16 ms·
Someone is impersonating us in a recruiting scam
- JoeAltmaier 4y agoReminds me of food delivery companies presenting themselves as restaurants. There was some question of if or how illegal it actually was.
- mnd999 4y agoSurely it comes down to trademarks. If you’re using someone else’s trademark you’re in trouble if they sue you.
- paulgb 4y agoOr wire fraud. IANAL but this in particular seems to go beyond trademark misuse into yeah-that's-a-crime territory: > For example, in this case, candidates received the “offer letter” with our old company logo in the letterhead instead of the new logo we introduced recently. The offer letter was also signed by a random "Advisor" named Tom Gahm (who actually doesn't exist) rather than the CEO.
- nowherebeen 4y agoOh the irony. These startups have been growth hacked!
- cyral 4y agoA good read: https://www.readmargins.com/p/doordash-and-pizza-arbitrage https://www.readmargins.com/p/doordash-and-pizza-arbitrage
- hn_throwaway_99 4y agoI mean, TBH this seems like a pretty dumb scam, and you have to be pretty gullible to fall for it. Send my bank account information over to a company before I've actually had face-to-face conversation with anyone there? And who would expect to get an offer letter before you've even had an actual interview (as opposed to just some questionnaire you had to fill out)?
- yieldcrv 4y agoI mean if I said it was for Direct Deposit this would match many candidates and employees experience.
- aynyc 4y agoPeople are gullible. I can probably build a website with reasonably fake job listings, and ask job applicants to fill out I-9. I'm pretty sure I can get a lot of personal data from that.
- vlunkr 4y agoThere are lots of dumb scams. It's a numbers game, you reach out to thousands of people and if only a few bite, you're probably still making a profit.
- V-2 4y agoPlus the "offer" (and all email communication) is run from a Gmail account, they didn't even bother to spoof or semi-spoof a credible looking address. Of course they're not targeting the best and brightest, but this is by design - such folks wouldn't jump at a random job opportunity to begin with
- elcomet 4y agoI'm not sure it help to shame people who fall for those scams. People do fall for it, scammed are exploiting human's trust that most people are nice. Most scams seem dumb once you know about them. And once some scam becomes well known, scammers will just change tactics. The important thing is to educate people (for example do not give your bank information over the phone ever, except if you are the one who called maybe) and have good insurances in case something like this happens. And I believe it could happen to any of us, even people who think they're not gullible.
- hn_throwaway_99 4y agoSorry, I didn't mean to shame folks, I just meant to highlight that there is very little in this scam that seems new or clever, so it doesn't seem particularly noteworthy. I probably get a couple of similar scams directed to me every week (we joke in our company how we all get texts from our "CEO" asking to respond to an urgent need...) Every now and then I'll read about an online phishing/spear-phishing scam and think "Wow, that is really good. I definitely may have fallen for that!" (e.g. the "delayed disconnect" phone scam - TBH I didn't even realize some landlines worked like that.) This is not one of those times.
- BashiBazouk 4y agoI was contacted through LinkedIn by a scammer with a position at a major company. The email was slightly off and the email suffix was a .company.somethingelse.com. I contacted the company HR department asking if it was a real job and if not, would they like all the information I had on the scammers. No reply...
- adrianmsmith 4y agoYou'd hope the company would care. But on the other hand I suppose it'd be you being scammed not them. As harsh as it seems, that's probably why they don't care.
- ghaff 4y agoAnd it would probably be a hassle for the HR person to reach out to legal, answer various questions, and deal with it. Not their job, not their problem, not a great attitude either--but so it goes.
- leaflets2 4y agoHow do you arrange incentive structures so that people in the company who get such emails, want to do something about it -- and, so others in the company (eg legal) want to, too? (Without messing up other things the company is doing)
- ghaff 4y agoFundamentally, it's culture. But even under the best of circumstances it's still hard to get people to care about things that they're not being measured on or rewarded for.
