Singapore crypto job scam drains $11.8 million after fake LinkedIn recruiter

A fake job interview on LinkedIn ended up costing a company US$11.8 million after a supposed recruiter walked a Singapore-based employee straight into a malware trap. The Singapore crypto job scam unfolded in stages that felt routine at first — a LinkedIn message, a few video calls, a coding test — before spiraling into a full breach of corporate infrastructure and a cryptocurrency heist, according to the Singapore Police Force and the Cyber Security Agency of Singapore.
Key takeaways
- A victim was approached on LinkedIn by a scammer posing as a recruiter for a crypto-related company, then guided through a fake interview process.
- A spoofed domain and a rigged technical assessment installed malware on the victim’s company-issued device without their knowledge.
- The malware harvested a session token, letting attackers bypass multi-factor authentication and break into the victim’s Bitbucket code repository account.
- From Bitbucket, attackers altered deployment instructions, moved into the company’s internal servers, and bypassed transaction controls to steal US$11.8 million in cryptocurrency.
- Singapore authorities have not linked the attack to North Korea or any other named hacking group.
Singapore Crypto Job Scam Leads to $11.8 Million Loss
The scam began with a message that looked like an ordinary recruitment pitch. SPF and CSA said the victim was first contacted on LinkedIn by someone claiming to recruit for a cryptocurrency-related company, kicking off an interview process that eventually gave outsiders access to the victim’s own employer.
… Continue reading the full article at the original source below.



