En.Bloomingbit Binance Implements Strict Phishing Drill Policy for Employees
Article Content
- •Binance conducts monthly phishing drills to enhance employee security awareness.
- •Repeated failures in drills can lead to remedial training and potential termination.
- •Social engineering attacks accounted for 65% of crypto security incidents in 2025.
Binance, the largest cryptocurrency exchange, has instituted monthly phishing drills for its employees, with potential termination for repeat failures. The drills, conducted by the internal 'Red Team', have been in place for three to four years and aim to improve security awareness. Employees who fail these tests receive remedial training, and repeated failures negatively impact performance evaluations. The simulated attacks mimic real-world social engineering tactics, such as impersonating recruiters and offering free conference invitations. In 2025, social engineering accounted for 65% of cryptocurrency security incidents, highlighting the importance of these drills. Binance currently manages approximately $137.7 billion in assets and serves 323 million users, making its internal security practices critical. The initiative reflects a growing concern over social engineering threats in the cryptocurrency sector.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (17)
Following this threat?
Track Binance in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…