Singapore Crypto Firm Loses $11.8 Million in LinkedIn Recruitment Scam
Cybercriminals bypassed multi-factor authentication using session-token theft disguised as a coding assessment.
A Singapore-based cryptocurrency company has lost an estimated US$11.8 million after cybercriminals executed a sophisticated social engineering attack. The breach began on LinkedIn, where attackers posed as recruiters to infiltrate the firm's internal systems.
The attackers initiated a fraudulent recruitment process that included a series of fake interviews and video calls to build trust with a target employee. Once the employee was convinced of the opportunity's legitimacy, the criminals delivered malware disguised as a standard coding assessment. Upon execution, the malware harvested active session tokens from the victim's device, allowing the attackers to bypass multi-factor authentication (MFA) and gain unauthorized access to the company's internal infrastructure and code repository.
The Rise of Social Engineering
This incident is part of a broader trend of highly targeted social engineering attacks aimed at the cryptocurrency sector. Rather than relying on brute-force attacks or simple phishing emails, modern threat actors are increasingly investing time in "long-con" scenarios. By mimicking professional recruitment workflows—complete with video interactions and technical tests—attackers can deceive even tech-savvy professionals into compromising their own workstations.
The MFA Vulnerability
This breach highlights a critical security flaw in the reliance on multi-factor authentication. While MFA is widely considered a gold standard for identity verification, session token theft renders it ineffective. By stealing a token that represents an already authenticated session, attackers can "hijack" the user's identity without ever needing to provide a password or a secondary verification code. This allows for seamless movement into sensitive areas of a corporate network, such as internal servers and proprietary codebases, without triggering security alerts.
Industry Implications
For the broader tech and crypto industries, the attack serves as a warning that standard professional interactions are being weaponized. The use of a coding test as a delivery vehicle for malware is particularly insidious, as it targets the exact behavior expected of a software engineer during a job search. Companies are now being urged to implement stricter endpoint detection and response (EDR) tools and to educate employees on the risks of downloading executable files from external recruiters, regardless of how legitimate the interview process appears.
What Remains Unconfirmed
While the financial loss and the method of entry have been established, the full extent of the data breach beyond the stolen funds remains unclear. It is not yet known if the attackers exfiltrated proprietary source code or customer data during their time inside the company's internal systems. Singaporean authorities continue to investigate the operation to determine if this was an isolated incident or part of a wider campaign targeting the region's financial hubs.