Authorities warn against cryptocurrency-related scams involving fake job offers after US$11.8 million in losses
In such cases, scammers pose as recruiters and trick victims into downloading malware through fake technical assessments, allowing them to compromise company systems and steal cryptocurrency.
Representations of cryptocurrencies are seen in this illustration on Aug 10, 2022.(File photo: Reuters/Dado Ruvic)
New: You can now listen to articles.
This audio is generated by an AI tool.
Read a summary of this article on FAST.
Get bite-sized news via a new
cards interface. Give it a try.
Click here to return to FAST
Tap here to return to FAST
FAST
SINGAPORE: A cryptocurrency-related scam involving fake job offers and compromised software systems has resulted in losses of US$11.8 million, the Singapore Police Force (SPF) and Cyber Security Agency of Singapore (CSA) said on Friday (Aug 14).
In one case, a victim was approached on LinkedIn by a scammer impersonating a recruiter from a cryptocurrency-related company.
The scammer communicated with the victim through email, using a spoofed domain closely resembling the legitimate company’s domain.
The victim also attended several video interviews on Google Meet, although the interviewer’s video remained switched off throughout.
Subsequently, the victim was directed to a spoofed website to complete a technical coding assessment on his company-issued device, during which he unknowingly downloaded malicious software.
The malware harvested the victim’s session token, which was then used to bypass multi-factor authentication to gain access to the victim’s Bitbucket account, which was linked to his company’s code repository.
Bitbucket is a code repository hosting service that developers can use to collaborate on code.
After gaining access, the attackers modified the company’s automated software deployment instructions and remotely accessed the company’s internal servers, said SPF and CSA. They also harvested credentials that allowed them to bypass transaction limits and approval checks to carry out cryptocurrency transfers.
SPF and CSA advised businesses and individuals, particularly those in the technology and cryptocurrency sectors, to adopt precautionary measures.
Some measures include verifying recruiter and company identities, protecting application programming interface (API) keys and internal credentials, strengthening multi-factor authentication and securing code repositories and deployment pipelines.
Should there be a suspected compromise, affected devices or systems should be isolated immediately, active sessions revoked, credentials reset, and access logs reviewed.
Individuals and businesses should notify their internal cybersecurity teams or service providers without delay, and assess whether accounts, repositories, internal servers or approval workflows have been altered.
![]()
Guess Word
Crack the word, one row at a time
![]()
Buzzword
Create words using the given letters
![]()
Mini Sudoku
Tiny puzzle, mighty brain teaser
![]()
Mini Crossword
Small grid, big challenge
![]()
Word Search
Spot as many words as you can
Source: CNA/rk(aj)
Sign up for our newsletters

Get the CNA app
Stay updated with notifications for breaking news and our best stories
Get WhatsApp alerts
Join our channel for the top reads for the day on your preferred chat app

Get bite-sized news via a new
cards interface. Give it a try.
Click here to return to FAST
Tap here to return to FAST
FAST
















