Urgent.News

One page, thousands of outlets. See who else covered it.

Editions

Finance & Markets

‘Technical assessment’ was malware: SPF and CSA warn of S$15 million LinkedIn crypto scam targeting tech workers

SPF and CSA have issued a joint advisory after a fake LinkedIn recruiter scam drained USD11.8 million in cryptocurrency by tricking a victim into downloading malware during a fake coding assessment... This article ( ‘Technical assessment’ was malware: SPF and CSA warn of S$15 million LinkedIn crypto scam targeting tech workers ) first appeared on The Independent Singapore News .

‘Technical assessment’ was malware: SPF and CSA warn of S$15 million LinkedIn crypto scam targeting tech workers

The Singapore Police Force (SPF) and Cyber Security Agency (CSA) of Singapore have issued a joint advisory warning against a sophisticated S$15 million crypto scam targeting tech workers. The scam was carried out through social engineering, spoofed communications, and a malicious software download during a technical coding assessment on LinkedIn.

The victim was initially contacted by a scammer posing as a recruiter from a cryptocurrency company on LinkedIn. Subsequent communication took place via spoofed email and video interviews on Google Meet, where the interviewer's video was disabled. The victim was led to a fake website for a coding assessment, during which the malware was unknowingly downloaded.

This malware bypassed authentication controls, stole internal company credentials, and enabled cryptocurrency transfers totaling US$11.8 million. The SPF and CSA advise the public to be wary of interviewers refusing to enable video on calls, requests for communication through unofficial platforms, and coding assessments requiring file downloads or code execution from unverified sources.

Technical professionals should be extra cautious, as they are more likely to execute code without questioning its origin. Businesses should implement technical safeguards such as secure storage of API keys and internal credentials, short-lived credentials, multi-factor authentication with additional controls like device binding and anomalous login detection, monitoring for suspicious logins, and strict access controls in code repositories.

Affected individuals can report suspicious crimes to the Police Hotline or the ScamShield Helpline, while urgent Police assistance can be obtained by dialing 999.

Written by urgent.news from The Independent Singapore's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at theindependent.sg →

More in Finance & Markets

More from Tuesday 18 August →