Award Banner
Award Banner

Over $15m lost to crypto scam involving fake job offers, compromised software systems: CSA, police

Over $15m lost to crypto scam involving fake job offers, compromised software systems: CSA, police
In this scam variant, the agencies said the victim was first approached on LinkedIn by a scammer posing as a recruiter.
PHOTO: AsiaOne file

The Singapore Police Force (SPF) and Cyber Security Agency of Singapore (CSA) have warned of a cryptocurrency-related scam involving fake job offers and compromised software systems, which has resulted in losses of about US$11.8 million (S$15.1 million).

In a joint statement on Friday (Aug 14), the agencies said that in this variant, the victim was first approached on LinkedIn by a scammer posing as a recruiter from a cryptocurrency-related company.

The scammer subsequently communicated with the victim via email using a spoofed domain that closely resembled that of a legitimate company.

The victim then attended several video interviews on Google Meet, during which the interviewer's video remained disabled throughout.

The victim was later directed to a spoofed website to complete a technical coding assessment on a company-issued device, during which they were induced to download malicious software without realising it.

The malware then obtained the victim's session token, which was used to bypass multi-factor authentication and gain access to the victim's Bitbucket account, a platform used to store and manage software code.

The scammer then used the account to alter the victim's company's software systems and access its internal servers, said the agencies, gaining access to credentials, which were allegedly used to bypass transaction limits and approval checks to carry out cryptocurrency transfers.

Prevention and mitigation measures

SPF and CSA warned that these scammers may impersonate recruiters, employers or business partners to gain trust and induce victims to disclose information, download files or execute code.

Individuals are advised to verify recruiters and companies through official channels before responding to job offers or attending interviews, and to be wary of interviewers who refuse to enable their video or ask them to communicate through unofficial platforms or unfamiliar websites.

Files from unknown or unverified sources should not be downloaded, nor should code from such sources be executed

Businesses should also secure application programming interface keys and internal credentials, strengthen multi-factor authentication, and monitor for suspicious logins, unfamiliar devices and unusual network activity.

If a compromise is suspected, affected devices or systems should be isolated, active sessions revoked, credentials reset and access logs reviewed. 

Cybersecurity teams or service providers should also be notified, and accounts checked for unauthorised changes.

For more information on scams, members of the public can visit www.scamshield.gov.sg or call the ScamShield Helpline at 1799.

[[nid:742601]]

xingying.koh@asiaone.com

This website is best viewed using the latest versions of web browsers.