- leaflets2 4y agoMaybe the execs and CEOs can try to be examples Rewarded... Maybe profit sharing? Then could pay back to do what's good for the company?
- seaerkin 4y agoThere are companies that offer brand and employee impersonation detection services, but something like this is undetectable. Any scam done through a public email provider, you really can't do much aside from reporting the email and raising awareness. Had the scammers linked back to a domain or website that looks similar to your brand, THAT is detectable and there are services that can help here.
- sbassi 4y agoYou should post a visible warning in your careers page, it may help for some cases.
- random_0 4y agoMay be they should add a notice on their home page too.
- bell-cot 4y ago> ...an elaborate scheme around [our company name] Why is she calling this "elaborate"? It's typo-ridden, done from random gmail addresses, and worse. I get "Nigerian Central Bank need you help transfering $40 million to you account" spam that looks better-done than this scheme. Edit: 's/is he/is she'
- daniel-cussen 4y agoThat's intentional in both Nigerian 419's and this. They are both looking for fools with money with which to part.
- mbostleman 4y agoThe author and CEO appears to be a she, preferred pronouns notwithstanding.
- aprinsen 4y agoMaybe it's not "elaborate", relative term, but it's multi step, several fake accounts, a fake mail server, multi step interview, and it's tailored to a specific company and targeted to a relevant audience.
- bpicolo 4y agoSomewhere out there, phishers with spell check are raking it in. Seriously though - a big focus of corporate phishing training is “watch out for typos”, which is insane. If that’s our main indicator of phishing we’re toast.
- jahewson 4y ago> We haven’t had anyone report that they actually got stollen from yet, but of course there would be a delay before they notice. I’d expect that to happen sometime around Christmas :p
- davidkuennen 4y agoOff topic but I love their website. Fast and nicely structured in general.
- sdflhasjd 4y agoNot a fan of kapwing as they seem to be running a spam campaign on reddit. Also not fond of hosts that put watermarks on media as it contributes to a kind of bit-rot.
- jenthoven 4y ago[This is Julia, the OC] We’re not running a spam campaign. Any more info here on what you’re referring to? We used to make it free to remove the Kapwing watermark, but needed to up our conversion recently to extend runway and fund R&D. Just shot every creative tool in our space leverages watermarks as a conversion lever because it means we can offer most things for free.
- sdflhasjd 4y agoI am referring to a recent spate in unusual comments on top posts that link to reaction-image like clips hosted by kapwing. I'm trying to find some examples, but naturally there's none to be seen as soon as I look. The comments contain unusual English, perhaps computer generated, and consist of an initial sentence, followed by a quoted hyperlinked sentence linking to kapwing. I assumed these were an attempt by kapwing, and if that's not the case, I apologise for my accusation.
- deleted 4y ago[deleted]
- trwhite 4y agoThese scams always have horrendous grammar. To me that's a huge red flag
- tessgadwa 4y agoI was targeted by a similar recruiting scam several years ago -- again, a smallish company which was high on my interest list, with a personalized email matching my stated skills and experience. All I can say is that while legit "cold" recruiting outreach happens all the time, if you are a job seeker take the time to verify these contacts. Don't give out personal or contact information until you are absolutely sure you know who you are talking to! A professional will not mind you taking this extra step.
- jenthoven 4y ago[This is Julia, the OC] 100% agree. At Kapwing, we would never penalize a candidate for verifying a job opening; in fact, we’d likely see it as a positive signal and sign of enthusiasm.
- leaflets2 4y agoWhat does OC mean? Thanks for writing about all this and warning people :-) I wonder how much the actions Kapwing took has reduced the amount of scam attempts -- if you happen to know? Maybe hard to measure
- bluehatbrit 4y agoMaybe "original creator"?
- ChrisMarshallNY 4y agoI was once contacted by Apple. The email almost got shitcanned, because it was so scruffy. The subject was just "Hello From Apple." There was no HTML in the email, and the letter was really short. It may have been an auto-generated one. It never turned into anything, but it was a legit contact.
