Binance runs monthly simulated phishing campaigns against its employees, using its internal Red Team to mimic real-world attacks such as bogus job offers, fake conference invitations, and credential-harvesting schemes. The drills have been conducted for three to four years, Chief Security Officer Jimmy Su confirmed, and are designed to measure awareness and reinforce secure behavior. Employees who fail must complete remedial training; repeated or severe failures can lower performance ratings and ultimately lead to termination.
The program targets the human layer often exploited in major crypto breaches. According to AMLBot data, 65% of over 2,500 investigated cases in 2025 started with social engineering. The Red Team records whether staff open suspicious messages, follow links, or share sensitive data, then adjusts training as attacker methods evolve. Su said early security habits "left a lot to be desired" but have improved steadily under the initiative. With 323 million registered users and roughly $137.5 billion in linked assets, Binance treats internal phishing resistance as a critical defense.
No other major exchange has publicly disclosed a comparable mandatory program with such direct employment consequences. While many firms likely run simulations, Binance’s transparency signals that insider compromise is a persistent, high-stakes risk—especially as regulatory pressure mounts and institutional capital flows in. Questions remain about the program’s long-term effectiveness, potential morale impacts, and whether it will extend to contractors and vendors.