Binance Tests Employees With Fake Phishing Attacks
Binance is running monthly simulated phishing attacks on its own employees and tying the results directly to performance reviews, chief security officer Jimmy Su has confirmed. How the Progra
A
AnonymousCryptoCompass newsroom
July 28, 2026
2 min read
NEWS
CryptoCompass editorial visual for markets coverage.
Binance is running monthly simulated phishing attacks on its own employees and tying the results directly to performance reviews, chief security officer Jimmy Su has confirmed.
How the Program Works
Binance runs an internal security system that carries out simulated phishing attacks on employees every month and can dismiss staff who repeatedly fail.The simulated attacks are handled by Binance's internal ethical hacking group, the red team, which infiltrates systems to find vulnerabilities and designs fake attack scenarios targeting employees.
Scenarios range from fake recruitment pitches to bogus conference invitations and attempts to collect personal data.The red team rotates tactics to keep tests realistic and broad.Su said the program has been in place for three to four years, and security awareness, which was lacking at first, has since improved substantially across the company.
Stakes for Employees
Su told Cointelegraph that Binance's internal red team performs phishing simulations on a monthly basis, and employees who fail receive remediation training, while continued poor performance can affect their performance review ratings and, in extreme cases, lead to dismissal.
Su said employees are incentivised to perform well because the results are reflected in their performance reviews. "If someone repeatedly fails the phishing-simulation attack, that will negatively impact their rating. That's the incentive to be vigilant."Repeated, severe failures could lead to their rating bottoming out, which could see them dismissed.
Binance says it has been running internal, simulated phishing attacks against its own staff for several years, testing how well employees resist social engineering attempts and tying repeat failures to remediation training and performance consequences.Social engineering continues to be a major driver of crypto security incidents.
Bybit is delisting XTER, SCA, TOKEN, HPOS10I, PUMPBTC, AFC, INTER, XAVA and AO from spot trading, removing all nine tokens from the exchange's spot market in a single update to its trading pa
Ark Invest bought 124,543 SPCX shares worth $14.1 million. The firm also purchased 4,799 SOLQ shares valued at about $30,000. Ark reduced its Robinhood (HOOD) position by selling 12,119 share
Which Crypto Presales 2026 Have the Best Security Reviews? Funds raised gets most of the attention in presale rankings. Audit quality rarely does. This piece flips that order. We're looking a