S.M.M.

Stop Manipulating Me · A Field Guide to Psychological Influence

ENTRY No. T14.13
CATEGORY Social Engineering
CLEARANCE Public / Essential
EDITION 01
Dossier · Manipulation Tactic

Fake Recruiters

Social Vector · Employment Fraud · High & Rising
Red Flag
How It WorksSEC 01

Fake recruiting is a fraud in which an attacker poses as a recruiter, hiring manager, or employer to extract money, personal or financial data, or unpaid labor from job seekers under the pretense of a real opening. It weaponizes hope, economic pressure, and the deference people naturally extend to a hiring authority: a job offer is emotionally loaded, applicants want it to be real, and handing over an SSN, ID scan, or bank details feels like normal onboarding.

Several patterns recur. Advance-fee scams demand upfront payment for “training,” “equipment,” or “background checks.” Data-harvest scams run a plausible interview to collect enough to commit identity theft, framed as “setting up your payroll.” Overpayment and mule scams send a check, ask you to forward part of it, and leave you liable when it reverses. Task or “gamified” scams — a fast-rising variant — lure victims into an app of trivial “tasks” showing fake earnings, then demand a personal deposit, often crypto, to “unlock” withdrawals that never come.

The unifying logic: a legitimate recruiter never asks the candidate for money and never rushes you off official channels. Real hiring is verifiable, slow, and moves toward the company; fraudulent hiring is urgent, secretive, moves away from verifiable channels, and — the defining tell — flows money or data from the applicant.

Warning SignsSEC 02
  • Any request for upfront payment. Fees for training, equipment, certifications, or "processing" — legitimate employers never charge candidates.
  • Early demand for sensitive data. SSN, bank login, or ID scans requested before a verified written offer.
  • Unsolicited contact. A role you never applied to, especially arriving by text or encrypted chat.
  • Pressure to move off-platform. Nudges into personal email or a messaging app, away from verifiable channels.
  • Deposit-to-earn or overpayment structure. A "job" that is really an app requiring your own deposit, or a check to partially return.
  • Unverifiable employer. Free-email addresses, urgency ("start today"), and a company or recruiter you cannot independently confirm.
Frequently Paired WithSEC 03
  • Advance-Fee Fraud · T24.8
    Shares the advance-fee and mule mechanics
  • Brand Impersonation · T14.3
    Borrows a real firm's credibility
  • Pretexting · T14.11
    The recruiter persona is the pretext
  • Trust Exploitation · T14.21
    Rides a trusted brand's reputation
How the Attack UnfoldsSEC 04
  • Stage 01 · Lure
    An unsolicited "recruiter" reaches out — via a job board, DM, or text — with a role that is easy to get and better than it should be.
  • Stage 02 · Investment
    A warm interview and "onboarding" build rapport and sunk cost; a small first request (an ID scan) primes a larger one.
  • Stage 03 · Extraction
    The ask lands: pay a fee, pre-share bank details, forward an overpayment, or deposit money to "unlock earnings" that never arrive.
Counter-ProtocolSEC 05
Defense: A real employer never wants your money or bank login — verify independently.
  • Verify the company and recruiter out-of-band. Reach the employer through its official careers page and known contacts, never a number or link the "recruiter" supplied.
  • Never pay for a job. No legitimate employer charges for training, equipment, or background checks.
  • Never pre-share financial data. Withhold SSN and bank details until a verified written offer is in hand.
  • Keep it on official platforms. Treat pressure to move to personal chat as a red flag; never deposit-and-forward money.
  • Get a second opinion and report. Ask someone not invested; report to the platform, FTC, and IC3.