Skip to main content
Advertisement
Advertisement

Singapore

Authorities warn against cryptocurrency-related scams involving fake job offers after US$11.8 million in losses

In such cases, scammers pose as recruiters and trick victims into downloading malware through fake technical assessments, allowing them to compromise company systems and steal cryptocurrency.

Authorities warn against cryptocurrency-related scams involving fake job offers after US$11.8 million in losses

Representations of cryptocurrencies are seen in this illustration on Aug 10, 2022.(File photo: Reuters/Dado Ruvic)

New: You can now listen to articles.

This audio is generated by an AI tool.

14 Aug 2026 02:38PM (Updated: 14 Aug 2026 08:46PM)

SINGAPORE: A cryptocurrency-related scam involving fake job offers and compromised software systems has resulted in losses of US$11.8 million, the Singapore Police Force (SPF) and Cyber Security Agency of Singapore (CSA) said on Friday (Aug 14).

In one case, a victim was approached on LinkedIn by a scammer impersonating a recruiter from a cryptocurrency-related company. 

The scammer communicated with the victim through email, using a spoofed domain closely resembling the legitimate company’s domain.

The victim also attended several video interviews on Google Meet, although the interviewer’s video remained switched off throughout.

Subsequently, the victim was directed to a spoofed website to complete a technical coding assessment on his company-issued device, during which he unknowingly downloaded malicious software.

The malware enabled the scammer to bypass authentication controls to harvest internal company credentials, and used them to carry out cryptocurrency transfers.

SPF and CSA advised businesses and individuals, particularly those in the technology and cryptocurrency sectors, to adopt precautionary measures.

Some measures include verifying recruiter and company identities, protecting application programming interface (API) keys and internal credentials, strengthening multi-factor authentication and securing code repositories and deployment pipelines.

Should there be a suspected compromise, affected devices or systems should be isolated immediately, active sessions revoked, credentials reset, and access logs reviewed.

Individuals and businesses should notify their internal cybersecurity teams or service providers without delay, and assess whether accounts, repositories, internal servers or approval workflows have been altered.

 

CNA Games
Show More
Show Less
Source: CNA/rk(aj)
Advertisement

Also worth reading

Advertisement