NewsCryptoBinance Says Monthly Staff Phishing Tests Target Social Engineering Risks

Binance Says Monthly Staff Phishing Tests Target Social Engineering Risks

Author: CryptoBreaking·

Key Takeaways

  • •Binance’s internal red team conducts monthly phishing simulations to assess and improve employee security behavior.
  • •Employees who fail simulations receive remediation training, and repeated failures can negatively affect performance reviews.
  • •Jimmy Su said severe recurring failures may ultimately lead to dismissal, though Binance has not disclosed specific thresholds.
  • •The simulations include varied scenarios such as fake recruiter outreach, malicious meeting updates and attempts to collect personal information.
  • •Binance says its program addresses human-focused security risks as the exchange serves 323 million registered users and holds an estimated $137.7 billion in assets.
Binance Says Monthly Staff Phishing Tests Target Social Engineering Risks

Binance says it has conducted simulated phishing campaigns against its own employees for several years as part of an internal effort to test resistance to social engineering and improve staff security practices. The exchange’s chief security officer, Jimmy Su, told Cointelegraph that the program is designed to measure whether “security hygiene” is improving across the organization.

According to Su, Binance’s internal red team runs phishing simulations on a monthly basis. Employees who fail the tests are assigned remediation training, while repeated failures can affect performance review ratings and, in severe cases, may lead to dismissal.

Binance’s internal red team tests employee readiness

Binance’s program focuses on testing the human layer of security, not only the company’s technical controls. Su said the red team acts as an attacker in realistic scenarios intended to show whether employees are becoming more alert to suspicious approaches over time. He said Binance has been running the simulated attacks for roughly three to four years.

“We do phishing attacks on our own employees on a monthly basis just so we understand if our security hygiene is improving,” Su told Cointelegraph. He said the objective is to identify weaknesses before malicious actors can exploit them in actual incidents.

“The ones that have failed it, we will do remediation training,” Su said.

Su also said Binance’s security hygiene in the earlier stages of the program “left a lot to be desired.” After maintaining the internal testing process over an extended period, he said the exchange has seen meaningful improvement.

The recurring nature of the program is central to Binance’s approach. Rather than relying on a single training session, the exchange uses repeated simulations, feedback and follow-up training to reinforce employee awareness and accountability.

Failed simulations can affect performance reviews

Binance’s internal phishing program is structured around both training and incentives. Su said employees are encouraged to perform well because results from the simulations are reflected in performance reviews.

“If someone repeatedly fails the phishing-simulation attack, that will negatively impact their rating. That’s the incentive to be vigilant,” Su said.

He added that repeated and severe failures could cause an employee’s rating to “bottom out,” which could ultimately result in dismissal. Su did not specify exact thresholds, timelines or the number of failures that would trigger those consequences.

The policy indicates that Binance treats recurring susceptibility to phishing as a measurable operational risk rather than only a training concern. In that framework, simulated attacks become part of how the organization evaluates readiness and employee adherence to security expectations.

Recruiter lures and Zoom-style attacks

Su described at least one scenario used by Binance’s red team: posing as job recruiters. The tactic mirrors a common social engineering pattern in which attackers use credible professional contexts and time-sensitive communication to persuade targets to respond or share information.

He also referred to “Zoom meeting attacks,” a type of social engineering technique that has circulated in the crypto industry. In such cases, attackers attempt to persuade victims to install malware disguised as a meeting update. These attacks can begin with lures such as fake job opportunities, and may also use other hooks including proposed funding or partnerships.

The risks described by Binance are consistent with broader security concerns across the digital-asset sector. Earlier coverage cited by Cointelegraph said AMLBot estimated that 65% of crypto security incidents in 2025 were driven by social engineering. Separately, a major hack suffered by Drift Protocol in April was described as the result of a long-term social engineering campaign.

Another example cited in related Cointelegraph reporting involved the “Zoom client” pattern. In September 2025, a major Venus Protocol user reportedly lost around $13 million after a malicious Zoom client compromised their computer and gave an attacker control over their account. Venus paused the protocol and used an emergency governance vote to recover the assets. The protocol later returned positions worth $11.4 million to the victim, according to that reporting.

Social engineering remains a key crypto security risk

Binance’s disclosure of its internal phishing simulations comes as social engineering remains a persistent attack surface for digital-asset companies. Even sophisticated security systems may not prevent compromise if employees are tricked into revealing credentials, installing malware, sharing sensitive information or approving malicious requests.

The scale of Binance’s operations increases the importance of internal processes. The exchange says it has 323 million registered users. DefiLlama estimates that Binance holds $137.7 billion in assets. At that scale, attackers have incentives to look for access paths that rely on human decision-making rather than only technical vulnerabilities.

For digital-asset businesses, employee compromise can be especially consequential because staff may have access to internal systems, customer-support tools, operational workflows or sensitive information. Onchain transfers can also be difficult to reverse once assets are moved, which makes prevention and early detection important parts of exchange security programs.

Su said Binance treats phishing resilience as an ongoing operational discipline rather than a compliance checkbox. He described scenarios that include attempts to collect personal information through seemingly harmless interactions, such as offering free conference invitations to test how many targets would provide details.

The use of varied lures reflects how social engineering campaigns can change over time. Simulations based on only one attack format can become less effective if employees simply memorize a familiar pattern. Rotating scenarios can help test whether employees recognize suspicious behavior across different contexts.

For crypto exchanges, custodians and other digital-asset firms, Binance’s program illustrates one approach to turning phishing resistance into a measurable internal control. It also shows how simulated attacks can be tied not only to awareness training, but also to performance evaluation and employee accountability.