Binance Conducts Strict Phishing Drills for Staff, Repeated Failures Risk Dismissal

AMLBot data shows social engineering is a major driver of crypto losses, with 65% of investigated cases in 2025 beginning from social engineering and phishing accounting for 18% of those cases.
Binance’s Red Team conducts Zoom meeting attack-style campaigns, a tactic where attackers lure targets into installing malware disguised as a video-conferencing app update.
Binance’s red team is described as an internal white-hat hacking unit, and the company also collaborates with external researchers through bug bounty programmes to strengthen security.
The red team records employees’ responses to simulated attacks, including whether messages are opened, links followed, or personal information is shared, to tailor remedial training.
Binance fires employees who repeatedly fail its monthly fake phishing tests, the world's largest crypto exchange has confirmed. The company's internal Red Team has been running simulated attacks on staff for three to four years, according to Cointelegraph.
The drills use realistic scenarios — fake recruiter messages, invites to free conferences, and bogus Zoom meeting links. Employees who click, share personal details, or fall for the trap face remedial training. Repeat failures can lead to the lowest performance rating or outright termination, Crypto Briefing reported.
Binance's Red Team is an internal white-hat hacking unit — meaning it tries to break in to help defend against real attackers. The team designs fake attacks that mimic real threats. Scenarios include messages from fake recruiters and invitations to free industry events, according to crypto.news.
The team tracks exactly what each employee does. It records whether a message was opened, whether a link was clicked, and whether any personal information was shared. That data shapes the remedial training each worker gets, Startup Fortune reported. Binance also runs bug bounty programmes, paying outside researchers to find security flaws.
One attack style the Red Team simulates involves fake Zoom meeting links. In the real version of this scam, attackers lure targets into downloading what looks like a video-conferencing app update. The file is actually malware. Binance trains staff to spot this before they click, according to Crypto Briefing.
Binance's Chief Security Officer, Jimmy Su, leads the effort. The goal is to reduce the risk of social engineering — scams that trick people rather than hack systems. With roughly 323 million users and about $137 billion in assets under custody, the stakes for getting this wrong are enormous, crypto.news noted.
Binance's drills reflect a broader crisis across the crypto industry. Data from AMLBot shows that 65% of investigated crypto loss cases in 2025 started with social engineering. Phishing alone accounted for 18% of those cases, Cointelegraph reported.
Social engineering means tricking a person rather than breaking a computer system. It is now one of the leading causes of crypto losses, alongside technical exploits. Training staff to recognize these tricks has become as important as any software firewall, according to HokaNews.
Binance ties phishing test results directly to performance reviews. The company wants staff to know that falling for a fake attack has real consequences. Repeated failures can result in the lowest possible performance rating, Startup Fortune reported.
In serious cases, termination is on the table. Binance says this hard line is meant to push employees to stay alert, not just in tests but at all times. The company frames it as a necessary defense for a platform handling hundreds of billions in user assets, according to Crypto Briefing.
Publishers
13
Articles
10
Reach
23