BBC reports that fraud on recruitment websites is on the rise. Attackers no longer just send suspicious emails; instead, they impersonate recruiters to approach job seekers on platforms such as LinkedIn, and then under the pretext of interviews or technical tests, they guide them to download files or applications containing malicious programs.
Victims lost £18,000 in just a few hours
A victim stated that after posting a job application on LinkedIn, they received a job offer from a "recruiter." The recruiter first conducted a video call, then requested the completion of a common technical test, and sent further instructions via a form on Google. The file appeared normal on the surface, but it actually contained malware.
Not long after completing the test, the online wallet assets of this job seeker were transferred away, resulting in a loss of about 18,000 pounds. The victim stated that they subsequently cleaned their computer and changed their password, but still felt shocked and angry upon discovering that their funds had been stolen.
LinkedIn and Indeed issue a reminder
LinkedIn and Indeed have both issued alerts about recruitment scams in recent months. LinkedIn Previous data indicated that young job seekers are more likely to fall victim to such scams, and in the highly competitive job market, many people tend to ignore unusual signs out of fear of missing opportunities.
LinkedIn suggests that job seekers should first verify the authenticity of the company and the position before deciding whether to continue the communication. Indeed also issued a reminder in July this year, alerting users to be cautious of download requests under the guise of interview processes.
Malicious apps disguised as interview tools
Cybersecurity researchers say that such attacks are more difficult to identify because the entire process appears to be similar to a legitimate recruitment process. Victims may be operating on genuine Google pages or facing installation programs with valid signatures, making them more deceptive than traditional phishing emails.
According to Malwarebytes, common tactics used by scammers include "continue with the process after installing the Indeed interview application" or "view the salary agreement after installing the application", etc. Once users download these programs, attackers may obtain sensitive data from the devices and then proceed to carry out ransom demands or theft of funds.
Indeed claims that there is no need to download any apps for the interview.
Indeed has recently made it clear that the interview process on the platform is completed entirely within the browser, and job seekers are not required to download any special applications additionally. Any message requesting participation in the interview by downloading an application is not part of the normal process.


Such cases show that recruitment scams have evolved from forging job information to more sophisticated disguises of "interview scenarios." For job seekers who hold crypto assets, once their devices are infected with malicious programs, losses can occur in a short time, and it is quite difficult to recover the funds.











