Fake Disney, Coca-Cola, Nike job adverts 'trying to steal your digital life'
Fake Disney, Coca-Cola, Nike job adverts 'trying to steal your digital life'

Cybersecurity researchers at NordVPN have linked 813 phishing domains to an operation impersonating recruiters from more than 75 major companies, including Disney, Nike, Coca-Cola, Nvidia, Adidas, Adobe and Booking.com. The scam can begin with an email, LinkedIn message or Facebook approach from someone posing as a recruiter. In some cases, criminals appear to have copied the name and photograph of a genuine employee from LinkedIn.

How the scam works

Job hunters are then directed to a branded page resembling Calendly to arrange an interview before being asked to sign in with Google or Facebook. NordVPN says the apparent login window, including its address bar and security padlock, can be faked. Passwords and verification codes entered by the victim can then be intercepted in real time, potentially opening up workplace email, advertising accounts and corporate social media profiles.

The campaign appears to have particularly targeted people working in marketing and communications, where a compromised account could give criminals access to valuable company systems and advertising budgets.

Experts warn of convincing pretext

Adrianus Warmenhoven, cybersecurity adviser at NordVPN, said job interviews provided scammers with an unusually convincing pretext because applicants expect to communicate with strangers, follow instructions and provide information about themselves. He said: “A branded page can closely resemble a genuine Calendly invitation before presenting what appears to be a Google or Facebook login window. In reality, that window is built into the scam page, meaning even the address bar and security padlock can be faked.”

Daniel Mohacek, CEO of Truth Engine, said the fraud worked by borrowing the credibility of brands and real people that applicants already recognise. A company logo, genuine employee photograph or apparently credible LinkedIn profile can lower a jobseeker’s guard before they have checked who is actually behind the approach. Mohacek said: “Something looking credible is not proof that it is genuine. Fraudulent recruiters operating on LinkedIn may even have fake endorsements to add a layer of credibility.”

Impact on jobseekers and employers

Kate Underwood, founder and chief people strategist at Southampton-based Kate Underwood HR and Training, said recruitment scams were becoming increasingly sophisticated and preyed on people worn down by the job hunt. She added: “This isn't phishing for your CV. It's phishing for your whole digital life.”

Francis West, CEO at Security Everywhere, said he saw variations of recruitment scams every month, involving recruitment agencies as well as household-name employers. He added: "These scams are very common, I see variations every month, not just with big brands but recruitment agencies too. They work because job hunting puts people in exactly the mental state scammers want: hopeful, anxious, and moving fast so they do not miss out. Nobody double-checks a login page when they think Disney just offered them an interview."

Advice for jobseekers

Career coach Amelia Brooke, of Amelia Brooke Career Vision, said she had reported a suspected recruitment scam on LinkedIn just last week. She added: "It's extremely common. Just last week, I reported one to LinkedIn. Scammers exploit the excitement of an interview from a major global brand. The most common technique I have spotted is typo-squatting, where scammers deliberately alter company names by a letter or two – like Deloitte, PwC-Global-Careers, or KPMG-Jobs to catch the attention of candidates who might not realise the domain or name is slightly off."

Harvey Dhillon, founder and CEO at Zmartly, said a compromised work login belonging to somebody in marketing or communications could also expose company advertising accounts containing stored payment details. He added: "Job scams work because the login matters, not the person. Reporting on the campaign says those approached work in marketing and comms, whose login often opens an ads account with a payment method on it."

Kelly Smallcombe, fractional chief people officer at Meliorem HR Consultancy, said applicants should check whether an approach makes sense when compared with the employer’s usual recruitment process. She added: "Large companies list their applicant tracking system on their careers page, so a booking link that doesn't match is a red flag straight away. Genuine recruiters aren't sourcing candidates through Facebook, they're on LinkedIn or major job boards, and that's also where they'll have found your details."