Numerous Binance users have reported a surge in receiving alarming phishing text messages that seem authentic, matching the phone numbers and message format of official Binance notifications. These texts use similar wording, indicating a targeted phishing campaign by a specific threat actor or group aiming at Binance users.
The messages often alert users about unauthorized account activities, like adding a new two-factor authentication device. In many cases, the texts mention an unexpected Binance API connection with Ledger Live, prompting recipients to call a specified number. Some users claim these messages appear alongside legitimate Binance notifications, causing confusion and leading them to interact.
There has been a notable increase in consumer complaints relating to this issue. Users have expressed surprise as the scam messages came from the same sender ID normally used by Binance for valid notifications. It appears that the scammers are utilizing leaked user data from dark web forums to create targeted messages that appear legitimate, exploiting names, phone numbers, and emails obtained from these breaches.
The phishing attempts often involve a sense of urgency, prompting users to call a provided phone line rather than click on a link, unique to traditional phishing tactics. Binance has acknowledged these smishing scams and has extended its Anti-Phishing Code to SMS to combat these fraudulent activities.
Binance's Chief Security Officer, Jimmy Su, confirmed the company's efforts to address the rising smishing incidents, emphasizing the importance of user awareness and caution when handling suspicious messages. The Anti-Phishing Code, now incorporated into SMS messages, serves as a unique identifier to help users distinguish between genuine communications from Binance and fraudulent attempts.
All users, whether registered with Binance or not, are advised to remain vigilant and report any suspicious texts. It is recommended that users take additional precautions, like verifying transactions through official Binance channels, implementing multifactor authentication, and refraining from sharing personal information over the phone. Staying cautious and reporting any such incidents to Binance's support team is crucial to combat these phishing attempts effectively.