- ipaddr 4y agoReminds me of the Amazon ones.
- mhzsh 4y agoYears ago, my previous employer had a few listings on Indeed for software engineers (some were very long-running). A recruiter reached out to us with a candidate they had, who had experience in the areas we were looking for, which was enticing because people like this were not so easy to come by for a small company not based in a major city. By chance, we found out during the interview process with the candidate that the recruiter was playing both parties. This very shady recruiter cloned our job listing (removing the company information) and was able to out-rank us in the search. They presented themselves to the candidate as if they were working for us, and to us they presented themselves as trying to place this candidate, effectively collecting a recruiting fee for hijacking our listing forwarding a resume. They ended up with nothing but a warning from lawyers, but they _almost_ got an easy paycheck out of it.
- a2tech 4y agoI don’t think this is uncommon—in fact I think it’s the way many recruiters work.
- raverbashing 4y agoHence why most companies don't accept placements by recruiters unless it's the one they specifically hired for the job
- apohn 4y agoUnfortunately recruiters lie about "exclusivity" as well. About a year ago I was on the job market and multiple recruiters reached out to me with the exact same job listing, just with the company name removed. All of them claimed to have an exclusive relationship with the company and they were working directly with the hiring manager. With 5 minutes of Googling I found the original position and the company that posted it. Do they get penalized if they present a candidate for the job and the company says "No recruiters" and they remove the candidate from their candidate pool?
- benglish11 4y ago
- 120bits 4y agoThis is the 4th time I have heard this news in a month. I wasn't paying much attention till it happened to my girlfriend. A person with a linkedin profile, that looks very legit saying they work for Nike at a senior level position reached to my gf for a job role. Well, at first she was excited and then she forwarded me their profile. It was really good presentation, however, few things were way off. Like the timelines on their profile were not accurate. The related experience was shady and more. As I dig deep I was convinced its a scam. I reported the profile to Linkedin.
- toss1 4y agoI've been reading quite a few more of these lately. It appears that LinkedIn has a problem not only with the tsunami of everyday recruiter spam flooding out their primary value proposition (real biz connections), but now criminal scams exploiting their platform. Seems like one of those tipping point phenomena, that doesn't seem critical, until it is, and by then, it's too late and mostly all of the customers have decided they're done with it.
- jenthoven 4y ago[This is Julia, the IC] In this case, LinkedIn had nothing to do with the scam. The thieves were using my real name and they didn’t create a fake profile for the supposed recruiter, so there’s unfortunately no phony profile to report.
- matsemann 4y agoSomeone used this technique to steal hundreds of millions in crypto tokens from a company recently, so looks to be a common and lucrative scam more people are trying. https://news.ycombinator.com/item?id=32001742 https://news.ycombinator.com/item?id=32001742
- kstrauser 4y agoUgh, LinkedIn. Someone created a profile saying they were in my company's Mumbai office. We're 100% US-based, which is very important in our specific market. It could be very bad for us if a large customer thought we were lying about having employees outside the US. I finally had to resort to blatant Twitter shaming to get LinkedIn to address the problem.
- teetertater 4y agoOn the other hand: I once got an offer letter with typos, after just a phone screen.. and it was totally legit! I worked there for a while
- IG_Semmelweiss 4y agoI wanted to add information. Please correct if I am off: The reported heist of $xxx in Axie crypto by takeover of the majority of nodes, was organized N Korean group that created an entire fake company in linkedin and related story and web presence... The group used the mark - a senior engineer at axis - as a gateway to the nodes themselves, under the pretense of recruitment. The engineer went thru a very formal interview process, during which he received a PDF with sophisticated malware trojan. Food for thought.
- whimsicalism 4y agoYou are correct although it seems a bit under-reported. How does a senior engineer have control over millions of dollars without review? I also am somewhat skeptical of this one-click PDF hack. They used a zero-day for this attack? In Chrome? Why hasn't this been discussed if so?
