Scammers posing as recruiters for cryptocurrency companies have taken $11.8 million (S$15.1 million), using fake job offers to compromise their targets' employers, according to a joint advisory from the Singapore Police Force and the Cyber Security Agency of Singapore.
The victim was then sent to a spoofed website to complete a technical coding assessment, and did so on a company-issued device, downloading malicious software in the process without realizing it.
From there the attackers altered the employer's software systems and reached its internal servers, the agencies said, collecting credentials that were then used to get around transaction limits and approval checks and move funds. The advisory does not name any company, say where the funds went, or attribute the attacks to anyone. Decrypt has approached LinkedIn for comment and will update this article should they respond.
Contagious InterviewsSingapore agencies’ advice to individuals is to verify recruiters through official channels, treat an interviewer who will not turn on their camera as a warning sign, and never run code from an unverified source. For companies, the agencies recommend securing API keys and internal credentials, strengthening multi-factor authentication and watching for unfamiliar devices and unusual network activity. Where a compromise is suspected, they advise isolating affected systems, revoking active sessions, resetting credentials and reviewing access logs.


















