RSS Amplifier

Ethical Edge by Evie’s Substack · Jul 29, 2026

The Recruiter Was Never Real: What a Near-Miss Reveals About Recruitment Fraud in 2026

0
Sign in to vote or save

Evie Wentink · Ethical Edge by Evie’s Substack

She wasn’t job hunting. That’s what made her a target.

On a recent episode of Let’s Talk About Ethics, I sat down with Melanie Shong Ham to unpack something that happened to her out of the blue: a polished, professional, entirely convincing email from a “Global Director of Talent Acquisition” at a major aerospace and defense contractor. Melanie has a consulting practice. She wasn’t looking. And that’s exactly the profile fraud actors are learning to target — people confident enough, and comfortable enough, to let their guard down just slightly because they have nothing to gain by pursuing the opportunity too hard.

What unfolded over the following days is a case study every compliance and HR professional should sit with, because the old advice — “check for typos, check for weird email addresses” — no longer holds. AI has quietly dismantled the tells we used to train people to spot.

Every checkpoint Melanie ran, the scheme passed.

The email address used the real company’s domain formatting, not a Gmail or Hotmail knockoff. The company logo wasn’t pixelated or obviously lifted. The signature block included a working LinkedIn link — dressed up to look native, but actually routed straight back to the sender’s own inbox rather than a real profile. The recruiter’s LinkedIn profile itself looked legitimate on the surface: right kind of activity, right tone, the kind of low-visibility posting pattern you’d genuinely expect from someone at director level who has to toe a corporate line.

Even the absence of a posted job listing didn’t raise a flag — because in large organizations bidding on major contracts, that’s normal. Melanie later confirmed the company was in the final stages of a substantial Navy contract, which made the “we’re staffing ahead of the announcement” story land as plausible rather than suspicious.

This is the scary part: none of the individual signals were wrong. The fraud wasn’t sloppy. It was methodical, and it was built by someone who understood how real corporate recruiting actually behaves.

The first real flag wasn’t technical. It was behavioral.

After Melanie sent her resume, the “recruiter” claimed it might not clear the applicant tracking system — not because of her experience, but because of formatting. That’s a plausible enough claim on its face. What wasn’t plausible was what came next: he wasn’t offering to reformat pieces of it himself, which is common practice among legitimate recruiters. He was referring her to a third-party resume writer.

Located in Nigeria. Specializing, supposedly, in resumes for the U.S. aerospace and defense industry.

That combination — a claimed specialization in a highly regulated, security-clearance-adjacent American industry, paired with geography that made no logical sense for that expertise — was the moment the story stopped holding together. Melanie’s instinct was right: the goal wasn’t a better resume. It was a foothold into her financial information, and potentially her device, through a “vendor” relationship dressed up as career help.

The second flag came from urgency. Once Melanie slowed down — citing a legitimate work deadline — the pressure increased. Repeated check-ins. Reminders that a hiring manager was waiting. Anyone, at any level, should treat urgency applied to a financial or personal-data decision as a signal to slow down further, not speed up.

Before responding to the resume-writer referral, Melanie did something simple that most job seekers never think to do: she asked whether the domain and sender were legitimate — through a general search, not the company’s own portal, and separately confirmed against the company’s official contact guidance. The company’s own site confirmed only two legitimate recruiting-related email formats existed, and neither matched what she’d received.

She also traced the “reviewer” whose testimonial vouched for the resume writer, and messaged that person directly. The response came back almost instantly, written in noticeably broken English inconsistent with someone in a “fairly high-level HR” role — and inconsistent with the AI-polished professionalism of everything else in the scheme. That inconsistency was the tell. The fraud was AI-assisted where it needed to look credible at a glance, but the human layer behind it — the improvised follow-up conversation — didn’t hold up.

Melanie did everything right, reported the incident to the company, and received a prompt, appreciative response. The company confirmed no one from their organization had reached out to her, and that the role didn’t exist as described.

And then — as far as she could tell — that was the end of it.

No public notice. No LinkedIn post warning candidates. No banner on the careers page. Nothing to catch the next person, even though there was a next person: someone else, targeted by the same actors weeks earlier for a different, lower-level role, at the same company.

This is the gap I want compliance and HR leaders to actually close, not just acknowledge. Receiving a fraud report is not the end of the process — it’s the trigger for one. At minimum, that process should include:

  • An internal escalation path that routes the report to IT, HR, and compliance simultaneously, not sequentially, so response time doesn’t depend on which department happens to open the email first.

  • A tabletop exercise, run before this happens rather than after, that walks through exactly what Melanie’s report set in motion — or should have.

  • External communication, even brief: a note on the careers page or a LinkedIn post confirming that job postings are always listed on the official site, and that unsolicited outreach should be verified through a specific channel.

  • Employee notification, particularly for anyone in a public-facing or recruiting-adjacent role whose name, likeness, or title could plausibly be spoofed next.

Banks have normalized this kind of fraud communication. Most employers haven’t, even though the exposure — reputational, legal, and to candidates’ financial safety — is comparable.

The old advice to job seekers still applies, just with a caveat: if it’s too good to be true, it probably is — but “too good to be true” no longer looks obviously fake. It looks like a director-level LinkedIn profile with a real logo and a plausible story about an unannounced Navy contract.

The tell that actually held up wasn’t a typo. It was a pattern: professionalism everywhere the fraud needed to survive a background check, and inconsistency the moment a live human had to improvise. That’s the distinction worth training people to notice — and it’s the distinction most fraud-awareness training still doesn’t teach.

Share

Leave a comment

Read the original on ethicaledge.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.