← All articles

Field record

Software EngineeringJob HuntingCybersecurity

Scams in Job Hunting (2026)

Job hunting for engineers comes with scams as well.

An adversary in a steampunk hot-air balloon watches a job hunter through a spyglass and dangles an ornate fish on a hook between the hunter and office towers representing job postings

Finding a new project is stressful enough on its own. And this is probably why attackers won't leave job hunters alone—at least software engineers. This is a little bit funny, as these are people who are usually more aware of bad practices and can spot a scam early.

So what's going on right now? First, I will describe what I personally encountered, and then what I was warned about.

Your resume needs a special format, and only we can do it properly

I got a message from a "recruiter": nice compensation, interesting company. The first messages looked normal. Then he asked if I had my resume in XXX format. When I said no, he pointed me to his colleague, who would help me.

But instead of an introduction to a colleague, I got a link to a Zoom/Microsoft Teams meeting where an agent would help me! As I am in a different time zone, my response was, "OK, I will reach out to him tomorrow." And then it started: "You should do it ASAP." The first red flag: urgency. It didn't take long.

When I responded that I didn't like the urgency and would create the CV myself (with AI, of course), the tone shifted to "You should let professionals do it," because "Your career depends on it." The second red flag.

When I started looking into the recruiter, I found that:

  • He was based in Japan and was finding engineers for Europe. (I saw this at the beginning, but people relocate and work remotely, right?)
  • His profile was created the same day he reached out to me.

And as for the company (it's a well-known company):

  • There was no job posting on the official website.

At this point, I knew what was going on. But I was curious about the nature of the scam.

And it's simple: they will sell you a specialized, stamped version of your resume for one or two hundred dollars. It's useless, and you can probably create it yourself. But I also had another potential attack in mind:

Is joining a random Zoom/Microsoft Teams meeting dangerous?

Technically, no, but during those meetings, an attacker could send you a file, either directly or through a download link—with malware, of course—and steal anything he can.

This leads me to the second method.

Malicious take-home assessment

The second round of a technical interview: download this GitHub repo, run the whole project, and complete the assignment.

The hidden malicious code steals credentials, API tokens, wallets, or access to company systems.

I haven't encountered this yet, but here is evidence: https://www.atlassian.com/blog/how-we-build/disrupting-contagious-interview.

Whether it's a take-home assessment or a new hobby project we download, before running an unknown repo:

You can ask your AI to check the codebase for suspicious or malicious code without running the project.

Current frontier models should be able to spot it and warn you in time.

Fix the interview software

During a technical interview, the recruiter asks you to download and execute a file supposedly needed to resolve a video-call error. It installs malware.

You should never use "random" files offered by anybody to try to fix "interview" software. If there is an issue, switch to different software or update the software from its official website or an app store. And don't run terminal commands, grant remote access, or disable security protection to "fix" an interview.

Fictional project

My Job Hunting AI Agent found an interesting project. I filled out a form and pressed submit. "Job not found" popped up in red below the form. Right next to it was "careers@xxx".

So I opened Gmail and wrote a message, even adding a funny line: "The error on your site won't stop me from solving your problem: hiring a senior engineer."

The response from the remote server was:
550 5.1.1 User does not exist -

I tried the general email address with the same result.

I looked at the /about page, copied the CEO's name, and pasted it into LinkedIn. There were a couple of similar names, but no one mentioned the project. The same went for the CTO.

I asked the AI to look at the about page, try to find the people, and examine the project closely. Here's what it found:

  • The people mentioned on the site exist on LinkedIn (or at least people with the same names do), but nothing connects them to the project.
  • The project was founded three years before the domain was registered (but rebranding happens).
  • The site claimed a team of 47 people, who were nowhere to be found.
  • The site claimed €4M in seed funding in 2023 and an €11M Series A in early 2025.

In the end, it looks like a nice presentation page, but no real project at all. Maybe it is a scam, or preparation for a scam. Who knows?

Final note?

Attackers are not breaking in—they are signing in. And for that, they need to steal your credentials first. They do this with malware: software installed on your device behind your back through a random file. Pay attention to what you are downloading and who sent you the file.

Stay safe, and see you next Monday.