case file 12recruiter impersonationDecember 2025email, LinkedIn, video calls
the recruiters who never sent that email
Scammers impersonate real recruiters at real companies, run fake interviews, send fake offer letters, and ask the candidate for money. The recruiters whose names are stolen find out when victims contact them.
160+
impersonated recruiters catalogued publicly
24,688
employment fraud complaints to the FBI in 2025
$363m
reported losses to job seekers in 2025
what happened
This is candidate fraud pointed the other way. Instead of a fake candidate applying to a real company, a fake recruiter approaches a real candidate using a real company's name, logo and an actual employee's identity.
GitLab published the pattern in December 2025 after a wave targeting its own name: lookalike domains, fake recruiter profiles on LinkedIn and Teams, realistic interview invitations, authentic-looking offer letters, invented certifications, and then a request for an upfront payment for equipment or a background check.
Tenfold, a recruiting firm, maintains a free public catalogue of these signals, including more than 160 real recruiters whose identities have been stolen to run these scams, with the fraudulent addresses used in each of their names. Some of those recruiters are well known in the industry, and one of them is the firm's own founder.
how it was caught
Usually by the impersonated recruiter, after a confused candidate contacts them to ask about an interview they never conducted.
The FBI's Internet Crime Complaint Center recorded 24,688 employment fraud complaints in 2025 with $362.9 million in reported losses, up from $264 million the year before. Those losses are borne by job seekers, not by employers.
what it cost
For candidates, direct financial loss plus the identity documents they handed over during a fake onboarding.
For the company whose name is used, a brand problem it cannot fix and a stream of candidates arriving in its real pipeline already suspicious of it. Every company should publish which domains it actually recruits from, which is why aperture maintains an authorized domains notice of its own.
the tells
signals that were visible, in hindsight, before anyone was hired.
- The recruiter writes from Gmail, Outlook or a lookalike domain rather than the company domain.
- You are asked to pay for equipment, certification, or a background check.
- The whole process happens over chat, with no verified calendar invite.
- The role does not appear on the company's real careers page.
- The recruiter will not verify their identity from a company email address.
what would have stopped it
the checks aperture runs on every session, mapped to this case. nothing here is hindsight-only. each one runs before a hiring team spends an hour on the candidate.
A candidate can only tell a real approach from a fake one if the company has said, publicly, which domains it recruits from. aperture publishes its own.
A fake interview relies on a generic meeting link anybody can create. An interview that runs on the employer's own verified platform is one a candidate can check before they hand anything over.
Fraudulent recruiter addresses are catalogued publicly by the very recruiters being impersonated. Those catalogues can be checked, and aperture checks them.
sources
- [1]New wave of fake job scams impersonating recruiters
GitLab · blog · December 10, 2025
A company publishing the domains and tactics being used to impersonate its own recruiters, including lookalike domains and requests for upfront equipment payments.
- [2]2025 Internet Crime Report
FBI Internet Crime Complaint Center · fbi · 2025
Employment fraud: 24,688 complaints and $362,934,762 in reported losses in 2025, up from $264 million the previous year. These are losses to job seekers, not to employers.
- [3]Might Be Fake: a public catalogue of candidate fraud and hiring scam signals
Tenfold · public database · 2026
A free, sourced, Google-indexed lookup of 4,000+ fraud signals, 1,400+ email addresses, 2,400+ IP addresses and 160+ impersonated recruiters. Built by Tenfold, not by aperture.
more case files
north korean it scam · July 2025
the laptop farm in a suburban house
For three years, a woman in Litchfield Park, Arizona kept dozens of company laptops running in her home so North Korean IT workers could appear to be logging in from America. 309 U.S. companies paid them.
north korean it scam · July 2024
the security company that hired one
KnowBe4 trains other companies to spot social engineering. It interviewed a principal software engineer four times on video, ran a background check, checked references, hired him, and shipped him a Mac. Malware started loading 25 minutes after it arrived.
deepfake · March 2025
put your hand in front of your face
Hiring for one backend role out of about 500 applicants, security startup Vidoc got two AI-deepfaked candidates deep into its pipeline. One was exposed by a request that took three seconds: cover part of your face with your hand.