Job scams have outpaced the warning signs most people know to look for. Now, fraudsters are systematically stealing the identities of working recruiters, including their names, photos, firm affiliations, and LinkedIn profiles, and using that genuine information to contact job seekers directly. The outreach is personalized. The credentials check out. The role being pitched often exists. From the candidate’s side, it looks indistinguishable from a legitimate recruiter outreach until the request for money or personal data arrives, and by then significant trust has already been extended.

This is not a problem that lives at a distance from us. Staffing professionals are among the most impersonated categories in this type of fraud precisely because recruiter credibility is what makes the deception work so well. Like candidates, recruiters are being exploited.

Job scam losses have grown fivefold in four years, and most go unreported

The Federal Trade Commission documented job scam losses growing from $90 million in 2020 to more than $501 million in 2024. The FTC also estimates that fewer than 10% of fraud victims file a report with a federal agency, which means the financial damage is likely several times larger than what those figures capture. The Better Business Bureau found that one in three people who encounter a job scam lost money, with a median loss of $1,500 per victim. For someone already out of work, that loss compounds quickly. The FBI’s Internet Crime Complaint Center documented $20.9 billion in total cybercrime losses in 2025 and noted explicitly that AI involvement in fraud is undercounted because most victims do not recognize it when it occurs.

But financial loss is only part of the damage. Victims hand over résumés, Social Security numbers, and bank details that scammers use for identity theft long after the original contact.

AI is the engine on both sides of this problem

Fraudsters are now using large language models to scrape candidate profiles and generate personalized outreach at scale, voice cloning tools to replicate a recruiter’s voice from a few seconds of publicly available audio, and deepfake video to impersonate real people on camera. Volume and quality no longer trade off against each other. A scammer can send thousands of individually tailored messages, make convincing follow-up calls in a stolen voice, and appear on a video interview as someone they are not, all with consumer-grade tools.

The same technology is available for defense. Reverse image search verifies profile photos in seconds. AI-powered analysis built into Gmail and Outlook flags domain spoofing and header anomalies that are invisible to the naked eye. Deepfake detection tools from providers including Microsoft and Reality Defender analyze video calls for synthetic media in real time. The governing principle is straightforward: if AI is being used to manufacture trust, the response is to use AI to interrogate it. Leveraging a diverse portfolio of these tools can help people protect themselves.

How to use verification as your top defensive play

Here’s what a well-executed scam looks like in practice: A candidate posts about a layoff on LinkedIn. Within days, an email arrives from someone using the name and credentials of a real recruiter at a recognizable firm. The email references a real open role. The tone is professional. The only giveaway is the sending domain. The address is a Gmail account rather than a firm or company domain, and the scammer has a prepared explanation for that too. Most candidates would not catch it on the first read. Some do not catch it until they are asked to pay for something.

Verification takes five minutes. Recovering from fraud takes considerably longer. These steps reduce exposure substantially.

  • Check the sending domain before anything else: Legitimate recruiters use company-branded email addresses. A Gmail, Outlook, or Yahoo address from someone claiming to represent a staffing firm is a red flag regardless of how professional the message looks. Do not accept an explanation for why a personal address was used.
  • Verify the recruiter through a separate channel: Search the recruiter’s name on LinkedIn directly rather than clicking any link in the email and send a message asking whether the outreach was genuine. A real recruiter will confirm. A scammer cannot.
  • Confirm the role on the employer’s careers page: If the position is posted, that’s a good sign. But also look for language on the employer’s site about authorized recruiting partners or approved email domains. Some employers publish this specifically because impersonation fraud has targeted their open roles.
  • Stop if payment is requested: Legitimate staffing firms are compensated by the employer, not the candidate. Any request for payment, whether for a resume review, a background check, or any other reason, is fraudulent. There is no version of this that is genuine.

Employers carry reputational risk that they may not know they have

When a scammer impersonates a recruiter to fraudulently represent an open role, the employer’s name is embedded in the deception. Candidates who are defrauded remember the company they believed they were being considered by. The reputational exposure is real even though the employer did nothing wrong.

Two steps reduce that exposure directly. First, publish clear language on your careers page identifying which staffing partners you work with and which email domains their recruiters use. This gives candidates a way to self-verify before any damage occurs. Second, formalize your recruiting partnerships. Ad hoc outreach from unverified sources creates the ambiguity that scammers require. When candidates know exactly who your authorized partners are, fraudulent contacts become identifiable rather than plausible.

How Contemporary Staffing operates

All outreach from Contemporary Staffing comes from verified addresses tied to our domain. We do not charge candidates fees at any point. Our compensation comes from client organizations. If a candidate wants to confirm that a message from us is genuine before responding, they can check our site or contact us directly, and we will verify it the same day.

Job scam losses have grown fivefold in four years; the tactics now clear the bar that most people set for due diligence, and the FBI believes AI is involved in more cases than it can actually document.

Candidates who skip verification are not being careless. They are operating on a checklist that no longer matches the threat. The question for both job seekers and hiring organizations is whether their process reflects where the risk actually is now, or where it was five years ago.

Recent Insights