1. Spot the Red Flags
- Unsolicited contact: Be immediately suspicious of unexpected calls, texts, emails, or direct messages—even if they appear to come from a known company, bank, or agency.
- Artificial urgency: Scammers create pressure using panic or excitement (e.g., "Your account will be suspended in 15 minutes" or "You won a prize, claim now"). Real organizations give you time to think.
- Irreversible payment requests: Never pay via wire transfers, gift cards, crypto, peer-to-peer payment apps (like Zelle or Venmo) to strangers, or unexpected pressure to send cash.
- Requests for sensitive access: Legitimate companies will never ask for your multi-factor authentication (MFA) codes, full passwords, or remote access to your computer.
2. Core Rules of Defense
- Disconnect and verify independently: If you get a suspicious message from a bank or service, hang up or close the message. Look up the official customer service number on your physical card or main website and call them directly.
- Slow down the interaction: Take a breath. Scammers rely on high emotion to override critical thinking. Taking 10 minutes to step away usually breaks their spell.
- Never click raw links: Hover over links to check the full web address, or better yet, navigate to the site manually through your browser bookmark or search engine.
- Keep your security tight: Enable two-factor authentication (2FA) using an authenticator app rather than SMS where possible, and use strong, unique passwords across all accounts.
3. What to Do If It Happens
- Report immediately: Contact your bank or payment platform right away to freeze accounts or dispute charges.
- Report to authorities: File a report with local law enforcement and national consumer protection agencies (like the FTC in the US or your local equivalents).
- Break the stigma: Remind your readers that scammers are professional manipulators, and falling victim is nothing to feel ashamed of.
If they had your resume, they likely got it through one of a few common channels:
- Public Job Boards & Portfolios: If you uploaded your resume to sites like Indeed, Monster, ZipRecruiter, or LinkedIn—or attached it to a personal website—scammers often scrape these public databases or set up fake employer accounts to collect contact details.
- Data Breaches: Job application portals, recruitment agencies, or company databases occasionally suffer data breaches, exposing stored applicant files and contact lists.
- Phishing / Fake Job Listings: Scammers post fake job ads on real job boards. When candidates apply with a resume, the scammers harvest the phone number, email address, work history, and location.
How to Spot Job-Related & Resume Scams:
- Unsolicited Interviews or Offers: Be cautious of companies reaching out to offer an interview or job offer without you explicitly applying, especially if the offer arrives via text or messaging apps (like Telegram, Signal, or WhatsApp).
- Vague Communication & Overpayment: Be wary if the "recruiter" communicates exclusively via text/email, skips a video or face-to-face interview, or offers to send a check to buy home-office equipment.
- Check the Domain: Always inspect the sender's email address. Scammers often use free addresses (companyname@gmail.com) or lookalike domains (@company-careers-jobs.com instead of @company.com).
How to Protect Your Resume Data Going Forward:
- Remove Sensitive Details: Never put your home address, driver's license number, or reference contact details directly on a public resume—city and state, phone, and email are sufficient.
- Use a Dedicated Contact: Consider using a secondary email address specifically for job applications and public profiles.
Scammers intentionally invent roles that sound slightly specialized or temporary (like a "two-week remote English language specialist") because:
- It creates artificial urgency: A short two-week gig makes you feel like you have to act fast before the opportunity disappears.
- It flatters your background: Using real skill keywords from your resume makes it feel tailored, even when the company's actual operations have nothing to do with that work.
- It explains away weird processes: Labelling a short-term contract gives them an excuse for why the onboarding feels informal or handled off their main platform.
Key Takeaways to Protect Yourself:
- Always trust your red flags: If an email or offer passes your initial check but something still feels off, don't ignore that feeling. Keep investigating until you get clarity.
- If it sounds too good to be true, it usually is: Whether it's an overly generous remote rate or an effortless hiring process, trust your instincts when something feels off-balance.
- Go directly to the company: While reporting to agencies like the FCC gives you a official paper trail, notifying the security team of the impersonated company directly often yields much faster results.
- Personal details aren't proof: Just because someone has your resume or knows your background doesn't mean they are legitimate. Data gets scraped from job boards constantly.
- Verify on the official source: Never rely on a recruiter's word. Search the company's main portal independently to confirm the job ID and title exist.
- Beware of "HR friction": Rigorous paperwork and tough interviews can be psychological tricks to make you chase them.
Scammers count on us feeling too embarrassed to speak up. By sharing our stories and reporting these attempts, we take away their power.