https://krebsonsecurity.com/2021/05/how-to-tell-a-job-offer-from-an-id-theft-trap/ Advertisement [1] Advertisement [6] Krebs on Security Skip to content * Home * About the Author * Advertising/Speaking How to Tell a Job Offer from an ID Theft Trap May 21, 2021 23 Comments One of the oldest scams around -- the fake job interview that seeks only to harvest your personal and financial data -- is on the rise, the FBI warns. Here's the story of a recent LinkedIn impersonation scam that led to more than 100 people getting duped, and one almost-victim who decided the job offer was too-good-to-be-true. [jobscam] Last week, someone began began posting classified notices on LinkedIn for different design consulting jobs at Geosyntec Consultants, an environmental engineering firm based in the Washington, D.C. area. Those who responded were told their application for employment was being reviewed and that they should email Troy Gwin -- Geosyntec's senior recruiter -- immediately to arrange a screening interview. Gwin contacted KrebsOnSecurity after hearing from job seekers trying to verify the ad, which urged respondents to email Gwin at a Gmail address that was not his. Gwin said LinkedIn told him roughly 100 people applied before the phony ads were removed for abusing the company's terms of service. "The endgame was to offer a job based on successful completion of background check which obviously requires entering personal information," Gwin said. "Almost 100 people applied. I feel horrible about this. These people were really excited about this 'opportunity'." Erica Siegel was particularly excited about the possibility of working in a creative director role she interviewed for at the fake Geosyntec. Siegel said her specialty -- "consulting with start ups and small businesses to create sustainable fashion, home and accessories brands" -- has been in low demand throughout the pandemic, so she's applied to dozens of jobs and freelance gigs over the past few months. On Monday, someone claiming to work with Gwin contacted Siegel and asked her to set up an online interview with Geosyntec. Siegel said the "recruiter" sent her a list of screening questions that all seemed relevant to the position being advertised. Siegel said that within about an hour of submitting her answers, she received a reply saying the company's board had unanimously approved her as a new hire, with an incredibly generous salary considering she had to do next to no work to get a job she could do from home. Worried that her potential new dream job might be too-good-to-be-true, she sent the recruiter a list of her own questions that she had about the role and its position within the company. But the recruiter completely ignored Siegel's follow-up questions, instead sending a reply that urged her to get in touch with a contact in human resources to immediately begin the process of formalizing her employment. Which of course involves handing over one's personal (driver's license info) and financial details for direct deposit. [esiegel] Multiple things about this job offer didn't smell right to Siegel. "I usually have six or seven interviews before getting a job," Siegel said. "Hardly ever in my lifetime have I seen a role that flexible, completely remote and paid the kind of money I would ask for. You never get all three of those things." So she called her dad, an environmental attorney who happens to know and have worked with people at the real Geosyntec Consultants. Then she got in touch with the real Troy Gwin, who confirmed her suspicions that the whole thing was a scam. "Even after the real Troy said they'd gotten these [LinkedIn] ads shut down, this guy was still emailing me asking for my HR information," Siegel said. "So my dad said, 'Troll him back, and tell him you want a signing bonus via money order.' I was like, okay, what's the worst that could happen? I never heard from him again." HOW TO SPOT A JOB SCAM In late April, the FBI warned that technology is making these scams easier and more lucrative for fraudsters, who are particularly fond of impersonating recruiters. "Fake Job or Employment Scams occur when criminal actors deceive victims into believing they have a job or a potential job," the FBI warned. "Criminals leverage their position as "employers" to persuade victims to provide them with personally identifiable information (PII), become unwitting money mules, or to send them money." Last year, some 16,012 people reported being victims of employment scams with losses totaling more than $59 million, according to the FBI's Internet Crime Complaint Center (IC3). But the real losses each year from employment scams are likely far higher; as the Justice Department often points out, relatively few victims of these crimes report the matter to the IC3. LinkedIn said its platform uses automated and manual defenses to detect and address fake accounts or fraudulent payments. "Any accounts or job posts that violate our policies are blocked from the site," LinkedIn said in response to a request for comment. "The majority of fake job postings are stopped before going live on our site, and for those