London, 27 May 2026 – A sophisticated phishing campaign targeting jobseekers has been uncovered by cybersecurity company NordVPN, as scammers look to impersonate recognisable brands including Meta, Disney, Coca-Cola and Spotify.
With unemployment at its highest level since the pandemic, more people are actively searching for work. Researchers from NordVPN’s Threat Intelligence team warn criminals are taking advantage of the increased volume of applications and outreach, using fake job offers to trick victims into handing over their social media login details.
This new approach is significantly more advanced than typical phishing scams, using multiple stages and evasion tactics to avoid detection and increase its chances of success.
The attack often begins with a polished recruitment email, sometimes sent via legitimate tools such as <:contentReference[oaicite:10]{index=10}> to help bypass spam filters and appear more credible. These messages mirror genuine outreach, using professional language and formatting to build trust.
Victims who click the link are directed to hidden “HUB” domains — such as careers.meta-findyourjob[.]com — which only activate when accessed through a specific referral link, helping the scammers evade detection from traditional spam filters.
From there, users are taken to fake job portals tailored to the brand being impersonated, including domains such as plus.jobfusion-mt[.]com, official.professionlaunch-mt[.]com, careers.coca-contactnow[.]info, connect.spotifycareerapply[.]com and jobquest.wdcfuturesteps[.]com. These sites allow users to browse seemingly legitimate roles, reinforcing the illusion of a real hiring process.
The final step prompts users to log in via Facebook to carry on with their application. By doing so, they are handing attackers full access to their account and any linked services if their details are entered. While not as lucrative as payment card information at first glance, compromised social media accounts can act as a gateway to wider identity fraud. Sadly, scammers may also try to impersonate affected users and dupe friends and family into clicking on links and transferring money.
Marijus Briedis, Chief Technology Officer at NordVPN, comments: “Periods of economic uncertainty often create the perfect conditions for scams like this. When more people are actively looking for work, there is understandably more trust placed in recruitment messages and job opportunities.
“What makes this campaign particularly dangerous is how convincing it is. From the branding to the job listings, everything is designed to replicate a real hiring process, making it much harder for people to spot the warning signs.
“Social media logins may not seem like the most sensitive information to hand over, especially when compared to bank details for example, however this is where people can fall into a trap. These logins can act as a gateway to much wider account access.
“Once compromised, attackers can use these accounts to spread scams to your loved ones, access other services or attempt identity fraud.
“As job searches increasingly take place online, it is vital that people slow down and question any unexpected opportunity, especially when it asks for login details or redirects them away from official websites.”
NordVPN’s Simple Steps To Avoid Recruitment Scams
- Always check the website address before entering any login details. Legitimate companies host careers pages on official domains, not unfamiliar third-party sites.
- Be cautious of “log in with Facebook” prompts. Genuine logins will always redirect to the official Facebook domain.
- Enable multi-factor authentication (MFA) on all accounts to add an extra layer of security.
- Avoid unsolicited job offers, particularly those that create urgency or pressure you to act quickly.