Cyberheist job: Fake offers impersonate Netflix, OpenAI, and FIFA to trick job seekers into handing over their Google credentials. This cyberheist job uses realistic recruitment emails and fake interviews on platforms like Zoom to fool victims. Attackers pose as HR representatives from these well-known companies, sending links to fake job applications that steal login details.
A cyberheist job campaign from the group TA4557 leverages trusted HR tools and Google Forms to appear legitimate. The phishing emails invite targets to apply for remote positions, leading to a fraudulent interview process. During this process, victims are asked to log into what seems like a job portal, but it actually captures their Google account credentials. The scheme targets people actively seeking work, exploiting their trust in major brands like Netflix, OpenAI, and FIFA.
Security researchers at Proofpoint identified this cyberheist job in late 2024 and January 2025. The attackers use the same HR platforms that companies normally use, making the fake offers hard to spot. They also send follow-up emails with fake offer letters, adding realism to the scam. This method increases the success of the cyberheist job, as victims believe they are progressing in a real recruitment process.
To protect against this cyberheist job, job seekers should verify all job offers directly through official company career pages. Never click on login links in unsolicited emails, and use multi-factor authentication on your Google account. Awareness of this cyberheist job is crucial, because the offers look convincing and rely on your trust in big names. If an offer seems too good to be true, it likely is part of a cyberheist job.
