Binance warns users of phishing attacks using fake security alerts via SMS and email to steal account credentials.
Regulation & Gov ·
Binance has cautioned users against a phishing campaign that relies on fraudulent security notifications delivered through SMS, email, and messaging applications to compromise account credentials. The scam works by luring victims to click malicious links embedded in fake alerts, which can lead to unauthorized access and fund theft from compromised accounts.
The attack exploits a common user behavior: responding urgently to security warnings. Threat actors craft communications that mimic legitimate Binance notifications, creating a false sense of immediacy around account protection or suspicious activity. Since these messages arrive through channels users regularly associate with official communications, they carry heightened credibility and increase the likelihood of engagement.
Binance has not disclosed details about the scale of the campaign, affected user count, or specific technical indicators of compromise in available advisories. The exchange has not announced whether it is working with law enforcement or has identified the specific threat actors responsible.