Binance Proactively Shields Employees from Social Engineering Attacks
Binance, the world's largest cryptocurrency exchange, takes its security seriously. Every month, the company conducts simulated phishing attacks on its own employees to test their defenses and identify vulnerabilities.
The fake attacks are carried out by Binance's red team, an internal ethical hacking unit. According to Chief Security Officer Jimmy Su, these exercises have been ongoing for three to four years and have significantly improved the company's security hygiene.
The simulated phishing attacks involve posing as job recruiters or offering free conference invites in an attempt to collect personal information from employees. If an employee repeatedly fails the tests, their performance rating will be negatively impacted, which could ultimately lead to dismissal.
This approach is a proactive measure to prepare for social engineering attacks, a common threat in the cryptocurrency space. In 2025, it's estimated that 65% of crypto security incidents were driven by social engineering, with high-profile hacks like the $285 million Drift Protocol heist being attributed to these types of campaigns.