Skip to main content
BTC / USDT——ETH / USDT——SOL / USDT——BNB / USDT——XRP / USDT——DOGE / USDT——TON / USDT——AVAX / USDT——LINK / USDT——ADA / USDT——TRX / USDT——DOT / USDT——BTC / USDT——ETH / USDT——SOL / USDT——BNB / USDT——XRP / USDT——DOGE / USDT——TON / USDT——AVAX / USDT——LINK / USDT——ADA / USDT——TRX / USDT——DOT / USDT——
Preise
cryptoJul 27, 2026, 10:52 AM

Binance Fires Staff Who Fail Monthly Phishing Tests

Binance runs mandatory monthly phishing simulations via an internal red team, with repeat failures affecting performance reviews and potentially leading to termination, according to CSO Jimmy Su.

Global cryptocurrency exchange Binance is running mandatory monthly phishing simulations against its own workforce, and employees who repeatedly fail the tests may ultimately lose their jobs. The initiative is led by Binance's internal ethical hacking unit, known as the "red team," and is designed to measure and improve the operational security habits of staff across the company.

Binance Chief Security Officer Jimmy Su said employees who fall for the simulated phishing lures are required to complete targeted remediation training. However, repeat failures carry more serious consequences, as test performance is factored into internal performance reviews. Staff whose scores bottom out can face termination, reflecting the exchange's view that human risk management is a critical part of its broader security infrastructure.

The simulations are not simple spam templates. The red team crafts realistic scenarios that mirror current cybercriminal tactics, including fake recruiter messages, counterfeit event invitations, and malicious video-conferencing updates. One common test mimics a "Zoom meeting attack," where employees receive phishing emails designed to trick them into downloading malware disguised as a software update. Other scenarios use fake job opportunities to harvest credentials, or fraudulent partnership proposals and conference invitations to see whether staff will improperly disclose personal or corporate information.

Binance, which says it holds well over $100 billion in user assets as the world's largest digital asset exchange, views these tests as a necessary defense against increasingly sophisticated social engineering threats. The firm's leadership noted that early internal testing revealed significant gaps in security hygiene, but years of persistent monthly simulations have produced measurable improvements across the organization.

The policy reflects a broader industry consensus that human error is the primary entry point for major security breaches in the Web3 and fintech sectors. Social engineering campaigns, from credential harvesting to business email compromise, account for most security incidents facing cryptocurrency platforms, according to industry data. Cybercriminals frequently target crypto exchange employees through social channels to bypass technical firewalls and gain access to critical network infrastructure.

By aligning HR policies with threat mitigation, Binance is signaling that major digital asset exchanges increasingly treat staff security awareness as a core part of protecting institutional infrastructure from credential theft and unauthorized access.

Source: FinanceFeeds