{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:21:00.869Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"title":"Fake recruiter's coding test cost payment processor CoinsPaid $37M","date":"2023-07-22","date_precision":"day","victim_org":"CoinsPaid","sector":"Cryptocurrency","country":"Estonia","primary_vector":"Fake Job Offer / Recruitment Lure","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI involvement was reported.","outcomes":["Cryptocurrency Theft"],"loss_usd":37000000,"loss_note":"CoinsPaid reported losses of over $37 million; company funds rather than customer funds bore the loss. Most of the proceeds were moved through SwftSwap.","records_affected":null,"threat_actor":"Lazarus Group (DPRK), suspected by CoinsPaid","summary":"Crypto payment processor CoinsPaid lost more than $37 million on July 22, 2023. The company said attackers had spent months trying to break in directly from March 2023 before switching to social engineering: posing as recruiters, they offered an employee a job with an unusually high salary and asked them to complete a technical assessment. The assessment installed malware. CoinsPaid attributed the attack to the Lazarus Group.","how_it_worked":"After direct infrastructure attacks failed, the operators changed target from the network to a person. Fake recruiters approached a CoinsPaid engineer over messaging and professional platforms with an offer well above market rate, then moved the conversation to an interview process. The 'technical task' the candidate was asked to run as part of that process was the payload. Running it on their working machine gave the attackers a foothold with the employee's credentials and access, from which they reached the infrastructure that authorised outbound transfers and drained more than $37 million. CoinsPaid noted the transaction patterns closely mirrored other Lazarus operations from the same period.","lessons":"Job-application code and take-home assessments must only ever run in a disposable, network-isolated VM, and recruiters approaching engineers with outsized offers should be treated as an active threat indicator, not an HR event.","confidence":"Reported","sources":[{"title":"CoinsPaid claims North Korean hacking group used fake job interview to steal $37M","url":"https://cointelegraph.com/news/coinspaid-claims-north-korean-hacking-group-fake-job-interview-theft","publisher":"Cointelegraph"},{"title":"The CoinsPaid Hack Explained","url":"https://coinspaid.com/company-updates/the-coinspaid-hack-explained/","publisher":"CoinsPaid"}],"entry_type":"incident","slug":"2023-fake-recruiter-s-coding-test-cost-payment-processor-coinspaid-37m","year":2023,"loss_kind":"direct_loss","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2023-fake-recruiter-s-coding-test-cost-payment-processor-coinspaid-37m"}]}