- zrobotics 4y agoI'd speculated previously on this, but that could be fairly trivially accomplished with signature requirement extensions. here's my prior comment: We had an employee compromised by a similar attack-executable linked in a Pdf. Basic flow was-phisher asked employee to sign a document relating to customs. The phisher had gathered that this employee works with shipping claims and returns, and surmised that they need to deal with customs documents requiring signature. There was a link to an exe hosted on a European cloud service in the PDF titled "install fake signature certificate company to sign this document". This directed to a download of a basic ransomware executable. This did get past our AV to the point of encrypting the employee's machine, but thankfully was blocked from spreading to the rest of the network. The employee's machine was toast, but I was able to restore from the prior day's backup and no major harm occurred. I was able to see the phishing attack since we use gsuite email so the ransom ware didn't erase the employee's inbox, but they did lose a half-day work and I updated our training. The attack itself was clever from a social engineering perspective, but the technical exploit was something any script kiddy could have downloaded from the open web, nothing advanced at all. But Gmail doesn't always scan links in PDFs, so a clever ruse was able to bypass Google's scanning as well as our local scanning.
- phendrenad2 4y agoI've heard from multiple senior engineers that they felt like they were being scammed while interviewing with a legitimate company. I end up spending a lot of time digging through the company website to make sure that at least ONE of the people I spoke to in interviews is even mentioned by name somewhere. If I can't do that, I make up some excuse to talk to the CFO about stock option vs base salary balance or something. This is all bullshit. Companies should accompany any request for personal information with a document signed by their private key, so I can verify it with the company's public key. Wasn't PKI invented in the 1980s?
- notjustanymike 4y agoWe've had an ongoing problem with this as well, and it's shockingly effective. A couple of "candidates" have reached out to us right before they were scammed. The con really preys on people's hopes - promise them a higher paying job, hopes of a better life, then casually extort them right at the end.
- frays 4y agoHow did the "candidates" actually get scammed? Did the bad actors steal their personal information and commit fraud? I don't understand what scammers get out of doing this. How do they make money?
- smabie 4y agoBy getting acct and routing numbers they can easily siphon money.
- notjustanymike 4y agoWith us, they would have the candidates purchase their own hardware from a custom store and then “reimburse” them.
- edm0nd 4y agoA North Korean APT and other nation-state backed hackers are using fake job offers and interviews to drop targeted malware. It's actually a pretty effective method. Certainly something to be aware of if you are job hunting and an engineer or sysadmin position for a large F500 company. Triple verify everything and dont open PDFs lol.
- blobbers 4y agoIf you work at a crypto exchange I have an exciting opportunity for you!
- hnthrow1553 4y agoThis has been happening to my org more and more too. It's been a combination of fake linked accounts reaching out to unsuspecting people and getting them to pay in return for getting priority access to the recruitment queue. Sadly, it works - we have had people show up at our offices for their non-existent interview. They tend to get very irate when you explain that they were scammed.
- AtNightWeCode 4y agoFirst impression. Fake. Some random company trying to get attention. Scams are often more generic or more poorly done. This would be some Americans trying to harm the biz by targeting. Not unheard of but not very likely.
- AtNightWeCode 4y agoReminds me of that guy from Sweden(?) who HIRED more than 100 people to a non-existing company. Best scam ever, because it is so stupid, and hard to understand why.
- tpmx 4y agoThis story from four months ago? https://metro.co.uk/2022/02/21/jobfished-bbc-doc-on-madbird-unveils-employees-swindled-into-fake-company-16143538/ https://metro.co.uk/2022/02/21/jobfished-bbc-doc-on-madbird-... (It was the UK.)
- AtNightWeCode 4y agoThis was 5-10 years ago. I can’t find an article now, but the dude was a scammer. He did things like eating at restaurants and leaving without paying. Then for some reason he made up this fake warehouse company with fake clients. He built an office, he even hired his fiancé and then hired 100+ workers. The scam was revealed the first workday for the workers. The location given was another warehouse company that were rather surprised to see all the people at the gates.
