Binance Keeps Employees on High Alert with Monthly Phishing Simulations
Binance, the world's largest cryptocurrency exchange, has been conducting simulated phishing attacks against its own employees every month to test their security awareness and vulnerabilities.
The company uses an internal ethical hacking unit called a 'red team' to conduct these fake attacks, which include posing as job recruiters or offering free conference invites to collect personal information.
Crypto companies are increasingly recognizing the importance of social engineering defense against phishing attacks. Binance's chief security officer Jimmy Su said that in February, AMLBot estimated that 65% of crypto security incidents in 2025 were driven by social engineering.
The company has been conducting these simulated attacks for three to four years and has seen significant improvement in its employees' security hygiene. Those who repeatedly fail the phishing-simulation attack can see their performance ratings negatively impacted, potentially leading to dismissal.