Crypto Job Scams on LinkedIn Cost $11.8M in Singapore
Crypto Job Scams on LinkedIn Cost $11.8M in Singapore
Singaporean authorities have reported that fake cryptocurrency-related job scams on LinkedIn have led to an estimated $11.8 million in losses. These sophisticated scams involve planting malware during bogus coding assessments, which then harvests session tokens to bypass multi-factor authentication and gain unauthorized access to victims' systems.
Sophisticated Crypto Job Scams Exploit LinkedIn Users
In a significant cybersecurity alert, Singapore has revealed that job scams targeting the cryptocurrency sector on LinkedIn have resulted in financial losses totaling $11.8 million. The fraudulent scheme operates by enticing victims with seemingly legitimate crypto job offers, which then lead to a deceptive 'coding assessment'. During this assessment, malware is discreetly installed onto the victim's device.
This malicious software is designed to harvest session tokens, effectively bypassing traditional multi-factor authentication (MFA) protocols. Once a session token is acquired, attackers can gain unauthorized access to various online accounts and sensitive data, including code repositories, without needing login credentials directly. The incident highlights the evolving tactics of scammers who leverage reputable platforms like LinkedIn to execute advanced social engineering attacks combined with technical exploits, posing a severe threat to individuals seeking employment in the crypto and tech industries.