EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Binance explains employee fishing drills in detail to fight social engineering attacks

2026-07-26 12:53:20
Bookmark

Binance: Internal phishing simulation testing lasts for several years, and employees have repeatedly failed or been fired.

Binance said that it has been conducting simulated phishing attacks internally against employees for years to test employees 'ability to withstand social engineering attacks and link repeated failures to the consequences of improved training and performance. Jimmy Su, the exchange's chief security officer, said the project aims to measure whether "safety and health" conditions have improved in a growing organization.

According to Binance Chief Security Officer Jimmy Su, the red team within Binance conducts fishing simulation tests every month. Employees who fail the test will receive improvement training, while continued poor performance may affect their performance evaluation scores and in extreme cases may even lead to dismissal.

Core Points

Binance Chief Security Officer Jimmy Su said that Binance conducts monthly fishing simulation tests through internal red teams. Employees who fail the test will receive follow-up training aimed at gradually improving employees 'safety habits. Test results may affect performance evaluations; repeated failures may lead to lower scores, which in turn increases employment risks. Su said that Binance has been carrying out such simulated attacks for about three to four years, and its security and health situation have improved compared with its early stages. The above strategy reflects broader industry risks: Social engineering attacks remain the main cause of cryptocurrency security incidents.

How Binance tests employee resilience to social engineering attacks

Binance's approach focuses on authenticity: the red team plays the role of attackers, not only testing technical controls, but also conducting investigations at the company's personnel level. Su said the simulation tests were designed to see if employees became more vigilant over time, adding that the project had been running for about three to four years.

"We conduct phishing attacks on employees every month to find out if our safety and health situation is improving," Su said. He pointed out that the goal is to detect vulnerabilities early-before malicious actors exploit them to launch real attacks. "For employees who fail the test, we will conduct follow-up training." Su also said that in the early stages, the safety and health situation was "not ideal." But after continuing internal testing for a period of time, Binance saw significant improvements. This long-term and sustained pace is important because human error is rarely resolved through one-time training and often requires repeated exposure, feedback, and accountability.

Escalating accountability mechanisms: training and performance evaluation

Binance's internal projects are not only about education, but also about incentive mechanisms. Su said that because simulation test results are reflected in performance evaluations, employees are encouraged to perform better. "If someone repeatedly fails the fishing simulation test, it will have a negative impact on their score. This is the incentive mechanism to be vigilant." He added that repeated and severe failures can cause a person's rating to "rock bottom" and could ultimately be fired. Although there is no specific threshold or timeline, the direction is clear: Binance views recurring susceptibility to fishing as a measurable risk, not just a problem that can be solved purely through training.

For employees and managers, this changes the way information security is discussed. Phishing defense is no longer seen as optional training but becomes part of organizations 'assessment of employee readiness-a shift towards continuous safety assessment.

Strategies: Recruitment bait and Zoom scams

Su described at least one scenario used in the red team simulation: teams disguised as recruiters. This reflects a common pattern of phishing attacks in the real world-using credible backgrounds and sense of urgency to reduce employee vigilance, especially when the target may be inclined to respond to recruitment-related messages. He also mentioned well-known social engineering techniques widely circulated in the cryptocurrency ecosystem, including the "Zoom Conference attack," in which attackers attempt to trick victims into installing malware disguised as conference updates. These attacks often start with bait such as fake job opportunities, but may also use other hooks, such as offering financing or partnerships.

Binance's description is consistent with many incidents in the industry. Reports indicate that it is estimated that 65% of cryptocurrency security incidents in 2025 are driven by social engineering attacks. In addition, a major hacking attack on Drift Protocol in April 2025 was also described as the result of a long-term social engineering attack. In a "Zoom client" attack in September 2025, a large Venus Protocol user allegedly lost approximately $13 million because a malicious Zoom client hacked into his computer and gave the attacker control of his account. Venus suspended the agreement, recovered the assets through an emergency governance vote, and subsequently returned positions worth approximately $11.4 million to victims.

Why internal phishing testing is becoming standard practice in the cryptocurrency space

Binance publicly discusses internal simulated phishing testing at a time when social engineering attacks are widely recognized as a persistent and often underestimated attack surface among digital asset companies. These projects are important because even with complex security systems, intrusions cannot be completely prevented if employees can be tricked into revealing access rights, installing malware, or approving actions. Binance also operates on a huge scale, making manual processes particularly important. The exchange claims 323 million registered users and is estimated to hold $137.7 billion in assets. In such a large environment, attackers have a strong incentive to focus on the easiest path-usually the human decision-making level.

Su said Binance has regarded phishing defense capabilities as an ongoing operational discipline rather than a compliance check item. The scenarios he described included collecting personal information through seemingly harmless interactions, such as offering free meeting invitations to see how many targets would share detailed information. This focus on variable bait is an important point for investors and operators who focus on the industry: attackers adapt, and defense training must adapt. Simulated tests that teach only one "pattern" of attack will soon become obsolete, while projects that rotate scenarios help test whether employees can recognize patterns rather than memorizing scripts.

It is worth watching next whether other major exchanges and custody platforms will adopt similar account-oriented mock testing projects, and more importantly, whether regulators and internal auditors will begin to view phishing prevention testing as a measurable control rather than a general training activity.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP