09.06.2026 - Job seekers are increasingly being targeted by cybercriminals. The hope of landing a new job, along with the associated willingness to react quickly and engage with unfamiliar procedures, lowers vigilance. Attackers exploit this systematically, deploying their entire arsenal – from phishing and classic scams to the distribution of malware.
Over the past few weeks, the NCSC has received several reports from job seekers. Cybercriminals specifically target people who are looking for work and are therefore more likely to act quickly and go along with unfamiliar requests. The attackers exploit this very lapse in vigilance, drawing on their entire arsenal of tactics. Using three reported cases, the NCSC demonstrates how these scams work and how to protect yourself effectively.
Phishing in the job application process: Fake interview login
In the first case, a jobseeker came across what appeared to be a job advertisement. Subsequently, they were offered a time slot for a phone interview, which they were asked to confirm via a Google Calendar entry. When they clicked to confirm, a login window appeared that looked deceptively real. Even the link provided appeared to lead to Google. What the reporter couldn’t tell was that the login credentials entered in that window weren’t used to confirm the appointment, but were sent directly to the scammers. The entire login page, including the displayed web address, was fake. It was therefore a classic phishing attempt, cleverly embedded within a supposedly legitimate application process. This is how the scammers obtain the login credentials for the victim’s Google account.
A package delivery job as a trap
In the second case, a job seeker came across an ad for a supposed "Swiss social welfare" programme, offering a well-paid work-from-home job, packing and forwarding packages. After a brief exchange of emails, further communication shifted to WhatsApp. Eventually, the job seeker was asked to submit a form with photos of their passport, identity card, driving licence and home address. At that point, the job seeker became suspicious and cut off all contact.
Behind this scam lies the phenomenon of the "freight forwarder" (also known as a "package agent" or "reshipper"), a method used to conceal criminal proceeds. The job involves receiving packages and forwarding them to addresses – usually located abroad – thereby covering the criminals' tracks. By rerouting the packages through an intermediate address, the scammers conceal the true recipient’s address and distance themselves from the shipment.
At the same time, the identity documents obtained during the application process are used to order high-value goods – such as electronic devices, cameras, or cell phones – in the victim’s name using stolen credit card information. If an online store requests identification, the scammers provide a copy of the merchandise agent’s ID. What is particularly insidious is that the scammers posed as "Swiss Social Welfare" and thus specifically targeted vulnerable individuals.
Fake recruiters on LinkedIn
In the third case, an IT professional was contacted on LinkedIn by a supposed recruiter who promised the job seeker a technical position at a well-known company. In a similar incident, the request even originated from a previously compromised LinkedIn profile that otherwise appeared genuine, which further boosted its credibility.
As part of a technical interview, the candidate was asked to download a private GitHub repository and complete a small programming task within it. This procedure is quite common in the IT industry and therefore did not arouse any suspicion. However, after the commands were executed, an "infostealer" installed itself unnoticed on the victim’s device. The malware was designed to secretly read crypto wallets, stored login credentials and browser cookies in the background and send them to the attackers. Such an incident becomes particularly serious if sensitive documents are also stored on the affected device.
Recommendations
- Do not disclose your personal information too soon. Bank account details or copies of identification documents are only relevant after a job offer has been made.
- Never make advance payments and do not make your account or address available for third-party money or goods transfers.
- Stop immediately if your antivirus software alerts you or a browser warning appears.
- Do not click on any links or execute any commands or programs whose origin you do not know.
- If you notice any inconsistencies or have suspicions, verify whether the company that supposedly posted the job listing actually has open positions. If necessary, call the number listed on the official website to confirm.
- Review the data protection and privacy settings of your social media accounts and specify which personal information you wish to share.
Current statistics
Last week's reports by category:
Last modification 09.06.2026