- Beaver117 4y agoRecruiters get what they deserve for ghosting people and being assholes
- useruser1991 4y agoUnrelated: Kapwing runs the most odious dark pattern I've seen for users who wish to cancel - they threaten to make all the content you created public.
- abadger9 4y agothis happened to me with facebook pre ipo! someone tried to impersonate them and screw with me on a fake technical interview. That person ended up getting kicked out of our college for academic reasons and the campus facebook recruiter found out and extended me an interview.
- baxtr 4y agoInteresting scheme. I wonder why they do it. Neither in the linked article nor in the comments here I found a real financial damage - other than huge waste of your time and loss of personal data. Anyone any clue on this?
- andreygrehov 4y agoThis could be one of the reasons - https://www.cnet.com/personal-finance/crypto/a-fake-job-offer-reportedly-led-to-axie-infinitys-600m-hack/ https://www.cnet.com/personal-finance/crypto/a-fake-job-offe...
- twostorytower 4y agoMost likely they send an offer letter that contains malware. Typically it looks like a PDF - but maybe requires a "special reader" to sign. This is used to hack your bank, crypto, maybe the company they work at currently (as many employees use their work laptop as a personal laptop even though they should not).
- fsckboy 4y agoI was just idly thinking "a name like kapwing should be easy to get a domain name for, i wonder where they got the name?", so I looked it up in wiktionary. Not sure if this is the origin, but wiktionary lists it as "(rare) the sound of a bullet richochet"... KA-PWING! is this how the company name is pronounced?
- jenthoven 4y ago[This is Julia, the OC] We've got you https://www.youtube.com/watch?v=vpUvcWjFkFs https://www.youtube.com/watch?v=vpUvcWjFkFs Also check out our blog post about the name :) https://www.kapwing.com/blog/why-we-chose-an-onomatopoeia/ https://www.kapwing.com/blog/why-we-chose-an-onomatopoeia/
- bobbaf 4y agoThis is also how they were able to steal money from Axie Infinity, they sent a malicious PDF file that was able to exploit and compromise the company's security and steal US$600 million! https://www.cnet.com/personal-finance/crypto/a-fake-job-offer-reportedly-led-to-axie-infinitys-600m-hack/ https://www.cnet.com/personal-finance/crypto/a-fake-job-offe...
- khendron 4y agoSomething similar happened to one of my corporations. Somebody targeted by scam the was suspicious and contacted me via LinkedIn. Discovered somebody had setup a completely separate and very legit looking website using a similar domain name (e.g., instead of company.com, it was companyinc.com). I have no idea if they successfully scammed anybody. One thing I did that is not mentioned in this article is that I contacted the police. The police took a statement and collected all the relevant files (e.g., the PDF job offers I had been sent). There was, unfortunately, not much the police could actually do. But having an official police report helped in my next step, which was to start an internet-wide game of whack-a-mole with the scammer's website. I'd identify the hosting company, send them an abuse report, citing the police report, and request the website be taken down. The hosting company would usually comply within 24 hours, then a week or so later the website would reappear using a different host. Lather, rinse, and repeat several times until the scammer gave up (or moved to a different domain that I have not discovered yet).
- axus 4y agoI wonder if they ever tried to take down your website with their own, phony, police report
- zrobotics 4y agoWe had a very similar issue. It wasn't recruiter, but a scammer setup a companyname+(inc).com domain to sell fake products. We went straight for their registrar with a trademark claim and were successfully able to get the domain transferred to us so we could redirect to our actual site. If they are hosting content that is clearly similar to yours, then a trademark claim can be successful. Then, rather than chasing down hosting providers, you only need to deal with it once. This is also a good point to spend a few hours registering any permutations of your domain that are similar enough to cause confusion to prevent this from reoccurring. This is why the Nissan.com guy could keep the domain, since he wasn't selling cars. If he'd been using the domain that could be argued to be impersonating Nissan the car company, he would have lost ownership.
