Binance Simulates Phishing Attacks on Employees Amid Growing Social Engineering Threat
Binance, the world's largest crypto exchange by volume, has been conducting internal red team operations to test its employees' vulnerability to phishing attacks. According to Chief Security Officer Jimmy Su, the program has improved the company's 'security hygiene' and has been active for over three years.
The simulated phishing attacks are designed to mirror real-world social engineering tactics, including fake job recruiter messages and too-good-to-be-true conference invitations. Employees who fall for these lures don't receive a slap on the wrist; instead, they're put through remedial training. Repeated failures can affect performance ratings, and chronic offenders face dismissal.
The program's focus on social engineering is significant, as a report from AMLBot found that 65% of all crypto security incidents in 2025 were attributed to this type of attack. By rotating tactics and adjusting the sophistication of the lures, Binance's red team ensures that employees can't just memorize one pattern and consider themselves safe.