Binance Runs Monthly Employee Phishing Drills, Repeat Failures Can Lead to Dismissal
Summary
- Binance said it conducts monthly simulated phishing attack drills for employees and that repeated failures can lead to dismissal.
- Binance said its Red Team has run the drills for the past three to four years, helping significantly improve security awareness across the company.
- Binance said it has 323 million registered users and $137.7 billion in assets under custody, while the threat of social engineering attacks is increasing.
Forecast Trend Report by Period



Binance, the world’s largest cryptocurrency exchange, conducts monthly simulated phishing attacks on employees and can impose disciplinary measures, including dismissal, on workers who repeatedly fail the tests.
Jimmy Su, Binance’s chief security officer, told Cointelegraph on July 26 that the company runs the in-house phishing drills every month to measure whether employees’ security awareness is improving. Workers who fail the tests receive additional training.
Binance’s internal white-hat hacking unit, known as the Red Team, runs the drills. The group attempts to breach internal systems the way real hackers would to uncover vulnerabilities. Su said the program began three to four years ago. While security awareness was lacking at the outset, it has improved markedly across the company.
The mock attack scenarios vary. One common tactic is for Red Team members to pose as recruiters. The exercises also include attempts to collect personal information under the guise of offering free conference invitations. In recent years, hackers have also used the so-called “Zoom meeting attack,” which tricks victims into installing malware disguised as an update for a video-conferencing app.
The results of the drills are also reflected in performance reviews. Repeated failures in phishing simulations hurt employees’ evaluation scores. If serious failures continue, workers can receive the lowest possible rating, which can ultimately lead to dismissal.
Binance has 323 million registered users, and assets in custody total $137.7 billion, according to DefiLlama estimates. The threat from social engineering attacks is rising across the industry. AMLBot, an anti-money-laundering solutions company, estimated in February that 65% of cryptocurrency security incidents in 2025 stemmed from social engineering.