Binance Runs Monthly Phishing Drills for Staff, Repeated Failures Can Lead to Firing
- Binance said it conducts simulated phishing attacks on employees every month and that repeated failures can lead to firing.
- Binance said training carried out over the past three to four years through its Red Team has significantly improved security awareness across the company.
- Binance said it has 323 million users and $137.7 billion in assets under custody, while the threat of social engineering attacks is increasing.
Forecast Trend Report by Period



Binance, the world’s largest cryptocurrency exchange, runs monthly simulated phishing attacks on employees and may discipline repeat offenders up to and including termination.
Cointelegraph reported on July 26 that Binance Chief Security Officer Jimmy Su said the company carries out in-house phishing drills every month to measure whether employees’ security awareness is improving. Employees who fail the tests receive additional training.
The drills are run by Binance’s internal white-hat hacking unit, known as the Red Team. The group tries to penetrate internal systems like real hackers to identify vulnerabilities. Su said the program has been in place for three to four years. Security awareness was lacking at first, but has since improved substantially across the company.
The mock attack scenarios vary. A common tactic is for Red Team members to pose as recruiters. Another involves attempts to collect personal information under the pretext of offering free conference invitations. One method hackers have frequently used in recent years is the so-called “Zoom meeting attack,” which tricks targets into installing malware disguised as an update for a video-conferencing app.
The results of the drills are also reflected in performance reviews. Employees who repeatedly fail phishing simulations receive lower evaluation scores. Repeated serious failures can result in the lowest possible rating and may ultimately lead to firing.
Binance currently has 323 million users and holds $137.7 billion in assets under custody, according to DefiLlama estimates. The threat of social engineering attacks is rising across the industry. AMLBot, an anti-money laundering solutions company, estimated in February that 65% of cryptocurrency security incidents in 2025 stemmed from social engineering.