All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Fake Crypto Job Scams Cost $11.8M in Singapore

Created at 14 Aug · 3:00 PM1 source↑ Market-relevant
IN SHORT

Scammers posing as recruiters for cryptocurrency firms have stolen $11.8 million in Singapore by using fake job offers to compromise company systems. The scheme involved tricking victims into downloading malware that granted access to corporate accounts and led to fund theft.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

$11.8 milliontotal losses from scam
S$15.1 milliontotal losses from scam in Singapore dollars

Who's Involved

Singapore Police Force
issued joint advisory on scam
Cyber Security Agency of Singapore
issued joint advisory on scam
LinkedIn
platform used for initial contact by scammers
Bitbucket
account compromised by malware
Fake Crypto Job Scams Cost $11.8M in Singapore

↳ Why This Matters

This scam highlights a sophisticated method of corporate cyber theft that leverages social engineering and malware to target cryptocurrency firms, resulting in significant financial losses and underscoring the need for enhanced cybersecurity measures and employee vigilance.

Key facts

  • Scammers have stolen $11.8 million (S$15.1 million) through fake crypto job offers.
  • The scam involved compromising company systems via malware downloaded during fake coding assessments.
  • Malware captured session tokens, bypassing multi-factor authentication and accessing Bitbucket accounts.
  • Attackers used stolen credentials to bypass transaction limits and move funds.
  • Scammers posing as recruiters for cryptocurrency companies have defrauded victims of $11.8 million (S$15.1 million) by exploiting fake job offers to compromise their employers' systems. According to a joint advisory from the Singapore Police Force and the Cyber Security Agency of Singapore, the scheme begins with a bogus recruiter contacting individuals on LinkedIn. The conversation then moves to email, using a spoofed domain that closely mimics a legitimate firm's, and interviews are conducted via Google Meet with the interviewer keeping their camera off.

    Victims are subsequently directed to a fake website to complete a technical coding assessment, often on a company-issued device. During this process, they unknowingly download malicious software. This malware captures a session token, which is used to bypass multi-factor authentication and gain access to the victim's Bitbucket account, a platform used for storing and managing source code. Once inside, attackers can alter software systems, access internal servers, and obtain credentials. These credentials are then used to circumvent transaction limits and approval processes, ultimately leading to the theft of funds.

    Researchers have documented similar operations, such as 'Contagious Interviews,' where fake recruiters target Web3 developers with malicious code, including compromised packages uploaded to the npm registry. While some campaigns are attributed to North Korean hackers, the tactics are not exclusive to them. The Russian-speaking group Crazy Evil, for instance, created a fake Web3 company, ChainSeeker.io, to lure applicants into installing malware. The advisory did not name any specific companies targeted or disclose where the stolen funds were transferred.

    Frequently asked questions

    The total losses from the scam amounted to $11.8 million, or S$15.1 million.

    Scammers used LinkedIn for initial contact, email with spoofed domains, Google Meet for interviews, and a spoofed website for the coding assessment. The malware targeted Bitbucket accounts.

    The malware captured session tokens, which allowed attackers to bypass multi-factor authentication and gain access to the victim's Bitbucket account.

    Individuals should verify recruiters through official channels, be wary of interviewers who do not turn on their cameras, and avoid running code from unverified sources. Companies should secure API keys, internal credentials, and monitor for unusual network activity.

    What Happens Next

    01Decrypt will update the article if LinkedIn responds to a request for comment.

    Get the newsletter.

    Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

    Cadence

    How It Developed

    Scammers used fake LinkedIn profiles to approach victims for crypto jobs.
    Victims were directed to spoofed websites for coding assessments.
    Malicious software downloaded during assessments captured session tokens.
    These tokens bypassed multi-factor authentication, granting access to Bitbucket accounts.
    Attackers altered software systems and accessed internal servers to steal funds.

    Sources

    T1
    Fake LinkedIn Crypto Job Scams Have Cost $11.8M: SingaporeDecrypt

    Related Stories

    Queensland man loses $166,000 to AI-powered crypto scam
    14 Aug · 3:16 PM
    Bitcoin's $116M Exploit Sparks Self-Custody Debate Amid ETF Inflow Rebound
    14 Aug · 3:46 PM
    Ireland Enhances Crypto Wallet Checks Under New AML Strategy
    14 Aug · 12:46 PM
    Crypto payments barely register among euro area merchants, ECB finds
    14 Aug · 8:41 AM
    Ethereum Foundation Drops Poseidon Hash Function for Post-Quantum Plans
    13 Aug · 11:46 PM