Jobseekers are facing a growing threat from sophisticated scammers who pose as recruiters on professional networking sites, luring candidates into downloading malicious software disguised as legitimate interview tools. One victim had £18,000 in cryptocurrency stolen within hours of downloading what appeared to be a standard assessment document during a fake job interview process.
The victim, who requested anonymity, was approached on LinkedIn by someone claiming to represent a real employer. After a seemingly authentic video interview, the fake recruiter asked them to complete a technical assessment using a Google Sheet document. Unknown to the candidate, the file contained malware that gave hackers access to their digital wallets and financial accounts.
"It's a horrible feeling to be out a substantial amount - something I wouldn't wish on my worst enemy," the victim said.
After waking to discover their savings gone, the victim took immediate action to contain the damage.
"I wiped my computer and changed all my passwords and was exhausted emotionally and mentally drained. I felt a mixture of disbelief and anger - at the hackers and at myself. I was also confused until I figured out how they had got me."
Why younger jobseekers are particularly vulnerable
Young professionals face disproportionate risk from recruitment fraud, according to data released by LinkedIn. The platform found that 32% of younger professionals encounter scams, yet nearly a third of them ignore warning signs because they feel pressured by an intensely competitive employment landscape. When the platform was approached for comment, representatives explained that in a crowded job market,
"many young people feel they can't afford to be skeptical... because they feel opportunities are so scarce."
This vulnerability is compounded by the sophistication of modern attacks. Cyber-security researcher Charlie Kelly from Have I Been Squatted analysed the case and noted that the scam bore none of the hallmarks of typical fraud attempts.
"This wasn't a badly written email with a suspicious attachment - this person was walked through what looked like a real job interview, on real Google pages, behind a real Google login, and the software they were asked to install was digitally signed like any legitimate app."
The pressure and excitement surrounding job opportunities makes candidates less cautious. According to security firm Fireblocks, the tactic has been used in campaigns linked to North Korean hackers, who targeted developers and cryptocurrency infrastructure professionals through fraudulent LinkedIn interviews in January 2026. The attackers used a pattern known as "Contagious Interview," associated with the Lazarus Group, demonstrating that these scams operate at an organised, international level.
How the malicious apps work
Criminals are exploiting job listing platforms by creating fake applications that mimic legitimate interview software. On Indeed, scammers have distributed fraudulent apps with names like a counterfeit Indeed Interview tool and one called MyInterview. According to cyber-security company Malwarebytes, the fake recruiters use persuasive language to encourage downloads, such as "Complete your interview by installing the Indeed app" or "salary agreement available after app installation."
Once installed, these malicious applications grant hackers access to private data stored on the victim's device. This information can be used for extortion or to launch financial attacks on bank accounts and cryptocurrency wallets. Indeed has been explicit in its guidance:
"Interviewing through Indeed's platform happens entirely in a browser and never requires downloading a special app. Any message asking a job seeker to download an app to participate in an interview is not legitimate."
The victim in this case had handed in their notice at their previous job and made their job-seeking status visible on LinkedIn, making them an obvious target. The scammer's approach was methodical: a direct message with a job offer, followed by a video call to build credibility, then a request to complete a technical assessment that would deliver the malware payload.
What platforms are doing to combat the threat
Both LinkedIn and Indeed have issued warnings and published guidance to help jobseekers identify fraudulent recruitment attempts. LinkedIn recommends verifying that both the company and the specific job listing are genuine, conducting thorough research before engaging with recruiters, and checking for verification badges on company pages and recruiter profiles. The platform's 2026 Job Search Safety Pulse provides detailed verification steps for candidates.
LinkedIn stated that it removes over 98% of scam-related content before users encounter it, according to a 2026 report. However, the sheer volume of fraudulent activity means some malicious content still reaches jobseekers. The platform acknowledged the scale of the problem in a crowded employment market where candidates feel they cannot afford to be cautious.
New detection tools are emerging to address the problem. HireID launched an Interview Integrity Platform in August 2026 that monitors more than 20 fraud signals during live interviews on Zoom, Google Meet, and Microsoft Teams, offering employers and candidates an additional layer of protection.
Red flags to watch for in recruitment communications
Jobseekers should be alert to several warning signs that indicate a recruitment approach may be fraudulent. Recruiters with minimal activity on their profiles, pressure to move conversations away from official platforms to messaging apps like WhatsApp, requests to download software or apps to participate in interviews, and cloned company pages are all common tactics used by scammers.
The competitive nature of today's job market makes candidates vulnerable to these tactics. Many jobseekers feel they cannot risk dismissing any opportunity, even when something feels unusual. However, legitimate employers conduct interviews through their official platforms and never require candidates to download third-party software to participate in the hiring process.
The victim's experience demonstrates how quickly and completely scammers can compromise financial accounts once they gain access to a device. The emotional toll extends beyond the financial loss, leaving victims feeling violated and questioning their own judgment.

Key facts
- A jobseeker lost £18,000 in cryptocurrency savings after downloading malware disguised as a technical assessment document during a fake LinkedIn interview
- 32% of younger professionals face exposure to recruitment scams, with nearly a third admitting they ignore red flags due to competitive job market pressures
- Scammers use sophisticated tactics including real Google pages, legitimate-looking digital signatures, and video calls to build credibility before delivering malware
- Legitimate job interviews on platforms like Indeed and LinkedIn occur entirely in browsers and never require downloading special applications
- International criminal groups, including those linked to North Korea, have been identified using fake recruitment interviews to target developers and cryptocurrency professionals






