BTC
ETH
HTX
SOL
BNB
View Market
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

Causing $11.8 million in losses, Singapore crypto recruitment scam compromises enterprise systems

2026-08-14 11:26
Odaily News, August 14 — The Singapore Police Force and the Cyber Security Agency have stated that a cryptocurrency-related scam involving fake job postings and software system intrusions has caused $11.8 million in losses. Scammers posed as recruiters for cryptocurrency companies on LinkedIn, communicated with victims via email addresses using lookalike domains similar to legitimate company domains, and arranged multiple Google Meet video interviews with cameras turned off throughout. Subsequently, victims were directed to lookalike websites, where they completed technical coding tests on company-issued devices and unknowingly downloaded malware. The malware stole victims' session tokens, which were used to bypass multi-factor authentication and gain access to Bitbucket accounts linked to the company's code repositories. After obtaining access, the attackers modified the company's automated software deployment instructions, remotely accessed internal servers, and stole credentials to bypass transaction limits and approval checks, completing cryptocurrency transfers. The Singapore Police Force and the Cyber Security Agency have advised technology and cryptocurrency industry companies and individuals to verify the identities of recruiters and companies, protect API keys and internal credentials, strengthen multi-factor authentication, and enhance the security of code repositories and deployment pipelines. If a suspected intrusion is detected, affected devices should be immediately isolated, active sessions revoked, credentials reset, and access logs reviewed.