
Cybercriminals are using increasingly convincing fake job interviews to gain access to personal and business computers.
In a recently reported incident, a supposed recruiter contacted a job seeker through LinkedIn about a promising technology position. The process appeared legitimate, including a scheduled video interview and a discussion about the company. During the call, however, the interviewer asked the applicant to download code from GitHub, run it on the computer, and share the screen.
The applicant became suspicious and had the code examined. It reportedly contained serious security vulnerabilities that could have exposed passwords, files, financial information, company data, and access credentials.
This is a form of phishing known as social engineering. Instead of relying on an obviously suspicious email, the attacker builds trust through a realistic opportunity before asking the victim to download a file, install software, run code, share a screen, or provide login information.
Warning signs include:
- A recruiter who cannot be independently verified
- An interviewer who refuses to appear on camera
- Pressure to download or run unfamiliar files
- Requests to share your entire computer screen
- Links sent through chat rather than an official company system
- Requests for passwords, verification codes, banking information, or identification documents early in the hiring process
Never run unfamiliar software or code on a personal or company computer. Verify the recruiter through the employer’s official website and contact the company using a publicly listed phone number or email address. Keep your operating system and security software updated, use unique passwords, enable multifactor authentication, and conduct technical evaluations only on an isolated test computer when appropriate.
If you believe you may have downloaded something malicious, disconnect the computer from the internet, notify your employer or IT department immediately, change important passwords from a different trusted device, and have the affected system professionally examined.
The most effective protection is often a brief pause. If a request feels unusual, stop and verify it before clicking, downloading, or sharing anything.
Written by Garry Lodoen
Operations Manager, Licensed Private Detective
Alaska Investigations Group
