Particle.news

Binance Runs Monthly Phishing Simulations on Employees

The tests enforce remedial training with career consequences to reduce social‑engineering risk across its large user and asset base.

Overview

  • Multiple outlets reported on Sunday that Binance’s internal red team now runs simulated phishing attacks every month across its global workforce to track staff security habits over time.
  • The red team builds realistic lures such as fake recruiter messages and conference invites and records whether employees open messages, click links, or share sensitive details.
  • Employees who fail a simulation must complete remedial training and repeated or severe failures are tied to lower performance ratings and can lead to dismissal.
  • Binance says the three-to-four-year programme has measurably improved staff hygiene but warns simulations cannot stop account hijacks, reused conversations, or AI deepfakes so technical controls remain essential.
  • Industry context underscores the push: a 2025 AMLBot review found about 65% of crypto incidents began with social engineering and high-profile losses like Drift’s $285 million and a Venus user’s $13.5 million theft show the potential impact of staff-level breaches.