According to CNA, on August 14, Singapore police and the Cyber Security Agency stated that a cryptocurrency-related scam involving fake job postings and software system breaches had resulted in losses of $11.8 million.
In one case, the scammer impersonated a recruiter from a cryptocurrency company on LinkedIn, communicated with the victim using a spoofed domain email, and scheduled multiple Google Meet video interviews with the camera turned off throughout.
The victim was then directed to a fraudulent website, where they completed a technical programming test on a company-issued device, during which malware was downloaded. This malware stole the victim’s session tokens, allowing attackers to bypass multi-factor authentication and access the Bitbucket account linked to the company’s code repository.
The attacker then modified the automated software deployment instructions, gained remote access to internal servers, and stole credentials to bypass transaction limits and approval checks, completing cryptocurrency transfers.
Singapore Police Force and the Cyber Security Agency recommend that technology and cryptocurrency industry companies and individuals verify the identities of recruiters and companies, protect API keys and internal credentials, strengthen multi-factor authentication, and, upon detecting suspected breaches, isolate affected devices, revoke active sessions, reset credentials, and review access logs.


