Binance Targets Social Engineering Threats with Monthly Phishing Tests
Binance, the world's largest crypto exchange by user base and assets under management, has been running a monthly phishing test program for over three years. The program, led by Chief Security Officer Jimmy Su, targets employees with fake emails designed to mimic real-world social engineering tactics.
The red team at Binance designs scenarios that are varied in tactics, impersonation, and sophistication, ensuring that employees cannot memorize one pattern and consider themselves safe. Employees who fall for the phishing attempts receive remedial training, while repeated failures affect their performance ratings. In extreme cases, chronic offenders face dismissal.
The program's focus on social engineering is a response to the fact that 65% of all crypto security incidents in 2025 were attributed to this type of attack, according to AMLBot. By investing in robust internal security measures, Binance aims to reduce the risk of catastrophic breaches and maintain user trust.