Advanced Job hunt skill
Respond to a recruitment fraud incident
Respond to recruitment fraud by protecting affected candidates, scoping impersonation and access, preserving evidence, containing channels, and verifying recovery.
Protect people before optimizing brand response.
When to use
- Use for fake jobs, lookalike domains, fraudulent offers, advance-fee scams, identity-document collection, fake interviews, recruiter account compromise, candidate impersonation, or hiring-platform abuse.
- Use
respond-to-resume-identity-theftwhen the central victim is one professional whose identity and career materials were copied.
Preconditions
- Activate security, recruiting, privacy, legal, communications, support, domain, platform, payment, and affected-person authority with an incident lead.
- Preserve messages, headers, domains, DNS, sites, phone numbers, accounts, job posts, forms, payment requests, documents requested, platform logs, access events, and public reports with provenance.
- Establish safe verified contact channels outside the suspected accounts and minimize circulation of victim identity documents.
Procedure
- Provide immediate victim protection: tell candidates to stop payment and data transfer, preserve evidence, use independent employer contacts, and take proportionate account, financial, identity, or device protection steps.
- Publish a concise verified warning on controlled channels that describes known indicators and safe application routes without blaming victims or exposing unnecessary data.
- Build the incident scope across employer brands, roles, regions, languages, domains, subdomains, email, messaging, phone, video, advertisements, social accounts, payment destinations, forms, and impersonated staff.
- Determine whether attackers only copied public material or also compromised recruiter, email, ATS, identity, domain, vendor, or employee accounts.
- Establish evidence preservation with a synchronized chronology and evidence ledger linking each artifact, source, time, hash where useful, custody, access, and investigative action.
- Preserve restricted originals, but redact identity documents, financial data, credentials, and private messages from ordinary coordination records.
- Coordinate containment and recovery for controlled infrastructure: revoke sessions and tokens, reset recovery, repair forwarding and delegation, rotate affected credentials, remove malicious posts, block known channels, and freeze fraudulent payment routes where authorized.
- Coordinate domain registrar, hosting, search, platform, telecom, payment, and law-enforcement reports through documented owners. Keep copies because takedown can destroy public evidence.
- Reconcile impersonation and victim exposure: who was contacted, what they disclosed or paid, which credentials or documents were collected, what accounts were created, and what harmful actions remain possible.
- Notify affected people through verified channels with specific known exposure, actions, support, deadlines, and a correction route. Do not overstate takedown or recovery.
- Restore recruiting from known-good accounts and configuration; verify job postings, domains, sender authentication, forms, candidate portals, access, alerts, and staff escalation.
- Provide a canonical offer-verification page reached independently from the official careers domain. Let a candidate check a non-sensitive offer identifier, role status, authorized recruiter channel, and verified payment or equipment policy without exposing candidate data.
- Monitor re-registration, copycat domains, new ads, reused payment routes, victim reports, recruiter access, and identity misuse. Track each victim's open recovery needs.
- Close only after infrastructure, communications, victim support, regulatory duties, access restoration, and recurrence controls are independently reconciled.
Failure plan
- If a suspected recruiter channel may be compromised, do not coordinate recovery through it.
- If a takedown would erase the only evidence, preserve the minimum lawful copy first unless continuing harm requires immediate removal.
- If identity documents or account credentials were collected, treat exposure as more than a brand-impersonation issue and provide proportionate victim support.
- If scope remains uncertain, communicate confirmed facts and uncertainty instead of waiting silently or claiming containment.
Worked example
Candidates receive offers from a lookalike career domain after video interviews and are asked to pay for equipment and upload identity documents. Some postings copy real roles, and a recruiter mailbox has a new forwarding rule. The employer warns candidates through its verified site, preserves messages and access logs, revokes compromised sessions, contains malicious domains and payment routes, reconciles every known person's exposure, provides specific recovery help, restores recruiting from reviewed configuration, and monitors copycat infrastructure.
