Article is online

Singapore: $11.8M Lost to Fake LinkedIn Crypto Job Scams

Singapore: $11.8M Lost to Fake LinkedIn Crypto Job Scams

Preface


Overview: Singapore's law enforcement and cyber agency have reported combined losses of $11.8 million arising from a sophisticated scam that used fraudulent LinkedIn recruitment approaches and compromised corporate devices. This article explains the scam's mechanics, summarizes documented campaigns that use similar tactics, and offers practical guidance for individuals and organizations. The goal is to clarify how a routine job-seeking interaction can become a vector for supply-chain and credential attacks, and to emphasize simple defensive measures that reduce risk.



Lazy bag


Key takeaway: criminals posed as crypto recruiters on LinkedIn, moved conversations to email using spoofed domains, and pushed targets to complete coding tests on compromised sites. Malware captured session tokens to bypass multi-factor authentication, enabling attackers to access code repositories and internal systems. Verify recruiters, avoid running untrusted code, and secure internal credentials to reduce exposure.



Main Body


The Singapore Police Force and the Cyber Security Agency of Singapore jointly reported losses of approximately $11.8 million in incidents where attackers used fake recruitment workflows to breach companies. The attacks began with a seemingly ordinary outreach on LinkedIn: a message from someone claiming to be a recruiter for a cryptocurrency firm. What followed was a sequence of trust-building steps designed to get the target to run code on a corporate device.



After initial contact on LinkedIn, the conversation was continued over email using a domain that closely mimicked a legitimate company. This email transition reduces platform-based protections and can make spoofing easier to accept. The candidate then participated in multiple interviews, conducted over Google Meet, during which interviewers frequently kept their cameras off — a detail that the agencies highlight as a potential red flag.



As part of the recruitment process, the victim was instructed to complete a technical coding assessment. The assessment was hosted on a spoofed website that delivered malicious software when the candidate attempted the test. Because the victim used a company-issued laptop, the malware obtained access to corporate resources.



A critical step in the compromise was the harvesting of a session token — the authentication string that services issue to maintain an active user session. Because a valid token represents an already authenticated state, it can be presented to services to bypass multi-factor authentication (MFA). Using a stolen session token, attackers gained entry to the victim's Bitbucket account, where the employer's source code was stored and managed.



Once inside, the attackers modified software systems, moved laterally to internal servers, and collected additional credentials. These credentials were then used to evade transaction limits and approval workflows, allowing funds to be transferred. The advisory did not name affected firms, disclose where stolen funds ultimately landed, or attribute the attacks to a specific actor.



Security researchers have documented similar operations. One long-running campaign, referred to as the "Contagious Interview," lures Web3 developers to interact with malicious code; investigators found hundreds of tainted packages in public registries tied to these efforts. Other groups have aimed at corporate cloud environments rather than individual wallets, reasoning that corporate systems and cloud credentials offer larger payouts. High-profile impersonations of employees or recruiters from well-known crypto platforms have been used to trick targets into executing commands or installing malware.



Attribution for some of these campaigns has pointed to state-aligned or organized criminal groups, but the underlying playbook — social engineering via recruitment, followed by code execution and token theft — is simple enough that many different actors can and have adopted it. Variations include building entire fake Web3 companies with job listings and realistic web presences to create believable bait for prospective applicants.



In response, Singapore's agencies issued practical recommendations. For individuals: verify recruiter identities through official company channels, be wary of interviewers who refuse to turn on video, and never run code or installers from unverified sources. For companies: secure API keys and internal credentials, strengthen MFA configuration (for example, using hardware-based or FIDO2 solutions where feasible), monitor for unfamiliar devices and anomalous network activity, and limit administrative access based on least privilege principles.



If a compromise is suspected, immediate containment steps include isolating affected systems, revoking active sessions and tokens, resetting exposed credentials, and reviewing access logs to identify lateral movement. Prompt coordination with incident response professionals and law enforcement can help preserve evidence and limit further losses.



These incidents underline how recruitment — a routine business process — can be repurposed as an attack vector. Defense requires both individual caution during job searches and robust enterprise controls that assume endpoints and people can be targeted. Regular security awareness training, strict policy enforcement around code execution, and monitoring of developer environments reduce the chances that a single compromised device becomes a pathway to substantial financial loss.



Key Insights Table



































Aspect Description
Modus Operandi Attackers pose as crypto recruiters on LinkedIn, move communication to spoofed email domains, and host malicious coding assessments.
Primary Technical Failure Malware harvested session tokens from a company device, enabling bypass of multi-factor authentication and access to code repositories.
Impact Attackers altered internal software systems, harvested credentials, and moved funds, contributing to reported losses of $11.8M.
Known Campaigns Similar campaigns include the "Contagious Interview" and fabricated Web3 firms used to distribute malicious packages and wallet-draining malware.
Individual Defenses Verify recruiters via official channels, require video during interviews, and never run unverified code on work devices.
Organizational Defenses Protect API keys and credentials, strengthen MFA, monitor unusual device activity, enforce least privilege, and isolate suspected compromises.

Last edited at:2026/8/14

Mr. W

ZNews full-time writer