The most common question I get from people I used to recruit has nothing to do with resumes anymore. It's a screenshot. Someone forwards me a message from a "recruiter" at a company they've actually heard of, and asks some version of the same thing: does this look real to you? For years I could answer in about four seconds, because the fakes announced themselves. Broken grammar, a Gmail address, a salary that made no sense for the title. Now I open the screenshot and the honest answer is usually that I can't tell. The message is well written, the role is plausible, the company is real, and the person's photo looks like a person. That shift is the whole story, and it means the advice most of us have been giving for a decade has quietly stopped working.
The number that changed how I give this advice
When the Better Business Bureau published its 2026 employment scams study, the headline everyone repeated was that reports had doubled: 11,748 in 2024, 23,234 in 2025. That's alarming on its own. But the number I keep coming back to is the one underneath it, and almost nobody mentioned it: the median loss went down over the same period, from $1,500 to $1,000. Twice as many victims, each losing less.
That combination tells you something specific about what changed, and it isn't that the criminals got smarter. A con that extracts a lot from each victim is expensive to run: it takes research, a tailored story, days of rapport-building, and a human who can improvise. A con that extracts less from each victim but reaches twenty times as many people is a different business entirely, closer to spam than to fraud in the old sense. Falling median losses next to doubling volume is what industrialization looks like in the data. Somebody automated the top of the funnel.
You can see the same thing in where the messages arrive. BBB found that job scams run over text message made up roughly half of all 2025 reports, and in April 2026 the FTC reported that Americans lost $2.1 billion to scams that began on social media in 2025, eight times the 2020 figure, with nearly one in three people who lost money to any scam first contacted on a social platform. Texts and social DMs are cheap, they don't bounce, and they skip every spam filter a corporate email account would apply. The practical consequence for you is simple and slightly grim: you should expect to be contacted, probably more than once, and you should expect the message to look completely fine.
Why 'watch for typos and bad grammar' expired as advice
Nearly every job scam guide still leads with the writing quality tell. It made sense once. Scam outreach used to be produced by people writing in a second or third language with no tooling, and the seams showed. That constraint evaporated somewhere around 2023. Producing fluent, warm, on-brand recruiter outreach in any language is now free and takes about nine seconds, and the same tools generate a headshot, a plausible work history, and a company boilerplate paragraph to match.
Meanwhile, here is what real recruiter outreach looks like, from someone who sent thousands of them: a merge field that didn't populate, so it opens "Hi {{first_name}}." The wrong first name entirely, because two candidates got swapped in a sequence. A req that closed nine days ago. A follow-up to a message the recruiter forgot they already sent. I once sent a personalized note to forty-one people with the previous company's name still in the second paragraph. The polish signal has fully inverted. In 2026 I would sooner trust the sloppy message.
The tell that flipped
If your scam-detection method is aesthetic, you are grading the one thing the attacker can now generate perfectly for free. The parts of a hiring process an attacker cannot easily fake are procedural: a real requisition on a real careers page, a live human conversation, a written offer with a named signatory, and an identity-verification step that happens inside a payroll system behind a login. Grade those instead.
What a real hiring process actually looks like, in order
I ran hiring at three companies on three different applicant tracking systems, and the order of operations never varied, because it isn't a matter of manners. It's enforced by the software, by the finance team, and by federal paperwork rules. An employer cannot collect an I-9 or a W-4 from someone who isn't being hired, and no payroll department will set up a direct deposit for a person who has no signed offer in the system. The sequence below is the actual shape of the thing. Scams have to break it, because the whole point of the scam is to get to the last two rows without doing any of the first four.
