Fake recruitment approaches are becoming harder to spot, with criminals now guiding jobseekers through convincing interview processes before asking them to download malicious software. For small employers, the warning is not only about protecting candidates: fraudsters can impersonate a business, misuse its vacancies and target staff who are involved in hiring.
What has happened?
The BBC has reported on a jobseeker who lost £18,000 after a fake recruiter approached him through LinkedIn. The process included a video call and what appeared to be a normal technical assessment on a Google document. The document contained malicious software, which the victim downloaded before discovering that his online wallets had been emptied.
The report says criminals are also promoting bogus interview applications with names designed to resemble familiar recruitment services. Indeed told the BBC that interviews conducted through its platform take place in a browser and do not require a special app. Any message claiming that a candidate must install an app to participate should therefore be treated as suspicious.
LinkedIn research cited by the BBC found that younger professionals face particularly high exposure to scams. A competitive jobs market can make candidates more willing to respond quickly, which gives criminals an opportunity to manufacture urgency and discourage proper checks.
Why this matters to small employers
A small company may assume this is only a problem for jobseekers, but its name, logo, employee profiles and genuine vacancy descriptions can all be copied to make a false approach look credible. Candidates who are deceived may associate the bad experience with the real business, creating reputational damage even when the employer had no involvement.
Recruitment teams can also be targets. A supposed applicant may send a portfolio, coding exercise or document that contains malware. In a smaller firm, hiring is often handled by a manager using the same computer for payroll, banking, customer records and email. One unsafe download can therefore expose far more than a recruitment inbox.
The National Cyber Security Centre says phishing commonly aims to make people visit a site that steals information or downloads a virus. Its guidance recommends slowing down when a message creates urgency, checking communications through a trusted route and reporting suspicious approaches.
Five checks SMEs can put in place now
- Publish a clear recruitment process. State on your careers page which domains, phone numbers and platforms your company uses. Tell applicants whether interviews require downloads. A short warning that you will never ask for payment, cryptocurrency or banking credentials gives candidates something authoritative to check.
- Use company-controlled accounts. Recruiters and hiring managers should contact candidates from a business email address, not a personal account. If an agency is working for you, name it in the vacancy or give candidates a way to confirm the relationship.
- Limit downloaded files. Ask staff to preview applications in a browser or approved document system where possible. Unexpected executable files, mobile apps, browser extensions and password-protected archives should not be opened on a normal work device without an IT or security check.
- Verify unusual requests separately. If a candidate, recruiter or agency asks someone to install software, transfer money or share sensitive information, confirm the request using a phone number or website already known to be genuine—not contact details supplied in the message.
- Plan the first response. Staff should know who to contact if they open a suspicious file. Disconnecting an affected device from the network, informing the responsible IT person promptly and changing exposed passwords from a clean device can reduce the damage. Businesses should follow their incident plan and seek expert help where needed.
What to tell candidates
Add a concise anti-fraud note to job advertisements and interview invitations. It should explain that the company will not charge an application fee, ask candidates to buy equipment through a named supplier, request cryptocurrency or require unapproved interview software. Provide a contact address on the company’s own domain for checking questionable approaches.
Employers should also search periodically for their company name alongside phrases such as “jobs” and “careers”. This will not find every impersonation, but it may reveal copied vacancies or false recruiter profiles early enough to report them to the relevant platform.
The practical takeaway
Convincing recruitment scams exploit normal business activity rather than obviously implausible promises. Small firms should treat their hiring identity as part of their cyber-security perimeter. A documented process, trusted communication channels and a firm rule against unexpected downloads can protect applicants, staff and the company’s reputation at the same time.
