The usual warning about job scams arrives late. It tells you not to pay for training, not to accept an offer from a company you cannot verify, not to forward packages. All of that is correct, and all of it describes the final stage of a process that started weeks earlier.
A growing share of job fraud never reaches an offer at all. There is no fake contract to refuse, because the contract was never the point. The interview is the product. What it extracts from you, in the ordinary course of looking like a recruitment process, is worth more to the operator than any fee they could talk you into paying.
That shift matters, because it means the moment to be careful is much earlier than most people think, and the signals are different.
Why the interview became the target
Consider what a normal hiring process asks you to hand over, and how normal each request feels.
A copy of your passport or national ID, for the contract. A photo of yourself, for the badge. Your bank details, for payroll. Your date of birth and home address, for the HR file. A short video of you speaking, because the first round is recorded. Your mother's maiden name, because that is on the background check form. Emergency contact details, including a relative's phone number.
Requested individually, across three weeks, by somebody with a company email signature, each one is unremarkable. Assembled, they are a complete identity package: enough to open accounts in your name, pass a phone-based verification, or make a convincing approach to your family. The operator never needs to ask you for money, because you have already handed over the thing that is easier to sell.
The economics are simple. A fee scam earns once, from one person, and ends the moment they refuse. A document harvest earns repeatedly, from data that stays valuable for years, and the victim often does not know it happened.
The chat-app interview
The most common structure right now runs entirely inside a messaging app.
It opens with an unsolicited message, often on WhatsApp or Telegram, occasionally on LinkedIn or by text. The sender names a real company, sometimes a well-known one, and refers to your CV as though they found it on a job board. That part is frequently true, because CVs on public boards are scraped in bulk.
The role sounds good and slightly vague. Remote or hybrid. Flexible hours. A salary comfortably above what the title usually pays, but not so high that it reads as fake. Then the interview happens in the chat itself, as a series of typed questions over an hour or two.
This is the part worth pausing on, because the text interview is not laziness. It serves three purposes for the operator. It scales, since one person can run twenty at once. It leaves no voice or face to identify. And a typed conversation makes it natural to ask you to send documents as attachments, in a thread where sending things is the normal way to communicate.
The tell is structural rather than a specific question. A real interview is a conversation with pauses, follow-ups and someone who is clearly reading your answers. A harvesting interview moves through a fixed list regardless of what you say, and the questions drift steadily from your experience toward your details.
The onboarding portal
The more developed version adds a step that feels like reassurance and is actually the harvest.
You are congratulated, told you have passed, and sent a link to an onboarding portal to complete your file before the start date. The page is competent. It carries the real company's logo, colours and often text copied verbatim from their careers site. It asks for the full set of documents at once, which now feels justified, because you have been hired.
Two details separate these portals from the real thing, and both are visible in seconds.
The first is the domain. A genuine employer's onboarding sits on their own domain or on a named HR platform. A fraudulent one sits on a lookalike, a free subdomain, or a shortened link. Read the address slowly, letter by letter: a swapped letter, an added hyphen, ".co" where the company uses ".com", an extra word before the brand name. These are designed to survive a glance and fail a reading.
The second is the sequence. Real employers do not collect passports, bank details and identity documents before a signed contract exists. The order is offer, then contract, then documents. Any process that reverses that order has told you what it is.
The salary advance, which is the one that empties accounts
There is a variant that does take money, and it is worth describing precisely because it does not look like a fee.
You are hired. Before the start date, the company sends you an advance, for a laptop, a home office setup, or a first-month stipend. The payment arrives, and you can see it in your account. You are then asked to buy specified equipment from a named supplier, or to forward part of the advance to a colleague or a vendor.
The original payment is fraudulent, usually a cheque or a transfer from a compromised account. It reverses days later. The money you sent onward is real and gone, and it left your account on your instruction. You are out the full amount, and depending on the jurisdiction you may be a witness, a victim, or a suspect.
The rule that defends against this has no exceptions worth arguing with. Money that arrives from an employer before you have started work, which you are then asked to move, is not yours. Wait for it to clear fully, which takes longer than the arrival notification suggests, and never forward funds to anyone at an employer's request.
Four checks that cost about ten minutes
None of these require expertise, and they resolve almost every case.
Go to the company yourself. Do not use the link, the phone number or the email address in the message. Search for the company independently, open their careers page, and see whether the role exists. If it does not, or if it exists with a different salary and a different contact, you have your answer. If it does exist, apply through their page rather than through the message.
Check the email domain, not the display name. The sender's name can say anything. The part after the @ is what matters, and a legitimate recruiter for a company writes from that company's domain. A generic free-mail address, or a domain that resembles the company's without being it, is disqualifying on its own. Note that free-mail addresses are ordinary for small local employers, so weigh this against the size of the company being claimed.
Confirm the recruiter exists. Look for the person on the company's own site or on a professional network, and check that the profile predates your conversation and shows a history. A profile created recently, with few connections and a stock photograph, alongside a story about a senior role at a large company, does not hold together.
Ask for a voice or video call. This single request resolves a large share of cases. A real recruiter will schedule one without hesitation, because talking to candidates is their job. An operator running twenty text threads will refuse, deflect to a policy about written processes, or agree and then never appear.
What to do if you have already sent documents
If you are reading this with a sinking feeling, the useful thing is sequence, not panic. Acting in the first few days materially limits what can be done with the data.
- Stop responding. Do not warn them, argue, or try to recover anything. Silence removes their ability to extract more or to pressure you.
- Contact your bank directly, using the number on your card, if you sent bank details or moved any money. Ask them to flag the account for attempted fraud.
- Report the identity document to whichever authority issues it in your country. A flagged passport or ID number is much harder to use.
- Tell the real company. Their security team almost certainly wants to know their brand is being used, and they can have the fake portal taken down.
- Report it to the platform where contact began, and to your national cybercrime or consumer protection body. This feels futile and is not: these reports are how patterns get identified and domains get blocked.
- Change the password and enable two-factor authentication on any account that shares an answer with something you disclosed, particularly security questions.
One thing not to do is stay quiet out of embarrassment. These operations are designed by people who do this full time, tested against thousands of candidates, and refined on what works. Being taken in by a professional deception is not a character flaw, and the people who report quickly lose the least.
The underlying asymmetry
What makes this category of fraud effective is not technical sophistication. It is that it runs on a genuine emotion in a real situation.
Someone looking for work is hopeful, often under financial pressure, and has been trained by every piece of career advice to be responsive, accommodating and quick. A candidate who questions a recruiter's request feels like a candidate who is making things difficult. The scam borrows that entire posture and points it at you.
Which suggests the correct default. A legitimate employer will never be damaged by your caution. If verifying a company, asking for a call, or declining to send a passport before a contract exists costs you a real opportunity, that opportunity was not real. No genuine hiring process has ever collapsed because a candidate took ten minutes to confirm who they were talking to.