued poor performance could ultimately cost the employee their job.

AMLBot Estimated Social Engineering Drove 65% of 2025 Crypto Security Incidents

Social engineering has become a major concern across the cryptocurrency sector. AMLBot estimated in February that 65% of crypto security incidents in 2025 were linked to social engineering attacks. Instead of relying only on technical flaws, criminals increasingly use deception to gain access to valuable accounts and digital assets.

Recent incidents have shown how damaging those methods can be. Drift Protocol suffered a $285 million hack in April after attackers carried out a long-running social engineering campaign. Another widely used tactic involves fake Zoom meeting invitations that trick victims into installing malicious software disguised as an update.

One such case took place in September 2025, when a major Venus Protocol user lost roughly $13 million after installing a malicious Zoom client. Attackers took control of the victim’s account and accessed digital assets. Venus later paused parts of its protocol, approved emergency governance actions, and returned positions worth about $11.4 million.

Binance reports more than 323 million registered users and holds an estimated $137.7 billion in assets. The company views continuous employee testing as an important defense against increasingly convincing phishing campaigns and other social engineering attempts, with future effectiveness likely depending on whether staff continue to recognize evolving lures as attackers adapt their methods.