Scammers Used Fake Job Ads to Steal Credentials

Job seekers in marketing and communications are being targeted by credential-harvesting schemes.

Updated on Oct. 2, 2026 in Job Search

Isometric editorial illustration of a brass latch mechanism on a geometric data lattice, representing digital security threats.
Scammers are impersonating major brands to host fake interview portals, allowing them to harvest corporate authentication credentials from job applicants. AI Illustration. Upload story photo >

Live Poll

Do you feel confident in your ability to identify a fraudulent job advertisement online?

Fraudsters have impersonated brands like Disney and Coca-Cola to lure job candidates into fake interview portals. These scams capture real-time authentication codes by mimicking legitimate scheduling tools.

Why it matters

The scheme exploits the high-pressure nature of job hunting, where applicants are prone to lowered vigilance. Successful attacks provide bad actors with access to corporate email and advertising systems through compromised accounts.

Attackers leverage typo-squatting by changing 1 or 2 letters in domain names compared to official corporate sites. The scale of the breach is currently unknown, though LinkedIn reported receiving new scam notifications regarding these tactics.

The players

Disney

A multinational mass media and entertainment conglomerate.

Coca-Cola

A global beverage corporation and manufacturer of branded consumer goods.

LinkedIn

A professional networking platform owned by Microsoft that serves as a primary hub for recruitment.

The details

Scammers register lookalike domains to host fake interview scheduling pages that mimic services like Calendly. When candidates attempt to book an interview, they are prompted to authenticate via Google or Facebook through a fraudulent login window. This process allows attackers to bypass security and scrape authentication credentials in real time.

Timeline

  1. A scam was reported to LinkedIn in September 2026.

Market Landscape

This scam follows a documented pattern of credential-harvesting attacks that leverage typo-squatting to compromise corporate credentials. The tactics represent a persistent shift toward exploiting the trust established by major brands during the recruitment process.

Hiring managers should audit their external-facing recruitment links to ensure no lookalike domains are impersonating their brand. Job seekers must verify the URL of every scheduling portal before entering login credentials.

The takeaway

The urgency of a job search is a vulnerability that hackers actively exploit to compromise company networks. Standardize your recruiting process by using only verified, official company domains for all interview scheduling.

Further reading

For more on vetting potential employers and safeguarding your professional identity, visit Job Search.

Live Poll

Do you feel confident in your ability to identify a fraudulent job advertisement online?