| Stage | What normally happens | What does not happen in a real process |
|---|---|---|
| 1. First contact | Email to the address on your resume, or a message inside LinkedIn from a profile that predates the conversation, naming a specific open role. | An unsolicited WhatsApp or SMS with a job description but no link to the company's own careers page, or an immediate push to continue on Telegram. |
| 2. Screening call | A 20 to 30 minute live conversation with a human who can answer questions about the team, the manager, and the salary band. | An 'interview' conducted entirely as typed chat messages, or a job offered without anyone ever speaking with you. |
| 3. Interviews | Scheduled through a named tool (Greenhouse, Ashby, Calendly) on the company's own domain, with named interviewers you can look up. | Meeting links on a personal or lookalike domain, or a request to install unfamiliar software in order to attend. |
| 4. Offer | A written offer letter with title, salary, start date, and a named signatory, sent from a company domain. | A verbal or chat-message offer followed immediately by a request for your Social Security number or bank details. |
| 5. Onboarding paperwork | I-9, W-4, and direct deposit collected inside a named HRIS or payroll platform (Workday, ADP, Gusto, Rippling, Paychex, UKG) behind a login you create. | A Google Form, a PDF emailed back and forth, or 'just text me a photo of your ID and a voided check.' |
| 6. Equipment and expenses | The company purchases and ships hardware directly, or reimburses a documented purchase after you are on payroll. | Any payment from you up front, for any reason, reimbursed or otherwise. Also any check you are asked to deposit and partly forward on. |
If you remember one line from that table, make it this one: money and identity move late, and they move through named systems with logins. There is no legitimate version of a company that needs your Social Security number to "reserve your spot in onboarding" or asks you to buy your own laptop from a vendor they specify. That request has no honest form, so you never have to weigh how convincing the rest of the conversation was.
The verification that takes four minutes
Open a new browser tab and type the company's name yourself. Find the role on their own careers page. Then look up the company's main phone number independently and ask to be connected to recruiting, or email the recruiter at the address format used on the company's real domain. Never use a link, phone number, email address, or QR code that arrived in the message you are trying to verify, because every one of those is under the sender's control. If the role isn't on the careers page and nobody in recruiting has heard of the person, you have your answer without needing to judge their writing.
The four patterns that account for almost everything people forward me
- 1The task scam, which is now the dominant form. It starts with a text or WhatsApp message about flexible online work, then asks you to complete batches of small "tasks" (liking videos, "product boosting," "app optimization") on a dashboard that shows your earnings climbing. Small early payouts land in your account and feel real. Then the dashboard requires you to deposit your own money, usually in crypto, to unlock the next batch and release your balance. The FTC's data spotlight on gamified job scams found reports jumped from about 5,000 in all of 2023 to roughly 20,000 in the first half of 2024 alone, accounting for nearly 40% of that year's job scam reports, with crypto losses to job scams roughly doubling to about $41 million in the same six months. BBB put the 2025 median loss for task scams at $2,300, more than double the $1,000 median across employment scams generally.
- 2The fake check overpayment, usually dressed as a home-office stipend. You are "hired," a check arrives for more than you need, and you are told to buy equipment from a specified vendor and wire back the difference. The trap is a banking detail almost nobody knows: your bank must make deposited funds available within a couple of business days, but that is not the same as the check having cleared. A forged check can be returned weeks later, and when it is, the entire amount comes out of your account, including the part you already sent to someone else.
- 3The identity harvest, which is the one that scares me most because nothing feels wrong. Nobody asks you for money. You get an offer, a warm welcome email, and an onboarding packet requesting your Social Security number, date of birth, a photo of your driver's license, and direct deposit details. There is no job. The product being extracted is you: enough to open credit lines, file a fraudulent tax return, or pass an employment verification somewhere else. Because no payment is ever requested, every instinct you have been trained to use stays quiet.
- 4The real-company impersonation, which wraps any of the above in borrowed credibility. The company is real, the recruiter's name and photo belong to an actual employee you can find online, and the only forged element is the domain: one transposed character, an extra hyphen, a .co instead of .com, or a free mail account with the company name in the part before the @. Check the text after the @ symbol, character by character, and ignore the display name entirely, since display names are free to type and prove nothing.
Where they got your details in the first place
There is an uncomfortable thing about this topic that resume sites, mine included, do not say often enough: your resume is the single most useful document a scammer can obtain about you, and uploading it to a public job board is a form of publishing. Resume databases get sold and resold to "recruiters" with very light vetting, and an open-to-work flag on a public profile is, functionally, a targeting signal. That is not an argument for hiding. It is an argument for noticing that the document was written for a hiring manager and is now being read by other people too.
