• Singapore loses $11.8M to fake recruiting scams targeting crypto firms
  • US Dollar Steadies as Carry Trades Persist, Fed on Hold – OCBC
  • AUD/USD Price Forecast: Bulls Target 0.7100 After US Retail Sales Miss
  • GBP/USD Pushes Above 1.3500 as Broad-Based US Dollar Weakness Persists
  • Bitcoin, Ethereum, Ripple Face Steeper Correction Risk as Bearish Pressure Builds
2026-08-15
Coins by Cryptorank
Bitcoinworld Bitcoinworld
Bitcoinworld Bitcoinworld
  • Crypto News
  • AI News
  • Forex News
  • Sponsored
  • Press Release
  • Media Kit
  • Advertisement
  • More
    • About Us
    • Learn
    • Exclusive Article
    • Reviews
    • Events
    • Contact Us
    • Privacy Policy
Bitcoinworld
  • Crypto News
  • AI News
  • Forex News
  • Sponsored
  • Press Release
  • Media Kit
  • Advertisement
  • More
    • About Us
    • Learn
    • Exclusive Article
    • Reviews
    • Events
    • Contact Us
    • Privacy Policy
Skip to content
Home Crypto News Singapore loses $11.8M to fake recruiting scams targeting crypto firms
Crypto News

Singapore loses $11.8M to fake recruiting scams targeting crypto firms

  • by Dhaval
  • 2026-08-15
  • 0 Comments
  • 2 minutes read
  • 0 Views
  • 4 seconds ago
Facebook Twitter Pinterest Whatsapp
Cybersecurity concept: computer monitor with login screen and lock icon in a modern office

Singapore has reported losses of $11.8 million from a sophisticated scam in which criminals posed as recruiters for cryptocurrency-related companies, infiltrated corporate systems, and stole digital assets, according to CNA. The Singapore Police Force (SPF) and the Cyber Security Agency of Singapore (CSA) have issued a joint advisory urging tech and crypto firms to verify recruiter identities and strengthen internal security measures.

How the scam works

In one documented case, a victim received a fake job offer via LinkedIn. After downloading malware during a coding test on a company-issued device, the scammers captured the victim’s login session data, bypassed multi-factor authentication (MFA), and accessed the company’s code repository and internal servers. They then obtained credentials that allowed them to circumvent transfer limits and approval procedures, ultimately stealing cryptocurrency.

The attack chain highlights a growing trend: cybercriminals are exploiting the trust inherent in recruitment processes, particularly in the fast-moving crypto sector where remote work and digital onboarding are common. The use of social engineering to deliver malware is not new, but the level of sophistication in bypassing MFA and moving laterally within corporate networks indicates a well-resourced and organized threat actor.

Implications for the crypto industry

The losses underscore the vulnerability of crypto firms, which often manage high-value assets and rely on complex internal workflows. The fact that scammers could bypass transfer limits and approval procedures suggests that security controls were not sufficiently layered or monitored. This incident serves as a reminder that technical safeguards alone are insufficient without robust identity verification and employee training.

For the broader tech sector, the advisory from SPF and CSA is a clear signal that recruitment processes are being weaponized. Companies are urged to verify the legitimacy of recruiters, especially those contacting candidates via professional networks, and to ensure that job applicants do not download unverified software or grant unnecessary access to corporate devices.

What firms should do now

The authorities recommend a multi-pronged approach: verify recruiter identities through official channels, protect internal credentials with hardware-based MFA or phishing-resistant methods, and conduct regular security audits. Additionally, companies should monitor for unusual login patterns and implement strict access controls for sensitive systems. Employees should be trained to recognize social engineering attempts, and clear procedures should be in place for reporting suspicious communications.

Conclusion

The $11.8 million loss in Singapore is a stark reminder that cyber threats are evolving beyond traditional phishing emails. By targeting the recruitment process, scammers have found a way to exploit human trust and technical gaps simultaneously. The response from SPF and CSA emphasizes the need for continuous vigilance and proactive security measures. For crypto firms, this is not just a regulatory concern but a business continuity issue that demands immediate attention.

FAQs

Q1: How did the scammers bypass multi-factor authentication?
In the reported case, the scammers stole the victim’s login session data after malware was installed on a company-issued device. This allowed them to replay the session and bypass MFA, as the authentication had already been completed.

Q2: What should job seekers do to avoid falling victim to such scams?
Job seekers should verify the legitimacy of recruiters by checking official company websites and contacting the company directly. They should avoid downloading software or clicking links from unsolicited messages, especially during job application processes.

Q3: What security measures can crypto firms implement to prevent similar attacks?
Firms should implement phishing-resistant MFA, enforce strict access controls, conduct regular security training, and monitor for unusual login behavior. Additionally, they should verify all communication from external parties, including recruiters, and ensure that internal approval processes are not easily bypassed.

Disclaimer: The information provided is not trading advice, Bitcoinworld.co.in holds no liability for any investments made based on the information provided on this page. We strongly recommend independent research and/or consultation with a qualified professional before making any investment decisions.

Related Reading

  • South Korea’s Tax Agency Warns of Phishing Emails Posing as Crypto Tax Notices
  • Bitcoin Red Team Turns to Chinese AI for Open-Source Security Audits, Unearths 4,962 Flaws
  • Anthropic’s AI agents start turf wars and collude when left to their own devices
  • Hyperliquid Users Lose ~$550K in Google Search Ad Phishing Scam
  • Trezor shipping provider breach exposes data of 13,689 customers

Tags:

Crypto ScamCybersecurityjob scamPhishingSINGAPORE

Share This Post:

Facebook Twitter Pinterest Whatsapp
Dhaval

Dhaval

Author
Dhaval Aggarwal covers cryptocurrency markets and Web3 venture investing for BitcoinWorld. His reporting focuses on funding rounds, exchange listings, on-chain treasury activity, and the partnerships connecting crypto-native firms with traditional finance. Since joining the desk in 2023, he has tracked the deal flow behind major Layer-2 networks, Bitcoin treasury programs, and institutional adoption stories. He writes daily news pieces for active traders and longer analyses for readers following where the next cycle of crypto growth is heading.
Next Post

US Dollar Steadies as Carry Trades Persist, Fed on Hold – OCBC

Categories

92

AI News

Crypto News

Bitcoin Treasury Ambition: The Blockchain Group Seeks Staggering €10 Billion

Events

97

Forex News

33

Learn

Press Release

Reviews

Google NewsGoogle News TwitterTwitter LinkedinLinkedin coinmarketcapcoinmarketcap BinanceBinance YouTubeYouTubes

Copyright Β© 2026 BitcoinWorld | Powered by BitcoinWorld