job postings that aren't, whenever we find fake posts, we work to remove it quickly." LinkedIn's most recent transparency report says these automated defenses block or automatically remove 98.4% of the fake accounts. But the scam that ensnared Gwin and Siegel is more of a hybrid, in that the majority of it operates outside of LinkedIn's control via email services like Gmail and Yahoo. This, by the way, should be a major red flag for anyone searching for a job, says the FBI: "Potential employers contact victims through non-company email domains and teleconference applications." Here are some other telltale signs of a job scam, as per the FBI: -Interviews are not conducted in-person or through a secure video call. -Potential employers contact victims through non-company email domains and teleconference applications. -Potential employers require employees to purchase start-up equipment from the company. -Potential employers require employees to pay upfront for background investigations or screenings. -Potential employers request credit card information. -Potential employers send an employment contract to physically sign asking for PII. -Job postings appear on job boards, but not on the companies' websites. -Recruiters or managers do not have profiles on the job board, or the profiles do not seem to fit their roles. This entry was posted on Friday 21st of May 2021 01:41 PM Employment Fraud Latest Warnings Web Fraud 2.0 Erica Siegel fbi Geosyntec Consultants LinkedIn LinkedIn job scam Troy Gwin [119] Post navigation - Recycle Your Phone, Sure, But Maybe Not Your Number 23 thoughts on "How to Tell a Job Offer from an ID Theft Trap" 1. Steve May 21, 2021 Had I received this letter, would my suspicions be aroused by the awful writing? It doesn't look like something a native English speaker would compose. But in our world of multinational corporations and employees from diverse backgrounds - and frankly, I've known native English speakers who can't write even that well (though none of them have ascended to the level of Senior Recruiter, not yet at least) - how confident could I be? These days, everything requires verification. Reply - 1. Stephen May 21, 2021 From one Stephen to another, yeah, I am with you. To quote a famous president: "Doveryai, no proveryai." Reply - 1. ReadandShare May 21, 2021 I copied/pasted that quote into Bing Translate and it 'auto detected' as Spanish, failing to translate! Reply - 1. security vet May 21, 2021 ...roughly "trust, but verify" - in Russian... Reply - 2. Kris May 22, 2021 First thing I would have done was to look at the headers. I always do that with any weird email to see if I can get any clues on where it's coming from Reply - 1. Other Kris May 22, 2021 They were from gmail accounts, so the headers would have told you nothing. The people who got duped were naive enough to think a large corporation wouldn't use their own domain name. Reply - 2. Steve J. May 21, 2021 Great article Brian, thank you! LinkedIn must have their hands full dealing with this type of scam and fake profiles. I am sure the proliferation of cute animal pictures, political posts and my family member did this... diverts their attention from what really needs to be addressed. Over the last couple of years LinkedIn has become more of a Social Media site than a professional networking site. Unfortunate, I always had a great respect for the site and what it offered. Reply - 3. The Sunshine State May 21, 2021 What amazes me is that Internet user are not aware that just like LinkedIn , Facebook is a huge cesspool of scammers from Western Africa Reply - 4. Nick Condos May 21, 2021 I'm curious what the companies whose names are being spoofed for these scams can do, if anything. These fake jobs posts are not just on LinkedIn but on every gig-work site there is around the globe. Reply - 1. noodles May 21, 2021 In the case of Geosyntec (the real corp), if they are made aware of the scams and their intellectual property is used via clone sites or typosquatted sites and whatnot, they can issue take down notices through legal avenues to hosting providers and name registrars and such, but that can often take weeks/months unless you have good connections to people working at said hosting providers or registrars. Other options are using a service that does this for you - i.e. recorded future or zerofox and the like. They have agreements with the big players that give them auto takedown capability or nearly instant ability to take action. Lots of large orgs do this for brand and identity protection - they don't want people getting conned and their brand/name being associated to a bad experience. Reply - 5. Henry Winokur May 21, 2021 Uh, Brian, you used an abbreviation without defining it. What's PII? Reply - 1. rory May 21, 2021 Personally identifiable information Reply - 2. Chris May 21, 2021 PII=Personal Identifiable Information Reply - 3. security vet May 21, 2021 ...Personally Identifiable Information... ...IIHI = Individually Identifiable Health Information... Reply - 4. BrianKrebs Post authorMay 21, 2021 It's described in the story. And it's me quoting the FBI, not