The Jerusalem PostRapper ‘The Shadow’ removed as police volunteer amid investigationPunchNDLEA arrests businessman with N23m cocaine at Lagos airportESPN DeportesSantos y Chivas quieren despertar en Liga MXCNN Türk17 AĞUSTOS AKARYAKIT FİYATLARI: Benzin, motorin, LPG, akaryakıt fiyatları ne kadar? İstanbul, Ankara, İzmir akaryakıt fiyatlarında son durum...ESPNPitcher, surgery pioneer Tommy John dies at 83וואלהטראמפ הורה לצמצם את התמרון הצבאי עם דרום קוריאה - בהתבסס על יחסיו הטובים עם קוריאה הצפונית한겨레2층까지 솟은 흙탕물, 차량 둥둥…거제 주민들 “이런 비 처음 봐”UOLEmpresário e advogado são as profissões mais comuns entre os candidatosNew Straits TimesSouth Korea landslide kills one as heavy rains sweep southern areasHong Kong Free PressHow an escalating crackdown on Hong Kong’s independent bookstores put Taiwan publishers in the spotlightSBS 뉴스이 대통령 지지도 43.0%로 취임 후 최저…5주 연속 하락 [리얼미터]NTV17 Ağustos depreminin 27. yılı: Saat 03.02’de hayat durdu
The Daily Newsstand · Free, Always
Monday, August 17, 2026

Authorities warn against cryptocurrency-related scams involving fake job offers after US$11.8 million in losses

Translate

SINGAPORE: A cryptocurrency-related scam involving fake job offers and compromised software systems has resulted in losses of US$11.8 million, the Singapore Police Force (SPF) and Cyber Security Agency of Singapore (CSA) said on Friday (Aug 14).

In one case, a victim was approached on LinkedIn by a scammer impersonating a recruiter from a cryptocurrency-related company. 

The scammer communicated with the victim through email, using a spoofed domain closely resembling the legitimate company’s domain.

The victim also attended several video interviews on Google Meet, although the interviewer’s video remained switched off throughout.

Subsequently, the victim was directed to a spoofed website to complete a technical coding assessment on his company-issued device, during which he unknowingly downloaded malicious software.

The malware harvested the victim’s session token, which was then used to bypass multi-factor authentication to gain access to the victim’s Bitbucket account, which was linked to his company’s code repository. 

Bitbucket is a code repository hosting service that developers can use to collaborate on code.

After gaining access, the attackers modified the company’s automated software deployment instructions and remotely accessed the company’s internal servers, said SPF and CSA. They also harvested credentials that allowed them to bypass transaction limits and approval checks to carry out cryptocurrency transfers.

SPF and CSA advised businesses and individuals, particularly those in the technology and cryptocurrency sectors, to adopt precautionary measures.

Some measures include verifying recruiter and company identities, protecting application programming interface (API) keys and internal credentials, strengthening multi-factor authentication and securing code repositories and deployment pipelines.

Should there be a suspected compromise, affected devices or systems should be isolated immediately, active sessions revoked, credentials reset, and access logs reviewed.

Individuals and businesses should notify their internal cybersecurity teams or service providers without delay, and assess whether accounts, repositories, internal servers or approval workflows have been altered.

View the original on Channel News Asia

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.