Binance Conducts Monthly Simulated Phishing Attacks on Employees
Binance, the largest cryptocurrency exchange in the world, has implemented an internal security measure to protect against social engineering attacks. The company's chief security officer, Jimmy Su, revealed that Binance runs simulated phishing attacks against its own employees on a monthly basis.
The goal of these tests is to identify vulnerabilities and assess the company's 'security hygiene'. According to Su, in the beginning, the security hygiene left much to be desired, but after three to four years of running these simulations, Binance has improved significantly.
The red team, an internal ethical hacking unit, poses as job recruiters or offers fake conference invites to test employees' vigilance. If someone repeatedly fails the phishing-simulation attack, it can negatively impact their performance review and potentially lead to dismissal.