Attack Techniques

Recruitment fraud

Attacks that enter through hiring: fake candidates, fake recruiters, fake job offers.

Recruitment fraud covers attacks that enter through hiring. It runs in both directions: attackers posing as candidates to get inside an organisation, and attackers posing as recruiters to compromise employees who believe they are exploring a job.

This library records 6 cases, including the single largest loss documented here.

How the attack runs

Attacker as recruiter:

  1. An approach arrives through a professional network with a credible role and salary.
  2. A rapport-building process follows, which normalises document exchange.
  3. A prepared file arrives as a task, offer or specification.
  4. The target opens it on a machine with meaningful access.

Attacker as candidate:

  1. A fabricated or borrowed identity is presented for a remote role.
  2. Interviews are handled with synthetic video or a substitute person.
  3. Employment grants credentials and internal access legitimately.

Documented cases

How it differs from related techniques

Spear phishing describes the mechanics when the attacker plays recruiter. Synthetic identity describes the fabricated person when they play candidate. Recruitment fraud is the shared entry point.

The control that would have stopped it

  • Treat hiring as an attack surface with defined security involvement, not purely an HR process.
  • Never open candidate or recruiter files on a machine with production access. This alone would have prevented the Axie loss.
  • One unscripted live interaction in every remote hiring process.
  • Verify references through independently sourced contact details.
  • Warn staff that inbound recruitment is a known attack route, particularly engineers holding keys or infrastructure access.
Explore more

Related techniques and attack types

Parent attack type