60,000 Fake LinkedIn Jobs Used to Scam Applicants

TechSpot · High sophistication
Last updated September 24, 2026

Scammers are using realistic LinkedIn recruiter profiles and even verified company pages to post fake jobs that push people to off-platform sites or email addresses. The scams aim to take money (e.g., paid “resume help”) or collect sensitive personal data like driver’s licenses or Social Security numbers. A job seeker tracking these schemes says some attackers hijack dormant verified accounts to look legitimate while targeting applicants.

How the Attack Worked

Scammers built out fake job listings across LinkedIn using several tactics at once. Some created polished recruiter profiles from scratch, often in batches using copied photos and similar account details, to reach out to job seekers directly. Others went further and hijacked dormant, verified LinkedIn accounts, changing the work history to make the account holder appear to be a recruiter for a legitimate business. A third approach placed fraudulent job ads directly on legitimate, verified company pages, then routed applicants to outside websites or email addresses that had nothing to do with the real employer.

Why It Succeeded

The scams worked because they borrowed credibility from real platforms and real companies. A verified company page or a recruiter profile with a professional photo and consistent details reads as trustworthy to most job seekers, especially those who are recently laid off or applying for entry-level roles and eager to respond quickly. Attackers reportedly used AI to tailor job pitches to a person's résumé or career history, making outreach feel personalized rather than generic. Because verification does not guarantee legitimacy, applicants had little reliable way to distinguish a real recruiter from a fake one just by looking at a profile.

What to Watch For

  • Unsolicited critique of your résumé paired with a request for payment
  • Job ads on a trusted company page that link out to a site the company says it is not affiliated with
  • Instructions to email a résumé to an outside address instead of applying through the official careers site
  • Obvious errors in job ad content or mismatches with the employer's real job listings
  • Pressure to move fast or take the conversation off LinkedIn

Building Resistance

Organizations and job seekers can reduce exposure to these scams with a few consistent habits:

  • Independently confirm recruiter identities and job postings against the employer's official career site rather than trusting LinkedIn verification alone
  • Never pay a fee for resume help or recruiting services offered through unsolicited outreach
  • Avoid sharing high-risk personal information, such as a driver's license or Social Security number, early in a hiring process before the employer and process are verified
  • Report and flag profiles that look newly created, use copied photos, or show sudden changes in work history, since these can indicate account takeover

HR, recruiting, and brand protection teams also have a role to play by monitoring for spoofed listings tied to their company name and by educating applicants on the official channels used for real job postings.

Key findings

  • Scammers use polished LinkedIn job listings, recruiter profiles, and even verified company pages to lure job seekers.
  • Some scams push applicants off-platform to external websites or to email a resume to an outside address.
  • Scammers may hijack dormant, verified LinkedIn accounts and change work history to appear affiliated with legitimate companies.
  • Lures include charging a fee for “resume help” and harvesting high-value personal data (e.g., driver’s license, Social Security number).
  • Attackers are described as increasingly sophisticated, including using AI to tailor job pitches to a victim’s résumé or career history.

Who’s being targeted

  • Commonly targeted roles: All employees (job seekers), HR / Talent Acquisition, Recruiters, Hiring managers, Corporate communications / brand protection teams.
  • Affected industries: Online platforms / social networking, Recruiting / staffing, Financial services, Automotive / manufacturing.
  • Attack channels: linkedin, website, email.
  • Impersonated: Recruiter (using a copied or fake LinkedIn recruiter profile), A legitimate employer brand (using the employer’s verified LinkedIn company page), A legitimate employer (via fraudulent postings on/through LinkedIn).

Red flags to watch for

  • Unsolicited critique of your résumé paired with a request for payment
  • Recruiter profile appears newly created or mass-produced (similar photos/details)
  • Pressure to move fast or take the conversation/payment off LinkedIn
  • Job ad on a trusted page links to an external site "not affiliated" with the company
  • Obvious errors in the job ad content
  • Application path doesn’t match the employer’s official careers site process
  • Application requires emailing to an "outside address" rather than applying via official careers portal
  • Job listing leads to an unaffiliated website or non-company domain
  • Mismatch between LinkedIn job title and the company’s real career site listings
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How do scammers make fake LinkedIn job posts look legitimate?

