Scammers Used Fake Job Ads to Steal Credentials
Job seekers in marketing and communications are being targeted by credential-harvesting schemes.
Updated on Oct. 2, 2026 in Job Search

Live Poll
Do you feel confident in your ability to identify a fraudulent job advertisement online?
Fraudsters have impersonated brands like Disney and Coca-Cola to lure job candidates into fake interview portals. These scams capture real-time authentication codes by mimicking legitimate scheduling tools.
Why it matters
The scheme exploits the high-pressure nature of job hunting, where applicants are prone to lowered vigilance. Successful attacks provide bad actors with access to corporate email and advertising systems through compromised accounts.
Attackers leverage typo-squatting by changing 1 or 2 letters in domain names compared to official corporate sites. The scale of the breach is currently unknown, though LinkedIn reported receiving new scam notifications regarding these tactics.
The players
Disney
A multinational mass media and entertainment conglomerate.
Coca-Cola
A global beverage corporation and manufacturer of branded consumer goods.
A professional networking platform owned by Microsoft that serves as a primary hub for recruitment.
The details
Scammers register lookalike domains to host fake interview scheduling pages that mimic services like Calendly. When candidates attempt to book an interview, they are prompted to authenticate via Google or Facebook through a fraudulent login window. This process allows attackers to bypass security and scrape authentication credentials in real time.
Timeline
A scam was reported to LinkedIn in September 2026.
Market Landscape
This scam follows a documented pattern of credential-harvesting attacks that leverage typo-squatting to compromise corporate credentials. The tactics represent a persistent shift toward exploiting the trust established by major brands during the recruitment process.
Hiring managers should audit their external-facing recruitment links to ensure no lookalike domains are impersonating their brand. Job seekers must verify the URL of every scheduling portal before entering login credentials.
The takeaway
The urgency of a job search is a vulnerability that hackers actively exploit to compromise company networks. Standardize your recruiting process by using only verified, official company domains for all interview scheduling.
Further reading
For more on vetting potential employers and safeguarding your professional identity, visit Job Search.
Live Poll
Do you feel confident in your ability to identify a fraudulent job advertisement online?






