The interview went through several rounds of Google Meet calls, and the other side's camera was never turned on. That's one of the few details that left a trace in a scam case disclosed last Friday by the Singapore Police Force and the Cyber Security Agency of Singapore — and at the time, the victim didn't think much of it.
The joint announcement from both agencies states that this scheme, which impersonates crypto companies during recruitment, has caused total losses of $11.8 million (roughly S$15.1 million). According to the case description, the victim was first approached on LinkedIn by someone posing as a headhunter for a crypto firm, and the conversation then moved to email using a domain deliberately designed to mimic the real company's. This was followed by several rounds of Google Meet interviews, during which the interviewer's camera stayed off the entire time. Finally, the victim was directed to a fake website to complete a technical coding test — using a company-issued laptop — and it was during this process that malware was quietly installed.
The truly fatal step was what the malware was designed to target: session tokens, the authentication strings that services use to keep users logged in. Armed with these tokens, attackers didn't need passwords or verification codes — they could impersonate a legitimate user who had "already logged in," bypassing multi-factor authentication entirely to gain access to the victim's Bitbucket account, where the company stored and managed its source code. From there, the attackers modified the employer's software systems, worked their way into internal servers, harvested credentials, and ultimately used them to get around transaction limits and review mechanisms to transfer the funds out. The announcement did not name the victim company, nor did it disclose where the funds went or attribute blame to any specific party. Decrypt has reached out to LinkedIn for comment and will update this story if they respond.