Which is a good reason to look again at what your public resume actually contains. None of the following costs you anything with a real employer:
- ▸City and state only, never your street address. A full home address is frequently the last field an identity thief still needs, and no recruiter has ever declined a candidate for omitting it.
- ▸No date of birth, no marital status, no photo, no passport or national ID number. None of that belongs on a US resume regardless, and each field is worth real money to the wrong reader. (Leaving your graduation year off is a separate and also defensible call, for reasons covered in our piece on age discrimination in resume screening.)
- ▸No reference names or phone numbers on the resume itself. "References available on request" remains the correct answer, and it protects other people's contact details as well as your own.
- ▸Consider a dedicated email address used only for job applications. It costs nothing, keeps application mail out of your main inbox, and if that address starts receiving recruiter texts and WhatsApp messages you never signed up for, you have learned exactly which board leaked.
- ▸Keep your public profile and your resume consistent but not identical, for the reasons laid out in does your resume need to match your LinkedIn. A profile is a shop window; a resume is a document you hand to a specific person.
It's also worth saying that a message being unsolicited is not by itself evidence of anything. Real recruiters cold-contact people constantly, and a lot of good jobs start that way. The distinction is that a real cold approach can survive an independent check: the role exists on the careers page, the recruiter exists in the company directory, and the conversation moves onto company infrastructure quickly. A fake one needs you to stay inside the channel it arrived on. If someone resists moving to a company email address or a scheduled call, that resistance is the finding.
If you already handed something over
This happens to careful, intelligent people, most often when they are exhausted, three months into a search, and finally getting a yes. Speed matters more than self-recrimination here, and the order below is roughly the order of how much difference acting fast makes.
- 1If you sent money by bank transfer, wire, or card, call your bank's fraud line today, not tomorrow. Recovery odds fall sharply within the first 24 to 48 hours, and a wire that has not yet settled can sometimes be recalled.
- 2If you deposited a check and forwarded part of it, tell your bank before the check is returned. It will not erase the liability, but it changes the conversation from one where the bank discovers the fraud to one where you reported it.
- 3If you sent cryptocurrency, report it, but plan on the money being gone. That irreversibility is precisely why crypto is the preferred rail for task scams.
- 4If you gave up your Social Security number or a government ID, go to IdentityTheft.gov, the FTC's official recovery site, which generates a personalized recovery plan and the affidavits you will need. Then place a credit freeze with all three bureaus (Equifax, Experian, TransUnion). Freezes are free by law, take minutes, and can be lifted temporarily whenever you actually apply for credit.
- 5Report the scam at ReportFraud.ftc.gov and to BBB Scam Tracker, and report the account to whichever platform it used. This feels pointless and is not: the figures in this article exist only because people filed those reports, and pattern detection is how takedowns get triggered.
- 6Tell the real company being impersonated. Their security team almost always wants to know, they can often get a lookalike domain seized, and they may already be tracking the campaign.
One last thing, aimed at anyone deep enough into a search that a too-good message is starting to look reasonable. Scammers are not really selling a job. They are selling relief from the part of the search that feels worst: the silence, the unanswered applications, the sense that nothing you send lands anywhere. That is a real feeling with a real cause, and it's worth reading up on why strong candidates never hear back and on ghost job postings, because understanding the machinery makes the fake version far less persuasive. A message that arrives promising to skip all of it is not good luck. It is someone who has correctly guessed how tired you are.
Key takeaway
Stop grading job outreach on how it reads, because that signal is now generated for free and has effectively inverted. Grade it on sequence instead: a real process moves contact, live conversation, interviews, written offer, and only then identity and payment data, collected inside a named payroll system behind a login. Any request for money or for your Social Security number and bank details before a signed written offer exists is disqualifying on its own, no matter how good the rest of the conversation was. When in doubt, verify through a path you found yourself, never one supplied in the message.