Security Current Affairs

Binance Fires Employees Who Fail Its Monthly Phishing Tests

2026-07-26

Binance runs simulated phishing attacks on its own staff every month and will sack people who repeatedly flunk them. That's according to chief security officer Jimmy Su, and it tells you something important: the exchange knows that humans are the weakest link in security, full stop.

The fake attacks come from Binance's red team—an internal unit of ethical hackers whose actual job is breaking into systems to find holes. Run these simulations monthly and you get a clear picture of whether your people are getting smarter about security hygiene, or whether they're still clicking dodgy links like it's 2015.

Why the hardline approach? The numbers are brutal. Binance holds $137.7 billion in assets across 323 million registered users. In February, AMLBot found that 65% of all crypto security incidents in 2025 came down to social engineering. Not fancy zero-day exploits. Not billion-dollar hacks of some cutting-edge protocol. People being tricked into giving up access. A Drift Protocol hack in April cost $285 million after a sustained social engineering campaign. In September 2025, a single Venus Protocol user lost $13 million after installing a malicious fake Zoom client. One person. One mistake. Thirteen million gone.

Binance has been doing this for three to four years now. Early on, security hygiene was genuinely dire. But after years of testing and feedback, staff got better at spotting fakes. The red team knows how to make the attacks convincing—fake job recruiter emails, free conference passes, partnership proposals, all designed to harvest personal information. This is how real attackers work. So this is how you test whether people will bite.

The thing that makes Binance's program actually work is consequences. Results feed directly into performance reviews. Fail repeatedly and your rating tanks. Fail severely and repeatedly? You get fired. That's not a scare tactic; that's an incentive structure that acknowledges reality. If someone's going to be the human-shaped security hole that costs the exchange hundreds of millions, they need to know that matters to their employment.

It's also frankly what the industry has been slow to understand. Security isn't just firewalls and encryption and hiring expensive pen testers. It's also making sure your team won't hand over the keys because someone sent a convincing email. The "Zoom meeting attack" is now a recognised thing—hackers trick you into updating a video conferencing app, malware slides in, computers get compromised. Most of these start with a fake job ad. Criminals are patient and they're good at reading people.

Binance reported in Q1 2026 that it safeguarded $1.98 billion against 22.9 million scam and phishing attempts. That's the scale of the threat now. It's everywhere, it's relentless, and it works.

Binance's red-team approach shows crypto security has evolved beyond perimeter defenses. You can't just build walls anymore. Employee awareness is a critical defence layer. Security requires looking at everything—technical vulnerabilities, yes, but also human behaviour and how to shape it. That's the maturation the industry needed.


Source & further reading:

Sources