Binance runs monthly phishing drills, may fire repeat failures

Binance conducts monthly simulated phishing attacks on employees; failing tests can prompt training, lower performance ratings or dismissal after repeated failures.

Binance conducts monthly simulated phishing attacks on employees through an internal red team to test and improve staff security practices. The exercises have run for three to four years and are overseen by Jimmy Su, the exchange’s chief security officer, who said the program tracks employee progress and highlights where extra training is needed.

Tests are designed to resemble real-world social engineering tactics. Scenarios include red-team operatives posing as job recruiters, sending fake conference invitations to collect personal information, and using a bogus video-conferencing update or installer to try to deliver malware. The simulations aim to expose weak points in staff responses before attackers can exploit them.

Results from the monthly exercises feed into employee development. Staff who fail receive remediation training. Those with repeated or severe failures can see their performance rating reduced; ratings that fall to the lowest tier can lead to dismissal if problems continue.

The program operates against a backdrop of frequent social engineering incidents across the cryptocurrency sector. Industry estimates put social engineering behind about 65% of crypto security incidents in 2025. In separate cases, a prolonged social engineering campaign led to a $285 million exploit at one protocol, and a malicious video-conferencing client allowed an attacker to compromise a user’s machine at another protocol, producing a multimillion-dollar loss that was partly recovered through emergency governance.

Binance reports roughly 323 million registered users and industry estimates place assets on the platform near $137.7 billion. The exchange says the monthly drills have improved overall staff security hygiene since they began, and the company continues to vary test scenarios to assess different vulnerabilities.

“We do phishing attacks on our own employees on a monthly basis just so we understand if our security hygiene is improving,” Jimmy Su said. He added that the interview-style lure is only one scenario and that the red team rotates tactics to keep tests realistic and broad.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author