Binance's Chief Security Officer confirmed the exchange conducts monthly simulated phishing tests on employees, with repeated failures potentially resulting in dismissal.
Regulation & Gov ·
Binance's Chief Security Officer Jimmy Su disclosed that the exchange operates an internal Red Team conducting monthly simulated phishing campaigns to evaluate employee security awareness. The testing scenarios encompass fake recruitment pitches, counterfeit conference invitations, and social engineering attempts designed to extract personal information.
Employees who fall victim to these simulated attacks must complete remedial security training. Those with repeated serious failures face consequences including damage to performance evaluations and potential termination from employment.
Binance has maintained this security testing program for approximately three to four years. No details have been disclosed regarding the overall success or failure rates of the phishing simulations, the size of the workforce subject to testing, or specific metrics used to determine what constitutes a "serious" failure warranting escalated consequences.