Lifehacker warns job-interview phishing
- Lifehacker issued a warning about a phishing campaign that uses fake interview invitations to steal Google credentials from job seekers and candidates. - The scam specifically targets inboxes with convincing interview invites designed to harvest login details tied to Google accounts. - For high-profile candidates and people interacting with recruiters, verifying outreach sources and avoiding credential-sharing links is critical. (lifehacker.com)
1/ Lifehacker is warning about a phishing campaign that uses fake interview invitations to steal Google account credentials from job seekers. The article, by Emily Long and published July 8, cites reporting from BleepingComputer on the campaign. (au.lifehacker.com) 2/ The lure is straightforward: an email that appears to come from a recruiter at a recognizable company. Lifehacker said the campaign impersonates brands including Adidas, Netflix, Adobe and FIFA. BleepingComputer reported the operation used more than 34 company names. (au.lifehacker.com) 3/ The targets are not random. Lifehacker said the scam primarily targets marketing professionals seeking jobs at high-value companies across tech, hospitality, travel, food, entertainment and luxury goods. (au.lifehacker.com) 4/ One reason the emails can look convincing is that the attackers appear to use the names and photos of real recruiters. Lifehacker said that makes the outreach less likely to raise suspicion if a recipient tries to verify it quickly. (au.lifehacker.com) 5/ The attack chain matters. According to Lifehacker, a victim who clicks the recruiter’s calendar link is redirected several times before landing on a malicious page dressed up as an interview scheduling site. (au.lifehacker.com) 6/ The credential theft happens at the sign-in step. Lifehacker said the page prompts the target to “sign in with Google,” then displays what looks like a Google authentication pop-up that is actually controlled by the phishing page. (au.lifehacker.com) 7/ That technique has a name: browser-in-the-browser, or BitB. Lifehacker described the fake Google pop-up as an example of a BitB attack, which is designed to make a phishing prompt look like a normal browser login window. (au.lifehacker.com) 8/ The campaign also appears to borrow trust from legitimate services. Lifehacker said the attackers seem to use the HR platform PeopleForce and a Salesforce-operated domain to start the redirect chain, though it was not clear whether those accounts were created by the attackers or accessed with stolen credentials. (au.lifehacker.com) 9/ The practical point for candidates is that a familiar brand name or a recognizable scheduling flow is not enough. Lifehacker said a calendar or application link can appear to go through legitimate infrastructure and still end at a phishing page. (au.lifehacker.com) 10/ The first red flag is unsolicited outreach. Lifehacker said candidates should be cautious with recruiter messages received by email, LinkedIn or other platforms, especially if they never applied or the role seems unusually attractive. (au.lifehacker.com) 11/ The second red flag is any request to use single sign-on just to schedule an interview or submit an application. Lifehacker said prompts for Google, Apple or Facebook credentials in that context should be treated as suspicious. (au.lifehacker.com) 12/ The safest verification step is boring but effective: leave the message and go to the employer directly. Lifehacker advised candidates to check the company’s careers page themselves rather than trusting the link embedded in recruiter outreach. (au.lifehacker.com) 13/ For executives, board candidates and other high-visibility professionals, this is also a recruiter-channel risk. Anyone who regularly hears from search firms or inbound recruiters has more reason than most to verify domains, recruiter identities and the final destination of every scheduling link. That caution is an inference from the campaign’s use of recruiter impersonation and credential prompts. (au.lifehacker.com) 14/ The broader backdrop is that job scams remain common. The Better Business Bureau says employment scams continue to target job hunters seeking work, money or personal information, which helps explain why fake recruiting workflows remain an effective lure. (bbb.org) 15/ The simplest rule here: if an interview invite ends with a Google login pop-up, stop and verify before entering anything. In this campaign, the interview was the pretext and the Google account was the prize. (au.lifehacker.com)