By Jackson Godwin. Cybersecurity Analyst & Penetration Tester

Someone Pretended to Be Binance Support
Disclaimer: This story is fictional but inspired by real cryptocurrency scams reported by users worldwide. It is written to educate readers about fake customer support scams and how to protect their digital assets.
It Started With a Security Alert
It was late in the evening when I received an email that immediately caught my attention.
The subject line read:
“Urgent: Suspicious Login Attempt Detected on Your Binance Account.”
My heart skipped a beat.
Like many people who own cryptocurrency, I was aware that cybercriminals frequently target exchange accounts.
The email looked genuine.
It contained the Binance logo.
The colours matched the official website.
The language was professional.
There were no obvious spelling mistakes.
At first glance, it looked exactly like the kind of security alert you would expect from a major cryptocurrency exchange.
Then My Phone Rang
About fifteen minutes later, my phone started ringing.
The caller introduced himself politely.
“Good evening. My name is Daniel from the Binance Security Team.”
He sounded calm.
Professional.
Confident.
He explained that their security system had detected an unusual login attempt from another country.
Then he asked,
“Are you currently trying to access your Binance account?”
I immediately answered,
“No.”
He paused.
Then replied,
“That’s exactly why we’re calling.”
Everything Sounded Legitimate
The caller never rushed me.
He didn’t threaten me.
Instead, he explained how criminals sometimes steal cryptocurrency by gaining access to exchange accounts.
Ironically…
Everything he said about cybercriminals was true.
That made him sound even more believable.
He even advised me to enable security features like Two-Factor Authentication.
At that moment, I thought I was speaking with a genuine Binance employee.
He Already Knew My Email Address
Then something happened that increased my confidence.
He mentioned the email address linked to my Binance account.
It was correct.
He also knew my first name.
Immediately, I assumed he must have access to Binance’s customer records.
Looking back now, I realise that assumption was dangerous.
Personal information can sometimes be gathered from previous data breaches, phishing attacks, or information people have shared publicly online.
Just because someone knows your email address doesn’t mean they work for the company they claim to represent.
The Conversation Felt Natural
For almost twenty minutes, we discussed account security.
He answered my questions patiently.
He never asked for money.
He never mentioned cryptocurrency transfers.
Instead, he focused on protecting my account.
Everything about the conversation felt genuine.
If someone had listened to the call, they probably would have believed he was part of Binance’s security department.
That is exactly what made the scam so convincing.
Then He Asked Me to Verify My Identity
Toward the end of the conversation, he said,
“Before we secure your account, I need to verify that you are the legitimate owner.”
That sounded reasonable.
Banks verify customers.
Telecommunication companies verify customers.
Many businesses verify customer identities.
I expected him to ask for my name or email address.
Instead…
He asked for something much more sensitive.
My Instinct Told Me Something Was Wrong
The request wasn’t outrageous.
In fact, many people would probably have complied without hesitation.
But something about it made me pause.
I remembered reading a cybersecurity article that said:
“Scammers often spend time building trust before asking for sensitive information.”
That sentence suddenly came back to me.
Instead of answering immediately, I decided to slow the conversation down.
Sometimes, taking a few extra seconds to think is one of the best cybersecurity decisions you can make.
I Asked One Simple Question
Before giving him any information, I asked,
“Can I hang up and contact Binance through the official support page instead?”
There was complete silence.
Then his friendly tone changed.
He sounded slightly impatient.
“If you disconnect now, your account may remain at risk.”
That response immediately raised a red flag.
Legitimate companies generally encourage customers to use official support channels.
Someone who discourages independent verification may not be who they claim to be.
The Call Was About to Take a Dangerous Turn
At that moment, I realised I needed to be extremely careful.
The conversation that had sounded so professional only minutes earlier was beginning to reveal its true purpose.
The next question he asked confirmed every suspicion I had.
And it became one of the most valuable cybersecurity lessons I have ever learned.
(Continue in Part 2, where I’ll explain the psychological tricks fake support agents use, reveal the sensitive information the caller tried to obtain, and show how criminals impersonate trusted companies to steal cryptocurrency.)






