惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
G
Google Developers Blog
Blog — PlanetScale
Blog — PlanetScale
U
Unit 42
A
About on SuperTechFans
Vercel News
Vercel News
B
Blog
Martin Fowler
Martin Fowler
MyScale Blog
MyScale Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
腾讯CDC
D
Docker
V
Visual Studio Blog
博客园 - 叶小钗
The Cloudflare Blog
Jina AI
Jina AI
B
Blog RSS Feed
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
WordPress大学
WordPress大学
T
Tailwind CSS Blog
MongoDB | Blog
MongoDB | Blog
D
DataBreaches.Net
月光博客
月光博客
大猫的无限游戏
大猫的无限游戏

Consumer Insights

The ransomware negotiator who was working for the other side After years on the run, alleged Ryuk ransomware operator pleads guilty INTERPOL crackdown shows scammers shifting to social media Meta lets strangers remix your public Instagram photos with AI—here’s how to opt out Two arrested over credit card phishing - as the Netherlands is named Europe's worst for payment fraud India pauses WhatsApp username feature over security concerns Alleged teen ransomware hustler faces US charges after arrest in Finland WhatsApp usernames explained: how to reserve yours and stay safe Scammers race to cash in on Venezuelan earthquake disaster USB drives carrying China-linked malware infected Japanese military networks for nearly a year WhatsApp tests new safety prompt before you chat with strangers Social media is worth celebrating. It's also worth protecting. Polish police dismantle SIM-swap gang accused of crypto theft Operation Endgame deals fresh blow to StealC and Amadey malware networks Hacker hijacks Brazil's national alert system, sending "misanthropy" to millions of phones Cybercrime now rivals traditional crime across parts of Asia Apple's Hide My Email tweak leaves privacy fans fuming Americans lost $3.5 billion to imposter scams last year — and the scams are getting harder to spot Scammers have killed the physical Steam Gift cards Crypto investment scam sends couriers to collect victims' cash, FBI warns Maine forced to take down data breach portal after fake notices filed with authorities Privacy own-goal: World Cup blunder leaks Lionel Messi's passport details Why schools remain one of cybercriminals' favourite targets WhatsApp detects new spyware activity from Israel’s NSO Group despite court order Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5 Europol cracks down on illegal streaming globally Hackers didn't hack Instagram; they just asked Meta AI FBI Warns Fans About FIFA Scams Ahead of 2026 World Cup Virtual knife, real lawsuit: Counter-Strike skin dispute ends in court As Deepfakes Spread, YouTube Makes AI Labels Harder to Miss
Invited to a "job interview" with Netflix or OpenAI? Bewa...
Graham CLULEY · 2026-07-09 · via Consumer Insights

Have you received an email from a recruiter at Adobe, Netflix, or OpenAI offering you an exciting new marketing role? Well, before you start brushing up your interview technique, take a closer look at who is really behind it.

Security experts have uncovered a phishing campaign which impersonates over 30 well-known brands in fake job interviews designed to steal Google account passwords.

Will Thomas, a threat intelligence researcher Team Cymru, identified malicious domains that spoof household names including Adidas, Adobe, American Airlines, Aquent, Booking.com, Coca-Cola, Delta Air Lines, FIFA, Levis, Louis Vuitton, ManpowerGroup, Marriott, McKinsey & Company, Netflix, Omnicom Group, OpenAI, PepsiCo, Red Bull, Sephora, and United Airlines.

What makes the campaign more dangerous is its attention to detail. Rather than using a generic "Dear Job Candidate" email, the attackers appear to have done their homework (most likely via via LinkedIn) addressing recipients by name and targeting people who work in the relevant field.

Furthermore, the attacks use the names and photographs of genuine recruiters at the impersonated firms. In other words, the messages do not just claim to come from a particular company, but also appear to come from a specific, real, named person who works in recruitment at the business.

Thomas says that the emails appear to have been sent via PeopleForce, a legitimate HR and applicant tracking platform. Meanwhile, links in the emails bounce through a variety of trusted domains before ultimately landing on a phishing webpage.

The landing page invites job applicants to a calendar scheduling tool, and prompts them to sign in with their Google account to book an interview slot.

When victims click on "Continue with Google," a pop-up appears that looks like a legitimate Google authentication dialog.

The reality is that the pop-up is a browser-in-the-browser attack, and any login details entered go straight to cybercriminals.

It's worth noting that if you are using a good password manager it will refuse to auto-fill your credentials into the phishing pop-up, because it will recognise that the underlying domain is not one that belongs to Google.

As Bleeping Computer reports, the campaign has been running for at least five months, potentially tricking many people.

Recruitment scams have been around for years, but it is evident that they are becoming more sophisticated and targeted in their attempt to lure in more victims.

In the past the FBI has warned the public about scammers using fake job ads to steal money and personal information from applicants.

We cannot ignore that changes in the workplace play their part in making recruitment scams like this more successful.

More companies are laying off staff, citing artificial intelligence as the reason why they are slimming down their workforce.

Marketing departments - which rely heavily on content creation - are amongst those who are feeling the pressure, and when people are worried about their job security, an unsolicited email from a well-known brand offering an exciting new position can feel irresistible.

Earlier this year, Hot for Security published a guide explaining how many fake recruiter scams work, and how to avoid them.