Binance conducts monthly simulated phishing attacks against its employees to improve internal security hygiene and mitigate the growing threat of social engineering campaigns targeting the cryptocurrency industry.
Key Points
- Binance’s internal "red team" executes monthly phishing simulations, including fake job recruitment and conference invitations, to test staff vigilance.
- Employees who repeatedly fail these security tests face negative performance reviews, which can ultimately lead to termination.
- Chief security officer Jimmy Su reports that the program has significantly improved the company's overall security posture over the last four years.
- Social engineering remains a primary threat, accounting for approximately 65% of cryptocurrency security incidents in 2025 according to AMLBot data.
- Binance currently manages $137.7 billion in assets and serves 323 million registered users, making it a high-value target for malicious actors.