A cryptocurrency scam in Singapore involving fake job offers and technical coding assessments has resulted in losses exceeding US$11.8 million (about S$15.1 million) [1, 2, 3].
The Singapore Police Force and the Cyber Security Agency of Singapore issued a joint advisory on August 14 detailing how attackers impersonated recruiters from cryptocurrency firms. The scammers used spoofed domains closely resembling legitimate company websites to lend credibility to their approach [1, 2, 3].
Victims were invited to video interviews via Google Meet where the interviewers deliberately kept their cameras off. During these interviews, candidates were asked to complete technical coding tests on company-issued devices through spoofed websites, leading to the unknowing installation of malicious software [1, 2, 3].
The malicious code harvested session tokens and credentials, enabling the scammers to bypass multi-factor authentication measures and gain access to internal company code repositories hosted on Bitbucket. From there, the attackers altered automated software deployment instructions and remotely accessed company servers [1, 3].
Using the stolen credentials, the scammers evaded transaction limits and approval workflows to carry out unauthorized cryptocurrency transfers that culminated in the large financial losses [1, 2, 3].
Authorities advised businesses, especially those in technology and cryptocurrency sectors, to verify the identities of recruiters and companies genuinely. They recommended protecting API keys and internal credentials, strengthening multi-factor authentication, securing code repositories, and isolating compromised devices immediately. Victims should promptly notify their internal cybersecurity teams to contain any breaches [1, 2, 3].
The advisory issued on August 14 marks the latest effort by Singapore law enforcement to warn the public and help prevent further attacks of this nature [1, 2, 3].