They use polished recruiter profiles, copied photos, and in some cases hijacked dormant verified accounts or even legitimate verified company pages to make fraudulent postings appear trustworthy.

What do these fake job scams try to get from applicants?

Some scams charge a fee for supposed resume help, while others try to collect high-value personal data such as a driver's license or Social Security number.

Does LinkedIn's recruiter verification guarantee a job posting is real?

No. Verification is a trust signal, not proof of legitimacy, since scammers can still create convincing profiles or take over verified accounts.

What red flags should job seekers watch for?

Unsolicited resume criticism paired with a payment request, links to external sites not affiliated with the employer, and instructions to email a resume to an outside address instead of using the official careers portal.

Read the video transcript

That “perfect” LinkedIn job from a verified company page? It might be one of 60,000 fake listings built to drain you, not hire you. Scammers hijack or copy recruiter profiles, even on verified company pages, then post roles like data-entry or customer service that send you to an outside site or email. Next, the 'recruiter' says your résumé needs work and offers paid help or asks for your driver’s license or Social Security number. Here’s the twist: LinkedIn verification and slick AI-written messages make this look real. But the tell is the path. If a verified page sends you to a site not affiliated with the company, or a recruiter wants to move fast, go off LinkedIn, and get paid to 'fix' your résumé, it’s a scam. One move: before you click or pay, pause and independently check that job and recruiter on the company’s official careers site, if it’s not there, walk away.

Similar attacks

AI “Apple Support” Calls Steal iPhone Passcodes

AI “Apple Support” Calls Steal iPhone Passcodes

Researchers say a phishing-as-a-service platform called AnonyMousKIT targets people who recently lost or had an iPhone stolen by pretending to be “Apple Support.” The operation uses email/SMS/WhatsApp and AI-assisted voice calls to convince victims to share their iPhone passcode and follow a…

August 26, 2026
Fraudulent Gov Email and Passkey Lures Hit Orgs

Fraudulent Gov Email and Passkey Lures Hit Orgs

The bulletin describes real-world social engineering where staff were tricked into disclosing sensitive data or access. In one case, Revolut employees responded to fraudulent information requests sent from a real government-domain email account, exposing extensive customer records. Separately,…

September 14, 2026
Passkey Helpdesk Scam Hijacks Microsoft Accounts

Passkey Helpdesk Scam Hijacks Microsoft Accounts

Microsoft described two real-world campaigns: an invoice fraud blast impersonating executives to trick finance teams into ACH payments, and a passkey-themed helpdesk scam that steals or bypasses authentication to take over Microsoft cloud accounts. In the second campaign, victims are called or…

September 13, 2026
Claude Linked to Real Phishing and Credential Theft

Claude Linked to Real Phishing and Credential Theft

Anthropic reports multiple real-world threat groups used Claude to support cyber operations, including credential harvesting and data theft across many victims. The report includes specific, simulation-ready lures such as a fake ESET NOD32 login portal that sends stolen passwords to Telegram and a…

September 11, 2026
Passkey Helpdesk Scam Hijacks Microsoft 365

Passkey Helpdesk Scam Hijacks Microsoft 365

Microsoft reports active intrusions where attackers trick employees with “passkey/SSO update” helpdesk pretexts delivered by phone, SMS, or even Microsoft Teams. Victims are sent to lookalike Microsoft sign-in pages or guided through device-code sign-in, letting attackers capture session access and…

September 9, 2026
China-Linked Hackers Share Chrome Exploit Lures

China-Linked Hackers Share Chrome Exploit Lures

Proofpoint reported at least four espionage groups (mostly linked to Chinese state intelligence) using the same Chrome zero-day exploit kit (“BlueMoon”) to compromise victims and deliver malware. The operations used believable business and event-themed lures (internship inquiries, procurement…

September 9, 2026