Singapore crypto job scam costs company $11.8 million
A fake cryptocurrency job offer that infected a company-issued device has led to US$11.8 million in losses after attackers gained access to corporate systems and bypassed transaction controls, Singapore authorities have said. The Singapore Police Force and Cyber Security Agency of Singapore said on Aug. 14 that the victim was first contacted on LinkedIn by a scammer posing as a recruiter from a cryptocurrency-related company, beginning an interview process that eventually gave the attackers access to the victims employer. Communication moved from LinkedIn to email, where the supposed recruiter used a spoofed domain that closely resembled the legitimate companys address. The victim also attended several interviews through Google Meet, although the person conducting the interviews kept their camera switched off during the calls. As the recruitment process advanced, the victim was sent to a spoofed website and asked to complete a technical coding assessment on a company-issued device. Malicious software was downloaded during the assessment without the victim realizing the device had been compromised. Fake crypto job assessment opened access to corporate systems Once installed, the malware harvested the victim‘s session token, SPF and CSA said. Attackers then used the stolen token to bypass multi-factor authentication and gain access to the victim’s Bitbucket account, which