In the anxious space between employment and opportunity, a new kind of predator has taken root — one that wears the face of a recruiter, speaks the language of professionalism, and strikes at the moment a jobseeker is most hopeful and most vulnerable. Across the UK and beyond, young professionals navigating a competitive labour market are losing not just money but trust, as sophisticated scammers engineer fake hiring processes indistinguishable from real ones. The story of one victim losing £18,000 to malware hidden inside a coding assessment is not an anomaly — it is a signal of how thoroughl
Job Interview Scams Target Gen Z With Malicious Apps, Draining Savings
They felt they couldn't afford to be skeptical because opportunities felt so scarce
So this person lost eighteen thousand pounds because they downloaded a document during a job interview. How does that even happen? How does a document steal cryptocurrency?
The document contained malware—malicious code that gave the hackers access to their computer and their online wallets. Once they installed it, the hackers could move in and drain the accounts. It happened while they were asleep.
But here's the thing—we only have one victim's account. The BBC article mentions that others have reported similar attacks through Indeed, but we don't have numbers on how many people this has actually happened to. We know it's happening, but we don't know the scale.
Why is Gen Z specifically vulnerable? Is it just inexperience?
LinkedIn's data suggests it's more about the job market itself. Thirty-two percent of younger professionals face scam exposure, and many ignore red flags because they feel opportunities are scarce. When you're desperate for work, you take risks you wouldn't otherwise take.
That's LinkedIn's interpretation, though. We should be careful about accepting that framing wholesale. It's true that young people face a competitive market, but LinkedIn also has an incentive to explain away why scams are happening on their platform.
What makes these scams so hard to spot?
They look completely real. The victim went through a video interview, received what appeared to be a legitimate assessment on Google Sheets, and the software they downloaded had a digital signature—the kind of authentication that real apps have. It wasn't a obviously fake email.
The cyber-security researcher quoted in the piece, Charlie Kelly, makes that point clearly. But again, we're hearing about one case in detail. We don't know how many people have fallen for this or how many have spotted it and reported it.
What are the platforms doing about it?
LinkedIn and Indeed have both posted guidance about how to spot scams—verify the company is real, do research, don't download apps for interviews. But they're also acknowledging the structural problem: young people feel they can't afford to be skeptical.
The platforms are warning people, which is good, but the warning is essentially "be more careful." That's not a solution if the scams are genuinely hard to distinguish from legitimate hiring processes. And we don't have information about whether these platforms are taking down fake recruiter accounts or working with law enforcement.
The Pulse
- A UK jobseeker lost £18,000 in cryptocurrency overnight after completing what appeared to be a legitimate technical interview assessment embedded with malware.
- Scammers are no longer sending clumsy phishing emails — they are building full simulations of real hiring processes, complete with genuine Google pages, digital signatures, and professional video calls.
- LinkedIn data reveals a troubling pattern: 32% of Gen Z professionals report scam exposure, yet nearly a third admit to ignoring red flags because the fear of missing a job opportunity outweighs the fear of being deceived.
- Fake recruitment apps bearing names mimicking legitimate platforms are being used to harvest personal data and drain financial accounts, with victims often unaware until the damage is done.
- Both LinkedIn and Indeed have issued warnings and guidance, but acknowledge the structural vulnerability — in a tight job market, skepticism feels like a luxury young jobseekers cannot afford.
In the anxious space between employment and opportunity, a new kind of predator has taken root — one that wears the face of a recruiter, speaks the language of professionalism, and strikes at the moment a jobseeker is most hopeful and most vulnerable. Across the UK and beyond, young professionals navigating a competitive labour market are losing not just money but trust, as sophisticated scammers engineer fake hiring processes indistinguishable from real ones. The story of one victim losing £18,000 to malware hidden inside a coding assessment is not an anomaly — it is a signal of how thoroughly desperation can be weaponised.
A young UK professional, freshly between jobs and visible on LinkedIn, received what looked like a genuine recruiter message. The process that followed was convincing at every stage — a professional video call, a coding task delivered through a real-looking Google Sheet. They completed the work and went to sleep. By morning, £18,000 in cryptocurrency savings had been stolen by malware concealed inside the document.
Cybersecurity researcher Charlie Kelly described the attack as precisely engineered: real Google infrastructure, a digitally signed application, and a hiring simulation built to be indistinguishable from the genuine article. The victim, speaking anonymously, described the emotional toll as equal to the financial one — disbelief, anger, and a creeping confusion about how they had been caught.