--- name: respond-to-a-recruitment-fraud-incident category: get-hired description: Respond to recruitment fraud by protecting affected candidates, scoping impersonation and access, preserving evidence, containing channels, and verifying recovery. Use when attackers impersonate an employer, recruiter, worker, candidate, or hiring platform. --- # respond-to-a-recruitment-fraud-incident Protect people before optimizing brand response. ## When to use - Use for fake jobs, lookalike domains, fraudulent offers, advance-fee scams, identity-document collection, fake interviews, recruiter account compromise, candidate impersonation, or hiring-platform abuse. - Use `respond-to-resume-identity-theft` when the central victim is one professional whose identity and career materials were copied. ## Preconditions - Activate security, recruiting, privacy, legal, communications, support, domain, platform, payment, and affected-person authority with an incident lead. - Preserve messages, headers, domains, DNS, sites, phone numbers, accounts, job posts, forms, payment requests, documents requested, platform logs, access events, and public reports with provenance. - Establish safe verified contact channels outside the suspected accounts and minimize circulation of victim identity documents. ## Procedure 1. Provide immediate **victim protection**: tell candidates to stop payment and data transfer, preserve evidence, use independent employer contacts, and take proportionate account, financial, identity, or device protection steps. 2. Publish a concise verified warning on controlled channels that describes known indicators and safe application routes without blaming victims or exposing unnecessary data. 3. Build the **incident scope** across employer brands, roles, regions, languages, domains, subdomains, email, messaging, phone, video, advertisements, social accounts, payment destinations, forms, and impersonated staff. 4. Determine whether attackers only copied public material or also compromised recruiter, email, ATS, identity, domain, vendor, or employee accounts. 5. Establish **evidence preservation** with a synchronized chronology and evidence ledger linking each artifact, source, time, hash where useful, custody, access, and investigative action. 6. Preserve restricted originals, but redact identity documents, financial data, credentials, and private messages from ordinary coordination records. 7. Coordinate **containment and recovery** for controlled infrastructure: revoke sessions and tokens, reset recovery, repair forwarding and delegation, rotate affected credentials, remove malicious posts, block known channels, and freeze fraudulent payment routes where authorized. 8. Coordinate domain registrar, hosting, search, platform, telecom, payment, and law-enforcement reports through documented owners. Keep copies because takedown can destroy public evidence. 9. Reconcile **impersonation and victim exposure**: who was contacted, what they disclosed or paid, which credentials or documents were collected, what accounts were created, and what harmful actions remain possible. 10. Notify affected people through verified channels with specific known exposure, actions, support, deadlines, and a correction route. Do not overstate takedown or recovery. 11. Restore recruiting from known-good accounts and configuration; verify job postings, domains, sender authentication, forms, candidate portals, access, alerts, and staff escalation. 12. Provide a canonical offer-verification page reached independently from the official careers domain. Let a candidate check a non-sensitive offer identifier, role status, authorized recruiter channel, and verified payment or equipment policy without exposing candidate data. 13. Monitor re-registration, copycat domains, new ads, reused payment routes, victim reports, recruiter access, and identity misuse. Track each victim's open recovery needs. 14. Close only after infrastructure, communications, victim support, regulatory duties, access restoration, and recurrence controls are independently reconciled. ## Failure plan - If a suspected recruiter channel may be compromised, do not coordinate recovery through it. - If a takedown would erase the only evidence, preserve the minimum lawful copy first unless continuing harm requires immediate removal. - If identity documents or account credentials were collected, treat exposure as more than a brand-impersonation issue and provide proportionate victim support. - If scope remains uncertain, communicate confirmed facts and uncertainty instead of waiting silently or claiming containment. ## Worked example Candidates receive offers from a lookalike career domain after video interviews and are asked to pay for equipment and upload identity documents. Some postings copy real roles, and a recruiter mailbox has a new forwarding rule. The employer warns candidates through its verified site, preserves messages and access logs, revokes compromised sessions, contains malicious domains and payment routes, reconciles every known person's exposure, provides specific recovery help, restores recruiting from reviewed configuration, and monitors copycat infrastructure. ## Done - A recruitment fraud incident timeline records reports, evidence provenance, access findings, containment, takedowns, communications, decisions, and recovery - An impersonation and victim exposure register records channels, roles, affected people, disclosed data, payments, accounts, harmful actions, notices, support, and uncertainty - A containment, notification, and recovery report verifies trusted recruiting systems, revoked access, corrected public channels, victim follow-through, external reports, monitoring, and recurrence controls