Recruitment fraud covers attacks that enter through hiring. It runs in both directions: attackers posing as candidates to get inside an organisation, and attackers posing as recruiters to compromise employees who believe they are exploring a job.
This library records 6 cases, including the single largest loss documented here.
How the attack runs
Attacker as recruiter:
- An approach arrives through a professional network with a credible role and salary.
- A rapport-building process follows, which normalises document exchange.
- A prepared file arrives as a task, offer or specification.
- The target opens it on a machine with meaningful access.
Attacker as candidate:
- A fabricated or borrowed identity is presented for a remote role.
- Interviews are handled with synthetic video or a substitute person.
- Employment grants credentials and internal access legitimately.
Documented cases
How it differs from related techniques
Spear phishing describes the mechanics when the attacker plays recruiter. Synthetic identity describes the fabricated person when they play candidate. Recruitment fraud is the shared entry point.
The control that would have stopped it
- Treat hiring as an attack surface with defined security involvement, not purely an HR process.
- Never open candidate or recruiter files on a machine with production access. This alone would have prevented the Axie loss.
- One unscripted live interaction in every remote hiring process.
- Verify references through independently sourced contact details.
- Warn staff that inbound recruitment is a known attack route, particularly engineers holding keys or infrastructure access.