Singapore police and cyber security agencies say a scam built around fraudulent job offers and compromised company systems has led to losses of $11.8 million, or S$15.1 million. The warning outlines how attackers used fake recruiter profiles and spoofed company domains to trick targets, including people working in crypto and technology roles.

In the case described by authorities, the scheme began with a LinkedIn approach from someone posing as a recruiter for a crypto company. What followed was a chain of interviews, a bogus technical test, malware on a company device, and then unauthorized access that let attackers interfere with internal systems and move funds.

How the job approach turned into a breach

According to the advisory, the victim was first contacted on LinkedIn and later directed to continue the discussion by email. The email address used a spoofed domain designed to resemble a legitimate company, adding credibility to the fake hiring process.

The victim then went through several interviews on Google Meet. Authorities said the interviewer kept their camera off throughout, which they highlighted as a warning sign. Eventually, the applicant was sent to a spoofed website to complete a technical coding assessment.

That assessment was carried out on a company-issued device. In doing so, the victim unknowingly downloaded malicious software, giving the attackers a foothold inside the employer’s environment.

What the malware allowed attackers to do

Singapore’s agencies said the malware harvested a session token. That enabled the attackers to bypass multi-factor authentication and gain access to the victim’s Bitbucket repository, where the employer’s source code was stored and managed.

From that access point, the attackers altered the company’s software systems and reached internal servers. Authorities said they then collected credentials that were used to get around transaction limits and approval checks, which allowed funds to be moved.

The advisory does not identify the affected company, say where the money was sent, or attribute the activity to any specific hacking group. The official warning therefore describes the method and the impact, while leaving several operational details undisclosed.

A familiar playbook in crypto and Web3 hiring scams

The tactics described by Singapore line up with a pattern that has already been documented by security researchers. One long-running operation, known as Contagious Interview, has been reported to use fake recruiters to lure Web3 developers into running malicious code during supposed hiring exercises.

Researchers have also described booby-trapped npm packages being used in similar campaigns. The broader trend is that fake job offers are not only being used to target personal wallets or individual assets, but in some cases to reach company infrastructure and cloud systems.

That makes recruitment workflows an attack surface in their own right, especially when developers or technical staff are asked to execute code or install tools as part of an interview process.

Advice from Singapore authorities and the next step after a suspected breach

Authorities urged individuals to verify recruiters through official channels before engaging further. They also said that an interviewer’s refusal to switch on a camera should be treated as a possible red flag, and warned against running code from unverified sources.

For companies, the guidance includes protecting API keys and internal credentials, reinforcing multi-factor authentication, and watching for unfamiliar devices or unusual network activity. These measures are aimed at limiting the damage if an attacker succeeds in reaching a staff member through a fake hiring process.

If a compromise is suspected, the recommended next steps are to isolate affected systems, revoke active sessions, reset credentials, and review access logs. The advisory frames those actions as immediate containment measures following the type of intrusion described in the case.

Source: decrypt.co