- palata 4y agoI don't get how it works. If I give my IBAN, then people can send me money, but they cannot take money from me. A scam would need to ask e.g. my credit card data, but at this point it's pretty clear that it's not to send me money. I am not in the US. Is that different there? Like do you use the same numbers for both? Or do people just not know the difference?
- erichurkman 4y agoThe key is in the 'congratulations' email: > Please note that, on acceptance of this employment offer, the following equipment will be deliver to you to set up your home office, the funds for the purchase of the equipment will be made available to you prior to purchase and delivery. They will send you a $15k check, you'll buy the equipment, and Venmo them back the remainder. Meanwhile, the check bounces.
- pandaman 4y agoIn the US the same requisites are used for both directions of the transfer. If you give your account number and routing number to receive a deposit, the same numbers can be used to withdraw from your account. Coincidently, these numbers are on any check you cut. Banks provide protection (requiring authorization for every withdrawal or disabling withdrawals all together) to business accounts but the consumer accounts do not have this even as a paid service, at least in the major retail banks. The government is supposed to come after any fraud here with heavy criminal charges, it's essentially a check forgery but I don't think it's too busy or too successful doing this.
- palata 4y agoMy way feels so much simpler :-). It's a bit like public/private key: when I use my credit card, I know I'm paying. And if I pay from my bank, I do it from my e-banking and it's super clear. I can allow a company to withdraw directly, but still it's clear I'm doing it (and I don't use that, I hate that feature). Feels like it just prevents such scams. Of course then you can still convince people to "lend" you money ("send me 5k to leave my country and when I'm safe I send you 2M"), but that's slightly different.
- rmbyrro 4y agoInitially I expected they'd pretend to hire the person to use services for free. It could last about 45 days. After the first missed paycheck, they could drag 2 more weeks on "bank transfer issues". Depending on the person, even 60 days... They could potentially get 2 months of senior video editing free of charge. Sell this on Fiverr and make more money they were asking the candidates.
- cafard 4y agoBut then they'd have to go out and sell the editing work. This way they just hit the mark's bank account.
- robbitt 4y agoThis is common problem in nearly all intermediary business models from real estate agents, stock brokers (now nearly obsolete), recruiters to freight brokers...
- neya 4y agoHappened to me once to my company. I signed up for a bunch of porn sites with their fake email as most sites don’t require email verification. The only way to fight scam is by spam. Authorities and others take too long. The other way I fought back was to create a bunch of fake gmail addresses and keep in touch with them and waste their time. They hate it when you waste their time. But time wasted for them means money saved for someone.
- thamer 4y agoThe job offer says they'll receive an iMac Pro, a bunch of hardware and software, including "Crimson Editor". I wasn't familiar with it, but it seems to be an HTML editor for Windows that was last released in 2008, it's "so small that it can be copied in one floppy disk". Their website doesn't even have HTTPS: http://www.crimsoneditor.com/ http://www.crimsoneditor.com/ Did they copy part of this list of perks from a 15-year-old scam script?
- indymike 4y agoThere are multiple red flags here: 1. Asking you for a fee if you are hired. Staffing fees should be paid by the employer on top of agreed to compensation to the employee. In fact, if you a direct hire, you shouldn't even know what the recruiter is getting, but they should tell you they are getting paid. 2. Asking you to pay for or buy equipment that will belong to the company. Telling you we'll give you money to buy a Mac and other gear. Any legit company will simply ship the equipment to you, usually pre-configured. 3. A non-company domain for emails. 4. Unrealistic compensation. Who wouldn't want to edit video for $187K/year ($90/hr)? This is very high.
- mise_en_place 4y ago> The “applicant” gets a job offer letter PDF, supposedly from our HR department. The email may come from kapwingeditor@outlook.com. I laughed for a good 2 minutes at this one. You have to admire the chutzpah of some of these scammers.