FAKE Disney and Coca-Cola job interview invitations are being used to steal passwords and workplace logins in a phishing campaign spanning more than 800 scam domains.
Cybersecurity researchers at NordVPN have linked 813 phishing domains to an operation impersonating recruiters from more than 75 major companies, including Disney, Nike, Coca-Cola, Nvidia, Adidas, Adobe and Booking.com.
The scam can begin with an email, LinkedIn message or Facebook approach from someone posing as a recruiter. In some cases, criminals appear to have copied the name and photograph of a genuine employee from LinkedIn.
Job hunters are then directed to a branded page resembling Calendly to arrange an interview before being asked to sign in with Google or Facebook.
NordVPN says the apparent login window, including its address bar and security padlock, can be faked. Passwords and verification codes entered by the victim can then be intercepted in real time, potentially opening up workplace email, advertising accounts and corporate social media profiles.
The campaign appears to have particularly targeted people working in marketing and communications, where a compromised account could give criminals access to valuable company systems and advertising budgets.
Adrianus Warmenhoven, cybersecurity adviser at NordVPN, said job interviews provide scammers with an unusually convincing pretext because applicants expect to communicate with strangers, follow instructions and provide information about themselves.
He said: “A branded page can closely resemble a genuine Calendly invitation before presenting what appears to be a Google or Facebook login window. In reality, that window is built into the scam page, meaning even the address bar and security padlock can be faked.”
Daniel Mohacek, CEO of Truth Engine, said the fraud works by borrowing the credibility of brands and real people that applicants already recognise.
A company logo, genuine employee photograph or apparently credible LinkedIn profile can lower a jobseeker’s guard before they have checked who is actually behind the approach.
Mohacek said: “Something looking credible is not proof that it is genuine. Fraudulent recruiters operating on LinkedIn may even have fake endorsements to add a layer of credibility.”
He urged jobseekers to check unexpected approaches independently, including confirming that the vacancy appears on the company’s official website and using contact details sourced themselves rather than those supplied by the supposed recruiter.
How to spot a fake recruiter
Kate Underwood, Founder & Chief People Strategist at Southampton-based Kate Underwood HR and Training, said recruitment scams were becoming increasingly sophisticated and preyed on people worn down by the job hunt.
The use of real recruiters’ names and photographs, convincing company branding and realistic login pages makes that initial approach particularly difficult to question, she said.
Underwood added: “This isn’t phishing for your CV. It’s phishing for your whole digital life.”
She advised applicants never to use a Google or Facebook login window that appears inside another website, and instead to open a new tab and go directly to the employer’s careers page.
Francis West, CEO at Security Everywhere, said he sees variations of recruitment scams every month, involving recruitment agencies as well as household-name employers.
He added: “These scams are very common, I see variations every month, not just with big brands but recruitment agencies too. They work because job hunting puts people in exactly the mental state scammers want: hopeful, anxious, and moving fast so they do not miss out. Nobody double-checks a login page when they think Disney just offered them an interview.
“It targets anyone job hunting, but hits hardest with people newer to the market or out of work a while, where the excitement of a big name wanting them overrides caution. My advice: never log in via a link in an unsolicited message, go straight to the company careers site instead.
“Real interview scheduling almost never asks you to log in, just to pick a time. If in doubt, call the company switchboard and ask if they really invited you. In phishing tests we run at Security Everywhere, a fake booking page skinned like Calendly is the one that catches people even when they know it is a test.”
Pay the price
Career coach Amelia Brooke, of Amelia Brooke Career Vision, said she had reported a suspected recruitment scam on LinkedIn just last week.
She added: “It’s extremely common. Just last week, I reported one to LinkedIn. Scammers exploit the excitement of an interview from a major global brand.
“The most common technique I have spotted is typo-squatting, where scammers deliberately alter company names by a letter or two – like Deloitt, PwC-Global-Careers, or KPMG-Jobs to catch the attention of candidates who might not realise the domain or name is slightly off.
“Advice: Don’t just scroll past them when you see them. Just because you notice a scam doesn’t mean others will. So, on LinkedIn, click “Report Post” > “It’s suspicious or spam” > “Scam or fraud” to alert their security team to take down the posts, links, and burner profiles before other job seekers get lured in.”
The consequences may also extend beyond the person applying for the fake job.
Harvey Dhillon, Founder & CEO at Zmartly, said a compromised work login belonging to somebody in marketing or communications could also expose company advertising accounts containing stored payment details.
He added: “Job scams work because the login matters, not the person. Reporting on the campaign says those approached work in marketing and comms, whose login often opens an ads account with a payment method on it.
“Spotting the fake page is a security specialist’s call, not mine, but the bill afterwards isn’t. Under Meta’s terms you are charged for any orders placed through your ad account, so the bill starts with the employer.
“Cap the ad account’s total spend and store no card on it. If you are the one job hunting, never sign in to an interview booking page with the work account that has ads access. The person who clicked isn’t the one who pays.”
Scam
Kelly Smallcombe, Fractional Chief People Officer at Meliorem HR Consultancy, said applicants should check whether an approach makes sense when compared with the employer’s usual recruitment process.
She added: “Recruitment scams like this are everywhere, and job seekers are an easy target. Desperation does the scammer’s work for them, when someone’s chasing a well known employer, name recognition switches off their scepticism. To spot these, check how that employer actually recruits.
“Large companies list their applicant tracking system on their careers page, so a booking link that doesn’t match is a red flag straight away. Genuine recruiters aren’t sourcing candidates through Facebook, they’re on LinkedIn or major job boards, and that’s also where they’ll have found your details.
“Ask yourself how they could plausibly have found you and why. Then verify the role itself, is it live on the company website, do you actually meet the requirements. Big employers get hundreds of applicants per vacancy, they are not chasing candidates down frequently.”


