Jobseekers targeted in LinkedIn scam that cost one victim £18K
Updated: Sep 7
A job advert can look harmless. A recruiter message can feel like the break you have been waiting for. That is exactly what makes the latest jobseeker scam so dangerous.
Here at The Scam Hound, we reported the "Jobseeker Swindle" back in March, when many cases centred on upfront fees. Victims were asked to pay for background checks, training, equipment, or admin before they could start work.
That version has not gone away, but the tactic has changed. As job hunters have become more alert to requests for money, scammers have moved towards something harder to spot: Fake interview documents and bogus hiring tools that install malicious software.

The scam has moved beyond upfront fees
The earlier pattern was blunt. A fake employer would offer a tempting role, then ask the applicant to pay a fee before moving forward. Sometimes it was framed as refundable. Sometimes it was hidden inside supposed onboarding costs.
That method still catches people, but it now raises more suspicion. Most jobseekers know that a real employer should not demand money before an interview or job offer.
The newer version feels more convincing because it fits normal recruitment behaviour. Employers do send documents. They do ask candidates to prepare for interviews. They may ask for assessments, video calls, or test tasks.
Scammers exploit that familiarity.
In a case reported by the BBC, one victim had been actively searching for work and had spoken openly about that job hunt on LinkedIn. A role advertised on the platform appeared to lead to a promising opportunity. During the process, the supposed employer asked him to download a document to prepare for interview.
That download was not an interview file. It was malicious software.
Within hours, cryptocurrency accounts worth £18,000 in hard earned savings had been drained.
Why jobseekers are such attractive targets
Job hunting creates pressure. People worry about income, career gaps, bills, confidence, and competition. A strong-looking opportunity can make anyone act faster than they normally would.
Scammers know this.
They also know that public job-search activity can reveal useful clues. A profile might show someone is open to work, recently redundant, unhappy in a role, or trying to move into a new sector. Posts, comments, and CV details can help a scammer tailor their approach.
That makes the message feel personal rather than random.
A scammer posing as a recruiter may mention:
A real job title from the person’s profile
A sector the person has experience in
A recent post about job hunting
A remote role with flexible hours
A salary that feels just above market rate
A fast interview process due to “urgent hiring”
None of those details proves the job is real. They only prove that the scammer has done enough homework to sound believable.

The Gen Z scam gap matters
LinkedIn has released data describing what it called the Gen Z “Scam Gap”. According to the platform, younger professionals face the highest exposure to scams at 32%, while nearly a third, also 32%, admit to ignoring red flags.
Younger professionals may see more scam attempts, yet pressure to secure work can make warning signs easier to dismiss.
That does not mean only younger jobseekers are at risk. Anyone can be targeted. The point is that early-career workers may face a perfect storm: Less experience with recruitment norms, high competition, rising costs, and more public activity on job platforms.
Scammers are not relying on technical brilliance alone. They are relying on timing, stress, and the hope that comes with a possible new job.
Red flags in a fake recruitment process
A convincing scam does not always look ridiculous. It may include a professional tone, a job description, screening questions, and a named recruiter. The warning signs are often small.
Be cautious if a recruiter or employer asks you to download software, documents, browser extensions, or interview tools from an unfamiliar link. Real employers may use assessment platforms, but they should be verifiable, widely recognised, and linked from official company channels.
Other warning signs include:
Pressure to act quickly The recruiter pushes you to download a file or complete a task immediately.
Contact outside normal channels too soon The conversation moves rapidly to encrypted messaging apps or personal email.
Unverified domains The email address looks similar to a real company domain, but has extra words, odd spelling, or a free email provider.
Requests for wallet, banking, or identity details early Sensitive information should not be needed before a proper offer and checks.
A role that appears too easy for the salary High pay, flexible hours, little experience required, and immediate start can be bait.
Files with unusual instructions A document that asks you to disable security settings, install an update, or enter passwords should be treated as hostile.

How to check a job offer before clicking
The safest step is to slow the process down. Scammers want momentum. A real employer will not usually withdraw a serious opportunity because a candidate takes reasonable security precautions.
Before downloading anything, check the company’s official website. Look for the vacancy on its careers page. If the role is not listed, contact the company through a phone number or email address taken from its website, not from the message you received.
Search the recruiter’s name, but do not rely only on a profile existing. Fake or copied profiles can look convincing. Check whether the person has a credible work history, normal activity, and connections that make sense.
If a file has been sent, avoid opening it on a device that holds financial accounts, crypto wallets, password managers, or sensitive personal documents. Do not disable antivirus tools to make file access “work”.
For cryptocurrency users, extra care is needed. Malware that steals browser sessions, seed phrases, saved passwords, or wallet access can move fast. Keep seed phrases offline, use hardware wallets where suitable, and never store recovery details in screenshots, cloud notes, or plain text files.
If you think you have downloaded something malicious, disconnect from the internet, stop using the device for banking or crypto activity, and seek trusted technical help. Change passwords from a separate clean device. Report the scam to the job platform and to Action Fraud in the UK.
What platforms and applicants both need to do
Job platforms have a clear role to play. Scam adverts and fake recruiter accounts must be detected and removed quickly. Users also need simple warnings at the point of risk, especially when a message asks them to leave the platform or download a file.
At the same time, jobseekers need a security habit that fits real life. That means treating recruitment links with the same care as banking links.
The phrase “sent by a recruiter” should never be enough on its own.

A genuine employer will understand a request to verify a file, platform, or interview process. A scammer will often become impatient, vague, or threatening.
This latest LinkedIn scam shows how quickly fraud adapts. When upfront fees became easier to spot, criminals switched to malware hidden inside the hiring process. The next version may look different again.
The best defence is a pause. Check the company. Verify the recruiter. Question downloads. Protect financial accounts before opening anything unfamiliar.
This article is general fraud-prevention information, not financial advice. If a job opportunity asks for trust before it has earned it, treat that as the warning sign.






Comments