all case files

case file 12recruiter impersonationDecember 2025email, LinkedIn, video calls

the recruiters who never sent that email

Scammers impersonate real recruiters at real companies, run fake interviews, send fake offer letters, and ask the candidate for money. The recruiters whose names are stolen find out when victims contact them.

160+

impersonated recruiters catalogued publicly

24,688

employment fraud complaints to the FBI in 2025

$363m

reported losses to job seekers in 2025

what happened

This is candidate fraud pointed the other way. Instead of a fake candidate applying to a real company, a fake recruiter approaches a real candidate using a real company's name, logo and an actual employee's identity.

GitLab published the pattern in December 2025 after a wave targeting its own name: lookalike domains, fake recruiter profiles on LinkedIn and Teams, realistic interview invitations, authentic-looking offer letters, invented certifications, and then a request for an upfront payment for equipment or a background check.

Tenfold, a recruiting firm, maintains a free public catalogue of these signals, including more than 160 real recruiters whose identities have been stolen to run these scams, with the fraudulent addresses used in each of their names. Some of those recruiters are well known in the industry, and one of them is the firm's own founder.

how it was caught

Usually by the impersonated recruiter, after a confused candidate contacts them to ask about an interview they never conducted.

The FBI's Internet Crime Complaint Center recorded 24,688 employment fraud complaints in 2025 with $362.9 million in reported losses, up from $264 million the year before. Those losses are borne by job seekers, not by employers.

what it cost

For candidates, direct financial loss plus the identity documents they handed over during a fake onboarding.

For the company whose name is used, a brand problem it cannot fix and a stream of candidates arriving in its real pipeline already suspicious of it. Every company should publish which domains it actually recruits from, which is why aperture maintains an authorized domains notice of its own.

the tells

signals that were visible, in hindsight, before anyone was hired.

  • The recruiter writes from Gmail, Outlook or a lookalike domain rather than the company domain.
  • You are asked to pay for equipment, certification, or a background check.
  • The whole process happens over chat, with no verified calendar invite.
  • The role does not appear on the company's real careers page.
  • The recruiter will not verify their identity from a company email address.

what would have stopped it

the checks aperture runs on every session, mapped to this case. nothing here is hindsight-only. each one runs before a hiring team spends an hour on the candidate.

published authorized domains

A candidate can only tell a real approach from a fake one if the company has said, publicly, which domains it recruits from. aperture publishes its own.

interviews on a verifiable platform

A fake interview relies on a generic meeting link anybody can create. An interview that runs on the employer's own verified platform is one a candidate can check before they hand anything over.

open source threat intelligence

Fraudulent recruiter addresses are catalogued publicly by the very recruiters being impersonated. Those catalogues can be checked, and aperture checks them.

sources

  1. [1]
    New wave of fake job scams impersonating recruiters

    GitLab · blog · December 10, 2025

    A company publishing the domains and tactics being used to impersonate its own recruiters, including lookalike domains and requests for upfront equipment payments.

  2. [2]
    2025 Internet Crime Report

    FBI Internet Crime Complaint Center · fbi · 2025

    Employment fraud: 24,688 complaints and $362,934,762 in reported losses in 2025, up from $264 million the previous year. These are losses to job seekers, not to employers.

  3. [3]
    Might Be Fake: a public catalogue of candidate fraud and hiring scam signals

    Tenfold · public database · 2026

    A free, sourced, Google-indexed lookup of 4,000+ fraud signals, 1,400+ email addresses, 2,400+ IP addresses and 160+ impersonated recruiters. Built by Tenfold, not by aperture.

human intelligence,on your side.

switch it on today. tomorrow you read a shortlist, not a pile.

free to start, no credit card, set up in minutes