← Back to KHAO

Singapore · Google ·

Singapore agencies’ advice to individuals is to verify recruiters through official channels

2 min read

Compiled by KHAO Editorial — aggregated from 1 source. See llms.txt for citation guidance.

★ Tier-1 Source

For companies, the agencies recommend securing API keys and internal credentials, strengthening multi-factor authentication and watching for unfamiliar devices and unusual network activity.

Key facts

Summary

Singapore's police force and cyber security agency put losses from a scam using fake job offers and compromised software systems at $11.8 million. They describe a case in which a victim was approached by a bogus recruiter for a crypto firm and steered into a coding assessment run on a company laptop. The malware harvested a session token, which was used to bypass multi-factor authentication and open the victim's Bitbucket account. Scammers posing as recruiters for cryptocurrency companies have taken $11.8 million (S$15.1 million), using fake job offers to compromise their targets' employers, according to a joint advisory from the Singapore Police Force and the Cyber Security Agency of Singapore. Setting out how the scam works reported by The Straits Times and Channel NewsAsia, the agencies said a victim was approached on LinkedIn by someone posing as a recruiter for a crypto company, then moved to email, where the sender used a spoofed domain closely resembling a real firm's.

Read full article at Decrypt →

#Singapore #Google