PANews reported on April 14 that according to BeInCrypto, cybercriminals are using a new type of phishing SMS scam to target Binance users. Dozens of Binance users reported that they received a batch of seemingly regular phishing SMS messages, using the same phone numbers and SMS inboxes as the channels for receiving official Binance information. After comparison, the wording and format of these phishing SMS messages are highly similar. Based on this, it is speculated that a specific threat actor or criminal gang is planning a well-designed phishing attack against Binance users. In such targeted phishing attacks, SMS messages often warn users of unusual activity in their accounts, such as two-factor authentication of newly added devices. The most common phishing SMS messages mention the accidental association of the Binance API with Ledger Live, and urge the recipient to call the phone number provided in the SMS. Some users said that these phishing SMS messages appeared in the same SMS thread as legitimate Binance notifications, which was confusing and easy to fall into the trap. Many users were unprepared because the sender ID of the fraudulent SMS was the same as the real Binance notification ID.
Jimmy Su, Binance's chief security officer, confirmed that Binance has noticed an increase in SMS phishing incidents. He said: "More and more phishing scammers are impersonating us or other legitimate senders through SMS. These fraudulent messages look real and trick users into revealing sensitive information, clicking on phishing links or transferring money, resulting in user asset losses." Su also revealed that Binance has extended the anti-phishing code function to SMS services, which was originally designed for email. This code is a user-defined identifier that will appear in Binance's official information to help recipients identify real notifications and avoid being deceived by imposters. Currently, the anti-phishing code function has been launched in all licensed jurisdictions where Binance operates. In addition, according to Binance, both registered and unregistered users have reported receiving suspicious SMS messages.