Singapore crypto recruitment scam causes $11.8M loss

iconChainthink
Share
AI summary iconSummary
Singapore police and the Cyber Security Agency reported an $11.8 million crypto market scam involving fake recruitment and system intrusion. Scammers used LinkedIn to impersonate crypto company recruiters, fake domain emails, and Google Meet interviews with cameras turned off. Victims were lured to a fraudulent site to take tests on company devices, where malware stole session tokens and bypassed multi-factor authentication. Attackers modified deployment commands, gained access to internal servers, and stole credentials to transfer funds. Authorities urge users to verify identities, safeguard API keys, and enhance security measures. Crypto analysis experts emphasize the need for heightened vigilance in an evolving threat landscape.

According to CNA, on August 14, Singapore police and the Cyber Security Agency stated that a cryptocurrency-related scam involving fake job postings and software system breaches had resulted in losses of $11.8 million.

In one case, the scammer impersonated a recruiter from a cryptocurrency company on LinkedIn, communicated with the victim using a spoofed domain email, and scheduled multiple Google Meet video interviews with the camera turned off throughout.

The victim was then directed to a fraudulent website, where they completed a technical programming test on a company-issued device, during which malware was downloaded. This malware stole the victim’s session tokens, allowing attackers to bypass multi-factor authentication and access the Bitbucket account linked to the company’s code repository.

The attacker then modified the automated software deployment instructions, gained remote access to internal servers, and stole credentials to bypass transaction limits and approval checks, completing cryptocurrency transfers.

Singapore Police Force and the Cyber Security Agency recommend that technology and cryptocurrency industry companies and individuals verify the identities of recruiters and companies, protect API keys and internal credentials, strengthen multi-factor authentication, and, upon detecting suspected breaches, isolate affected devices, revoke active sessions, reset credentials, and review access logs.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.