Skip to content

Singapore Police Force Reveals Involvement in Cryptocurrency Job Scam, Causing $11.8 Million in Losses

Aug 14, 16:11

August 14th—Singaporean authorities, in collaboration with the Cyber Security Agency, announced today that a cryptocurrency-related scam involving false job offers and software system breaches has resulted in a $11.8 million loss. In this case, the fraudsters impersonated cryptocurrency companies' recruiters on LinkedIn to contact victims. They used spoofed domain emails similar to the genuine company domain to communicate with the victims and arranged multiple Google Meet video interviews with cameras turned off throughout. Subsequently, the victims were directed to a phishing website where they were asked to complete a technical programming test on company-provided devices, unknowingly downloading malware in the process. This malware stole the victims' session tokens, which were then used to bypass two-factor authentication and gain access to the Bitbucket account associated with the company's code repository. Once the attackers gained access, they altered the company's automated software deployment instructions, remotely accessed its internal servers, exfiltrated credentials to circumvent transaction limits and approval checks, and carried out cryptocurrency transfers.

Singaporean authorities, along with the Cyber Security Agency, recommend that businesses and individuals in the technology and cryptocurrency industries verify the identity of recruiters and companies, secure API keys and internal credentials, implement robust two-factor authentication, strengthen the security of code repositories and deployment pipelines, and, in case of suspected breaches, promptly isolate affected devices, revoke active sessions, reset credentials, and review access logs.

Source