Fraudox FRAUDOX

Fake job offers sent in your company's name

Fake job offers in your name are brand impersonation. The impersonated company, not the defrauded candidate, is the party whose report gets the listing removed.

Fraudox Team 4 min read

The candidate loses the money. Your brand is the reason they sent it. Someone copies your job postings, borrows a real employee's name, registers a careers domain that reads like yours, and runs a plausible interview that ends in a request for payment or identity documents. The company whose name is on the offer letter is the party that can get the material removed, because impersonation reporting on job boards, social platforms and messaging apps runs through rights-owner routes that ask the filer to be the trademark or identity owner, or their agent. A defrauded candidate should still report it, but the report that closes the listing has to come from you.

How the fake offer is assembled

Assembly is cheap and repeatable, which is why the same employers get hit twice.

  1. Scraped postings. Real vacancies lifted from your careers page, reposted with the same title, location and salary band.
  2. Borrowed people. Real recruiter names taken from public profiles, sometimes a senior leader, which makes it executive impersonation once a fake VP signs the offer.
  3. A careers domain that reads correctly. A lookalike domain such as yourbrand-careers.com, with working mailboxes, so nothing arrives from free webmail.
  4. A move off platform. The conversation shifts to WhatsApp or Telegram, away from anything that logs or moderates it.
  5. The ask. An advance fee for training or visas, a deposit for equipment that never ships, or onboarding paperwork collecting passport scans, national ID, bank details and tax forms.

The paperwork version is often the real objective: an identity package opens accounts elsewhere and holds its value long after the listing is gone.

Money can be charged back. A scanned passport cannot be recalled.

Standing decides who gets the removal

Rights-owner forms for brand impersonation ask for the trademark or the official domain and a confirmation that the material is unauthorised. Only the brand holds that, which is why these scams run for weeks while candidates report them: the people holding the evidence cannot make the claim, and the party who can has not been told.

Four surfaces, four removal paths

Surface What comes down Filed with What decides the outcome
Job board listing The posting and the employer account behind it The board's trust and safety team Proof the brand is yours and the listing is not
Social profile posing as a recruiter The account or page The platform's rights-owner route Profile URL, handle and ownership evidence
Messaging app account The account, sometimes the group The app's impersonation and fraud route Uncropped chat screenshots, the handle or number
Lookalike careers domain The hosted careers page first, then the domain itself Host abuse, then registrar abuse Evidence of use in fraud, not similarity alone

Registrar abuse desks act on demonstrable fraud and stay out of trademark arguments. Where the domain is merely similar rather than actively defrauding anyone, the question of who should hold it moves to a formal dispute running on a schedule of months, and choosing whether to file one is a question for your lawyer rather than an abuse desk.

Publish how you actually hire

One control costs nothing and works on every surface: a permanent page on your own domain stating how your recruitment really operates. Name the exact domains your recruiters email from. State that you never request payment, deposits or equipment fees, and that identity documents are collected only after a signed offer, through a named system. Give a reporting address and treat what arrives there as a takedown queue, not a support inbox.

A social post cannot do this job: it scrolls away, and a candidate three months from now will not find it. A stable URL can be linked from every posting, cited in an abuse report as your authoritative position, and found by anyone searching your name with the word scam.

What to collect before you report

Three items are specific to this fraud: the offer email with full headers, any payment instructions, and the sending domain with its WHOIS record. The rest is the standard evidence pack, namely the listing and profile URLs, uncropped timestamped screenshots, and proof of your brand ownership.

Your name is doing the work in this fraud, not your infrastructure, which is why nothing in your security stack sees it and nobody outside your company can file the report that ends it. Take the four surfaces down, publish the page people can check you against, and keep watching for the next listing, because your postings can be scraped again next month.

Seeing this threat against your brand?

Fraudox removes phishing sites, impersonation accounts, fake apps, and scam domains. You only pay for successful takedowns.