Copy article

Job hunters warned about fake Coca-Cola and Disney interview invitations

ended 23. September 2026

Job hunters are being warned about fake interview invitations which can hand criminals access to their employer’s emails, advertising accounts and social media pages.

NordVPN’s Threat Intelligence team uncovered an organised phishing campaign impersonating recruiters from more than 75 brands, including Disney, Nike, Coca-Cola, Nvidia, Adidas, Adobe and Booking.com.

The approach can begin with an email, LinkedIn message or Facebook message from somebody posing as a member of a company’s recruitment team. In some cases, the name and photograph belong to a genuine employee and appear to have been copied from LinkedIn.

Targets are then sent what appears to be a routine invitation to schedule an interview. The booking page closely resembles Calendly and may carry the colours and logo of the company offering the supposed job.

After choosing a time, the applicant is asked to sign in with Google or Facebook. The login box looks like a separate browser window, complete with an address bar, padlock, and a genuine-looking web address. In fact, it is part of the scam page.

  • How common are these scams?
  • Why do you think they work? Who are they targeting?
  • What advice do you have for people to avoid these scams?

Responses by tomorrow.

7 responses from the Newspage community

Copy all

Copy

Nothing counts these under their own name, which is the honest answer to how common they are. The ONS crime survey and the Home Office fraud strategy have no category for fake recruiter scams. The nearest official label lumps a promise of employment in with lottery and inheritance scams. Not giving job scams a count of their own is the wrong call. They work because the login matters, not the person. Reporting on the campaign says those approached work in marketing and comms, whose login often opens an ads account with a payment method on it. Spotting the fake page is a security specialist's call, not mine, but the bill afterwards isn't. Under Meta's terms you are charged for any orders placed through your ad account, so the bill starts with the employer. Cap the ad account's total spend and store no card on it. If you are the one job hunting, never sign in to an interview booking page with the work account that has ads access. The person who clicked isn't the one who pays.
Copy

How common? Very, and getting slicker by the month. NordVPN caught this crew spoofing over 75 real brands. Simple reason it works: job hunting wears people down, and a shiny "you got the interview" email is candy to someone who's been rejected all month.
Why does it land? It's a wolf dressed as a fairy princess. Real recruiter's name, real photo, ripped straight off LinkedIn. Even the login box looks legit, padlock and all. Nobody checks a costume that good.
This isn't phishing for your CV. It's phishing for your whole digital life.
My advice: never log in through a Google or Facebook box that's popped up inside someone else's page. New tab, straight to the company's real careers site, every time. Check the email domain, not the name on the tin. If a stranger's this desperate to get you logged in, ask why. The prettier the invite, the harder you should look for teeth.
Copy

The more we lean on impersonal tech for convenience, the more inconvenient life gets. This scam proves it. The fix is twofold: better security, though it'll always be playing catch-up with con-artists, and, dare I say it, doing business the old-fashioned way: person to person, face to face, with people you know, like and trust. Slower, more effort, but it pays off well beyond dodging phishing. Recruitment phishing is accelerating with automated kits now impersonating 75+ global brands, posing as recruiters who scrape identities from LinkedIn and steer candidates to fake Calendly-style booking pages. Browser-in-the-Browser kits fake the whole login window, padlock and URL included to harvest SSO credentials and reach Google Workspace, corporate socials and ad budgets. Never log in via Google or Facebook to book an interview, verify emails come from official domains, apply direct through the firm's careers page, and drag any login pop-up. If it won't leave the browser, it's fake.
Copy

These scams are very common, I see variations every month, not just with big brands but recruitment agencies too. They work because job hunting puts people in exactly the mental state scammers want: hopeful, anxious, and moving fast so they do not miss out. Nobody double-checks a login page when they think Disney just offered them an interview. It targets anyone job hunting, but hits hardest with people newer to the market or out of work a while, where the excitement of a big name wanting them overrides caution. My advice: never log in via a link in an unsolicited message, go straight to the company careers site instead. Real interview scheduling almost never asks you to log in, just to pick a time. If in doubt, call the company switchboard and ask if they really invited you. In phishing tests we run at Security Everywhere, a fake booking page skinned like Calendly is the one that catches people even when they know it is a test.
Copy

How Common? Extremely common. Just last week, I reported one to LinkedIn. Sadly, millions of fraudulent recruitment posts and messages circulate daily, making job-search scams one of the fastest-growing categories of online fraud I see on platforms like Reddit and that BBC's You and Yours frequently reports.

Scammers exploit the excitement of an interview from a major global brand. The most common technique I have spotted is typo-squatting, where scammers deliberately alter company names by a letter or two—like Deloitt, PwC-Global-Careers, or KPMG-Jobs to catch the attention of candidates who might not realise the domain or name is slightly off.

Advice: Don't just scroll past them when you see them. Just because you notice a scam doesn't mean others will. So, on LinkedIn, click "Report Post" > "It's suspicious or spam" > "Scam or fraud" to alert their security team to take down the posts, links, and burner profiles before other job seekers get lured in.
Copy

Recruitment scams like this are everywhere, and job seekers are an easy target. Desperation does the scammer's work for them, when someone's chasing a well known employer, name recognition switches off their scepticism. To spot these, check how that employer actually recruits. Large companies list their applicant tracking system on their careers page, so a booking link that doesn't match is a red flag straight away. Genuine recruiters aren't sourcing candidates through Facebook, they're on LinkedIn or major job boards, and that's also where they'll have found your details. Ask yourself how they could plausibly have found you and why. Then verify the role itself, is it live on the company website, do you actually meet the requirements. Big employers get hundreds of applicants per vacancy, they are not chasing candidates down frequently.
Copy

Recruitment scams prey on the desperation of out-of-work job seekers, which makes them a vulnerable target. There are many versions – for example they may force you to pay for a new CV before moving your application the next stage, require payment for WFH equipment or training, or simply create fake jobs to harvest personal data from your CV.

Job seekers should look out for red flags including initial contact from a gmail address, a request to move the conversation to WhatsApp, a too-good-to-be-true offer, and vague job requirements such as “good communication skills”.

Before progressing an application, check the recruiter’s email address and LinkedIn presence, confirm the job exists on the company website, don’t share personal information until you’ve met the recruiter, and above all don’t give in to the sense of urgency these scammers create. Recruitment processes take time. If you’re feeling under pressure to act quickly, step back and ask why. Never part with money to get a job.