Fake Disney and Coca-Cola job ads linked to 800 scam domains
Fake Disney and Coca-Cola job ads linked to 800 scam domains

Cybersecurity experts at NordVPN have identified 813 phishing domains connected to a scheme mimicking recruiters from more than 75 prominent corporations, including Disney, Nike, Coca-Cola, Nvidia, Adidas, Adobe and Booking.com. The campaign uses fraudulent job interview invitations to harvest passwords and workplace credentials.

How the scam works

The deception typically commences with an email, LinkedIn message or Facebook contact from an individual masquerading as a recruiter. In certain instances, criminals have seemingly replicated the name and profile picture of an authentic employee from LinkedIn.

Prospective candidates are subsequently redirected to a branded webpage resembling Calendly to schedule an interview before being prompted to authenticate using Google or Facebook. NordVPN reports the simulated login window, including its address bar and security padlock, can be convincingly falsified.

Targeted sector and expert warnings

Passwords and verification codes submitted by the target can then be captured in real time, potentially compromising workplace email, advertising accounts and corporate social media profiles. The campaign seems to have specifically focused on individuals employed in marketing and communications roles, where a hijacked account could provide fraudsters with entry to important corporate systems and advertising funds.

Adrianus Warmenhoven, cybersecurity adviser at NordVPN, explained that job interviews offered scammers an exceptionally persuasive cover story because candidates anticipate communicating with unfamiliar individuals, following directions and sharing personal details. He said: "A branded page can closely resemble a genuine Calendly invitation before presenting what appears to be a Google or Facebook login window. In reality, that window is built into the scam page, meaning even the address bar and security padlock can be faked."

Daniel Mohacek, CEO of Truth Engine, explained the fraud operated by exploiting the trustworthiness of brands and actual individuals that candidates already know. A corporate logo, authentic staff photograph or seemingly legitimate LinkedIn profile can reduce a job hunter's vigilance before they have verified who is truly behind the contact. Mohacek said: "Something looking credible is not proof that it is genuine. Fraudulent recruiters operating on LinkedIn may even have fake endorsements to add a layer of credibility."

Advice for job hunters

He encouraged job hunters to verify unexpected approaches independently, including establishing that the position features on the organisation's official website and utilising contact information obtained themselves rather than those provided by the purported recruiter.

Kate Underwood, founder and chief people strategist at Southampton-based Kate Underwood HR and Training, explained that recruitment scams were growing ever more elaborate and targeted individuals exhausted by their employment search. The use of real recruiters' names and photographs, convincing company branding and realistic login pages makes that initial approach particularly difficult to question, she explained. She continued: "This isn't phishing for your CV. It's phishing for your whole digital life."

Francis West, CEO at Security Everywhere, revealed he encountered variants of recruitment scams monthly, featuring recruitment firms alongside well-known employers. He continued: "These scams are very common, I see variations every month, not just with big brands but recruitment agencies too. They work because job hunting puts people in exactly the mental state scammers want: hopeful, anxious, and moving fast so they do not miss out. Nobody double-checks a login page when they think Disney just offered them an interview."

Career coach Amelia Brooke, of Amelia Brooke Career Vision, revealed she had flagged a suspected recruitment scam on LinkedIn only the previous week. She continued: "It's extremely common. Just last week, I reported one to LinkedIn. Scammers exploit the excitement of an interview from a major global brand. The most common technique I have spotted is typo-squatting, where scammers deliberately alter company names by a letter or two – like Deloitte, PwC-Global-Careers, or KPMG-Jobs to catch the attention of candidates who might not realise the domain or name is slightly off."

Harvey Dhillon, founder and CEO at Zmartly, warned that a hijacked work login from someone in marketing or communications could similarly compromise company advertising accounts holding saved payment information. He continued: "Job scams work because the login matters, not the person. Reporting on the campaign says those approached work in marketing and comms, whose login often opens an ads account with a payment method on it."

Kelly Smallcombe, fractional chief people officer at Meliorem HR Consultancy, advised candidates should verify whether an approach aligns with the employer's standard hiring procedures. She continued: "Recruitment scams like this are everywhere, and job seekers are an easy target. Desperation does the scammer's work for them, when someone's chasing a well-known employer, name recognition switches off their scepticism."