Binance Fights Phishing Threats from Within
Binance's internal security team conducts regular phishing drills to test employees' vulnerability to simulated attacks. The exchange runs these tests monthly, sending fake recruiter messages or free conference invitations via email or LinkedIn, in an effort to see who opens links, follows instructions, and hands over sensitive information.
The program has been running for three to four years, with results showing improvement during that time. According to Binance's chief security officer Jimmy Su, the company wants to understand if its security hygiene is improving through these exercises.
For an exchange of Binance's scale, handling over 323 million registered users and $137.7 billion in assets, this isn't a trivial matter. The goal is to prepare employees for real-world attacks, similar to the one that compromised Bybit in February 2025, where North Korean hackers stole approximately $1.5 billion in virtual assets.
While some may view Binance's approach as harsh, tying repeated failure to performance consequences can be an effective way to instill habits of caution and verification among employees. However, it's essential to balance this with a culture that encourages staff to report mistakes quickly rather than panicking after one bad click.