The case reflects a broader surge documented by LinkedIn and Indeed, the world's largest recruitment platforms. LinkedIn's own data identified what it called a Gen Z 'Scam Gap': 32% of younger professionals encounter scam exposure, yet many knowingly overlook warning signs. The reason is structural — in a crowded job market, the perceived cost of missing an opportunity feels greater than the risk of trusting the wrong message.
Scammers exploit this calculus deliberately. Cybersecurity firm Malwarebytes documented fake recruiters directing candidates to install fraudulent apps — mimicking tools from Indeed or services like MyInterview — that, once downloaded, hand over access to private data and financial accounts. Both major platforms have since clarified that no legitimate interview requires installing a third-party application.
What makes these attacks so dangerous is their completeness. The victim had done nothing careless by ordinary standards — they verified the call, completed the task professionally, and encountered criminals who had engineered every detail. For jobseekers in 2026, the warning is not simply to be careful. It is to understand that the tools of exploitation have grown as sophisticated as the desperation they are designed to exploit.
A young jobseeker in the UK accepted what seemed like a straightforward opportunity. A recruiter had found them on LinkedIn, sent a message, and invited them to interview for a position. The candidate, who had recently handed in notice at their previous job and made their job-hunting status public on the platform, felt the familiar mix of hope and urgency that comes with an open market. They participated in a video call that looked professional. Then came the technical assessment—a Google Sheet document with instructions to complete a coding task. They finished the work, went to bed, and woke to find their cryptocurrency wallets emptied. Eighteen thousand pounds in savings, gone. The malicious software had been waiting inside that innocent-looking document.
This was not a clumsy phishing email or a obviously fake job posting. According to Charlie Kelly, a cyber-security researcher at Have I Been Squatted, the attack was designed with precision. The victim had been walked through what appeared to be a genuine interview process, complete with real Google pages and a legitimate Google login. The software they were asked to install carried a digital signature—the kind of authentication mark that legitimate applications carry. The scammers had built a trap that looked indistinguishable from the real thing.
The victim's emotional aftermath was as thorough as the financial one. "It's a horrible feeling to be out a substantial amount—something I wouldn't wish on my worst enemy," they said, speaking on condition of anonymity. After discovering the breach, they wiped their computer, changed every password, and found themselves exhausted in ways that went beyond the practical. "I felt a mixture of disbelief and anger—at the hackers and at myself. I was also confused until I figured out how they had got me."
This case is not isolated. LinkedIn and Indeed, the two largest professional recruitment platforms in the world, have both issued warnings about a surge in job scams over recent months. LinkedIn released data it termed the Gen Z "Scam Gap." The numbers were stark: 32 percent of younger professionals reported facing scam exposure, yet nearly a third of that same group admitted to ignoring red flags. The reason, LinkedIn explained to the BBC, was straightforward. In a crowded and competitive job market, many young people feel they cannot afford skepticism. Opportunities feel scarce. The cost of missing one seems higher than the risk of overlooking a warning sign.
The scammers exploit this pressure deliberately. Malwarebytes, a cyber-security firm, documented how fake recruiters use specific lures: "Complete your interview by installing the Indeed app" or "salary agreement available after app installation." The apps themselves—bearing names like a fake Indeed Interview tool or one called MyInterview—are designed to grant hackers access to private data once installed. That data can be used for extortion or, as in the case of the cryptocurrency victim, for direct financial theft.
Indeed has been explicit about this in recent guidance: interviewing through their platform happens entirely in a browser. No legitimate job interview requires downloading a special application. Any message asking a jobseeker to install an app to participate in an interview is not from the company. LinkedIn, for its part, has posted advice on its website about verifying that a company and job are real, and conducting thorough research before engaging. But the platforms acknowledge the structural problem: young people in a tight job market feel they cannot afford to be skeptical.
The sophistication of these attacks makes detection genuinely difficult. This was not a badly written email with a suspicious attachment. It was a complete simulation of a real hiring process, built to feel authentic at every step. The victim had done nothing obviously wrong. They had been cautious enough to verify the video call, professional enough to complete the assessment, and unlucky enough to encounter criminals who had engineered their trap with technical precision. For anyone job hunting in 2026, the message is clear: the competition for work is real, but so is the danger of the tools designed to exploit that desperation.
Notable Quotes
It's a horrible feeling to be out a substantial amount—something I wouldn't wish on my worst enemy— The victim, speaking anonymously
This person was walked through what looked like a real job interview, on real Google pages, behind a real Google login, and the software they were asked to install was digitally signed like any legitimate app— Charlie Kelly, cyber-security researcher at Have I Been Squatted