Fake CEOs on LinkedIn Fuel IP & Data Theft

Help Net Security · Medium sophistication
Last updated September 22, 2026

A CSC report describes real-world scams where criminals impersonate executives and brands online to steal personal or payment information. Examples include fake CEOs contacting people on LinkedIn with bogus job offers, and lookalike “FIFA” domains used for fake ticket sales, travel offers, and giveaways. The report warns that AI is making these impersonation and brand-abuse scams faster to create and harder to spot.

Key findings

  • CSC report highlights impersonation, phishing, and domain-name abuse as top online IP risks.
  • A described Fashion Week scam offered high-end experiences and requested payment in Bitcoin/virtual currencies.
  • Clients reported executive impersonation on LinkedIn, using fake job opportunities to collect personal information for later attacks.
  • CSC found 65,590 third-party domains containing “FIFA” registered (Jan 2022–Apr 2026), some linked to fake ticketing/travel/merch/streaming/giveaways aimed at stealing personal or payment information.
  • AI is enabling faster creation of convincing fraudulent content, including voice and other digital copies of assets.

Who’s being targeted

  • Commonly targeted roles: All employees, HR/Recruiting, Finance (expense/travel payments), Marketing/Brand teams, Legal/IP teams, IT/Security teams.
  • Affected industries: Brand owners (cross-industry), Retail/e-commerce, Pharmaceuticals, Automotive, Sports/events and ticketing, Marketing/advertising.
  • Attack channels: linkedin, website.
  • Impersonated: Company CEO / senior executive, FIFA / FIFA World Cup-related brand.

Awareness takeaways

  • Treat unsolicited executive outreach (especially on LinkedIn) as high-risk and verify identity through a trusted, separate channel.
  • Before entering payment or personal details, verify event/ticket/travel offers by checking the official organization website and domain carefully.
  • Assume AI can make scams more convincing (including impersonation) and rely on verification steps, not “how real it sounds/looks.”

Red flags to watch for

  • Unsolicited message from a ‘CEO’ account
  • Pressure to share personal information quickly
  • Profile or connection history doesn’t match a real executive
  • Domain name looks unofficial despite containing “FIFA”
  • Too-good-to-be-true ticket/giveaway offers
  • Requests for payment or card details on an unfamiliar site
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine this: a LinkedIn DM, “Hi, I’m the CEO, I saw your profile and have a confidential opportunity.” CSC reports fake chief executives doing exactly this on LinkedIn, offering bogus jobs, then asking for your resume, phone, even ID details to use in later attacks. Same play with fake FIFA sites: CSC found over sixty-five thousand ‘FIFA’ domains, some selling fake tickets, travel, and giveaways to grab your card and personal data. Here’s the move: if a ‘CEO’ or ‘FIFA offer’ shows up out of nowhere, stop. Don’t reply or pay, open our official site or directory and verify through that, first.

Similar attacks

Wrong-Number Texts That Turn Into Scams

Wrong-Number Texts That Turn Into Scams

The article describes how “wrong-number” SMS messages are used as a first-step social engineering test to identify people who will engage with strangers. If the target replies, scammers may either build a long relationship that leads to fake investment fraud (“pig butchering”) or recycle the…

August 19, 2026
Fake Recruiters Hit Job Seekers With Malware Files

Fake Recruiters Hit Job Seekers With Malware Files

An alleged North Korean operation called “WaterPlum” targeted job seekers by posing as AI and blockchain companies and using the interview process to trick applicants into downloading malicious files. Authorities say the campaign infected tens of thousands of devices worldwide and led to theft from…

September 18, 2026
Recruitment Emails Hide BitB Google/Facebook Traps

Recruitment Emails Hide BitB Google/Facebook Traps

Researchers found a large recruitment-themed phishing campaign where victims receive unsolicited interview invites and are sent to fake scheduling or recruitment pages. The pages use “Browser-in-the-Browser” fake login popups to steal Google/Facebook passwords and, in some cases, capture MFA codes…

August 17, 2026
Fake FIFA Ticket Sites Steal Cards and OTPs

Fake FIFA Ticket Sites Steal Cards and OTPs

Researchers and the FBI warn that criminals are luring World Cup fans to convincing fake FIFA ticket websites, often via social media ads and shared links. The scam steals payment details in real time during checkout, including card data and one-time passcodes (OTPs), while victims believe they are…

July 16, 2026
60,000 Fake LinkedIn Jobs Used to Scam Applicants

60,000 Fake LinkedIn Jobs Used to Scam Applicants

Scammers are using realistic LinkedIn recruiter profiles and even verified company pages to post fake jobs that push people to off-platform sites or email addresses. The scams aim to take money (e.g., paid “resume help”) or collect sensitive personal data like driver’s licenses or Social Security…

September 23, 2026
Teams Helpdesk Vishing Pushes Remote Control Tools

Teams Helpdesk Vishing Pushes Remote Control Tools

Researchers observed a coordinated social-engineering operation (“Spring Ring”) where attackers used external Microsoft Teams accounts to pose as internal IT help desk staff and start voice calls. Victims were pressured to install remote-control tools (like Quick Assist or other RMM software) or…

August 31, 2026