{
  "id": 1742564,
  "title": "‘Technical assessment’ was malware: SPF and CSA warn of S$15 million LinkedIn crypto scam targeting tech workers",
  "url": "https://urgent.news/2026/08/18/technical-assessment-was-malware-spf-and-csa-warn-of-s-15-million",
  "topic": "finance",
  "section": "Finance & Markets",
  "published": "2026-08-18T10:33:48.000Z",
  "source": {
    "name": "The Independent Singapore",
    "slug": "the-independent-singapore",
    "url": "https://theindependent.sg/technical-assessment-was-malware-spf-and-csa-warn-of-s-15-million-linkedin-crypto-scam-targeting-tech-workers/"
  },
  "original_language": "en",
  "account": "The Singapore Police Force (SPF) and Cyber Security Agency (CSA) of Singapore have issued a joint advisory warning against a sophisticated S$15 million crypto scam targeting tech workers. The scam was carried out through social engineering, spoofed communications, and a malicious software download during a technical coding assessment on LinkedIn. The victim was initially contacted by a scammer posing as a recruiter from a cryptocurrency company on LinkedIn. Subsequent communication took place via spoofed email and video interviews on Google Meet, where the interviewer's video was disabled. The victim was led to a fake website for a coding assessment, during which the malware was unknowingly downloaded. This malware bypassed authentication controls, stole internal company credentials, and enabled cryptocurrency transfers totaling US$11.8 million. The SPF and CSA advise the public to be wary of interviewers refusing to enable video on calls, requests for communication through unofficial platforms, and coding assessments requiring file downloads or code execution from unverified sources. Technical professionals should be extra cautious, as they are more likely to execute code without questioning its origin. Businesses should implement technical safeguards such as secure storage of API keys and internal credentials, short-lived credentials, multi-factor authentication with additional controls like device binding and anomalous login detection, monitoring for suspicious logins, and strict access controls in code repositories. Affected individuals can report suspicious crimes to the Police Hotline or the ScamShield Helpline, while urgent Police assistance can be obtained by dialing 999.",
  "summary": "SPF and CSA have issued a joint advisory after a fake LinkedIn recruiter scam drained USD11.8 million in cryptocurrency by tricking a victim into downloading malware during a fake coding assessment... This article ( ‘Technical assessment’ was malware: SPF and CSA warn of S$15 million LinkedIn crypto scam targeting tech workers ) first appeared on The Independent Singapore News .",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}