Overview
- Multiple outlets reported on Sunday that Binance’s internal red team now runs simulated phishing attacks every month across its global workforce to track staff security habits over time.
- The red team builds realistic lures such as fake recruiter messages and conference invites and records whether employees open messages, click links, or share sensitive details.
- Employees who fail a simulation must complete remedial training and repeated or severe failures are tied to lower performance ratings and can lead to dismissal.
- Binance says the three-to-four-year programme has measurably improved staff hygiene but warns simulations cannot stop account hijacks, reused conversations, or AI deepfakes so technical controls remain essential.
- Industry context underscores the push: a 2025 AMLBot review found about 65% of crypto incidents began with social engineering and high-profile losses like Drift’s $285 million and a Venus user’s $13.5 million theft show the potential impact of staff-level breaches.