me saying it "Fake Job or Employment Scams occur when criminal actors deceive victims into believing they have a job or a potential job," the FBI warned. "Criminals leverage their position as "employers" to persuade victims to provide them with personally identifiable information (PII), become unwitting money mules, or to send them money." Reply - 6. Sok Puppette May 21, 2021 > One of the oldest scams around -- the fake job interview that seeks only to harvest your personal and financial data Yeah, I hear that one was really common around the savannah. Reply - 7. Susan Basko May 21, 2021 Brian Krebs, you are a brilliant researcher and writer. This entry is enlightening, to say the least HOW TO TELL A JOB OFFER FROM AN IDENTITY THEFT TRAP. I have seen job applications and even offers of money grants running these scams. Thank you for all you do, Reply - 8. Steve C# May 21, 2021 If they are using an email account that is not directly connected to their domain that is a Black flag. If they want you to pay for anything that is a Black flag, Always do research on the company and ask questions about the company and questions very specific about the job. Expect to talk with a real person. Reply - 9. P.D. May 22, 2021 Simpler Method: If it comes from an Indian firm, heave it. Reply - 10. Moike May 22, 2021 "Potential employers contact victims through non-company email domains and teleconference applications." This describes exactly the experience with some real jobs these days; a small or medium company does not perform the initial screening with their own HR department, but all contact is via a recruiting company or FaceTime / Zoom. Hopefully the recruiting company itself can be checked out to verify. Reply - 11. Sebastian May 22, 2021 The kind of scam is also typical in real estate scenarios when people try to find an appartement. Reply - 12. John Hicks May 22, 2021 A similar version has been going on for decades. Real small companies troll for your resumes and will include them as part of their bid packages for contract work for larger companies or the government. Their excuse is they'll offer you a job if they win the contract. You generally never hear from the small company again, unless multiple companies bid your resume for the same contract. Reply - 13. J Donald May 22, 2021 I've always wondered if/ how LinkedIn validates that a person's stated employer really is their employer. I suspect I could claim to work for, say, Goldman Sachs, and no one would call me on it. If I were then to pose as a hiring manager, or an HR staffer.... Reply - Leave a Reply Cancel reply Your email address will not be published. Required fields are marked * [ ] [ ] [ ] [ ] [ ] [ ] [ ] Comment [ ] Name * [ ] Email * [ ] Website [ ] [Post Comment] [ ] [ ] [ ] [ ] [ ] [ ] [ ] [ ] Advertisement [15] Advertisement [110] Mailing List Subscribe here Search KrebsOnSecurity Search for: [ ] [Search] Recent Posts * How to Tell a Job Offer from an ID Theft Trap * Recycle Your Phone, Sure, But Maybe Not Your Number * Try This One Weird Trick Russian Hackers Hate * DarkSide Ransomware Gang Quits After Servers, Bitcoin Stash Seized * Microsoft Patch Tuesday, May 2021 Edition Spam Nation Spam Nation A New York Times Bestseller! All About Skimmers All About Skimmers Click image for my skimmer series. Story Categories * A Little Sunshine * All About Skimmers * Ashley Madison breach * Breadcrumbs * Data Breaches * DDoS-for-Hire * Employment Fraud * How to Break Into Security * Latest Warnings * Ne'er-Do-Well News * Other * Pharma Wars * Ransomware * Security Tools * SIM Swapping * Spam Nation * Target: Small Businesses * Tax Refund Fraud * The Coming Storm * Time to Patch * Web Fraud 2.0 The Value of a Hacked PC valuehackedpc Badguy uses for your PC Badguy Uses for Your Email Badguy Uses for Your Email Your email account may be worth far more than you imagine. Donate to Krebs On Security Most Popular Posts * Sextortion Scam Uses Recipient's Hacked Passwords (1076) * Online Cheating Site AshleyMadison Hacked (798) * Sources: Target Investigating Data Breach (620) * Trump Fires Security Chief Christopher Krebs (534) * Cards Stolen in Target Breach Flood Underground Markets (445) * Reports: Liberty Reserve Founder Arrested, Site Shuttered (416) * Was the Ashley Madison Database Leaked? (376) * DDoS-Guard To Forfeit Internet Space Occupied by Parler (374) * True Goodbye: 'Using TrueCrypt Is Not Secure' (363) * Who Hacked Ashley Madison? (361) Why So Many Top Hackers Hail from Russia [computered-580x389] Category: Web Fraud 2.0 Criminnovations Innovations from the Underground [shreddedID-copy-285x189] ID Protection Services Examined Is Antivirus Dead? Is Antivirus Dead? The reasons for its decline The Growing Tax Fraud Menace The Growing Tax Fraud Menace File 'em Before the Bad Guys Can Inside a Carding Shop Inside a Carding Shop A crash course in carding. Beware Social Security Fraud Beware Social Security Fraud Sign up, or Be Signed Up! How Was Your Card Stolen? How Was Your Card Stolen? Finding out is not so easy. Krebs's 3 Rules... Krebs's 3 Rules... ...For Online Safety. (c) Krebs on Security