Newsroom
15 August, 2026 / News / AI / Tags: interviews, recruiters, code, interviewer, credentials

Police and cybersecurity officials detail a scheme using LinkedIn recruiters, disabled-video interviews and malware on company devices to breach systems and move digital assets
Singapore’s police force and Cyber Security Agency have reported losses of about US$11.8 million, equivalent to S$15.1 million, tied to a cryptocurrency scam that begins with fake job offers and ends with compromised corporate software systems.
In a joint advisory issued on August 14, the agencies described a method in which scammers first contact targets on LinkedIn while posing as recruiters from cryptocurrency-related firms. Communication then shifts to email accounts that use domains closely matching those of legitimate companies.
Victims are invited to multiple video interviews conducted on Google Meet. Throughout these sessions the interviewer’s camera remains switched off. After the interviews, targets are directed to a lookalike website and asked to complete a technical coding assessment on a company-issued device.
During that assessment, malicious software is downloaded without the victim’s knowledge. The malware captures a session token that allows attackers to bypass multi-factor authentication and gain entry to the victim’s Bitbucket account, a platform used to store and manage source code.
With access to the code repository linked to the employer’s systems, the attackers alter software configurations and reach internal servers. Credentials obtained at this stage are then used to circumvent transaction limits and approval checks, enabling unauthorized cryptocurrency transfers.
The Singapore Police Force and Cyber Security Agency cautioned that scammers may impersonate recruiters, employers or business partners to build trust and persuade targets to share information, download files or run code.
Individuals are urged to confirm the identity of any recruiter or company through official channels before engaging with job offers or interviews. Caution is advised when an interviewer keeps their video disabled or when communication moves to unofficial platforms or unfamiliar websites. Files or code from unknown sources should not be downloaded or executed.
Businesses are advised to protect application programming interface keys and internal credentials, reinforce multi-factor authentication, and watch for unusual logins, unfamiliar devices or abnormal network activity. Code repositories and deployment pipelines should receive additional security attention.
If a compromise is suspected, affected devices or systems should be isolated immediately. Active sessions must be revoked, credentials reset and access logs reviewed. Cybersecurity teams or external service providers should be notified, and accounts examined for unauthorized changes.
Members of the public seeking further information on scams can consult the national ScamShield resources or contact the dedicated helpline.









