Normal view
-
/r/netsec - Information Security News & Discussion
- Malicious Coding Agent Skills and the Risk of Dynamic Context | Datadog Security Labs
-
/r/netsec - Information Security News & Discussion
- AI Vulnerability Research and the Fuzzer Era Dรฉjร Vu
-
The Register - Security
- US bank reports itself after slinging customer data at 'unauthorized AI app'
US bank reports itself after slinging customer data at 'unauthorized AI app'
RubyGems Suspends New Signups After Hundreds of Malicious Packages Are Uploaded
New TrickMo Variant Uses TON C2 and SOCKS5 to Create Android Network Pivots
-
/r/netsec - Information Security News & Discussion
- I spent a weekend trying to get OpenClaw to leak my own personal data and it caught me immediately...
The New Gradโs Guide to Job and Recruitment Scams
Graduation season should be about launching your career, not dodging scams.
But for many new grads, the job search now comes with a hidden risk: fake recruiters, fraudulent job offers, and convincing messages designed to steal money, personal information, or both.
The threat is larger than many people realize. According to McAfeeโs 2026 State of the Scamiverse report, 76% of Americans have encountered a scam, and the average person receives 14 scam messages every day through text, email, and social media. Americans now spend an estimated 114 hours each year trying to figure out what is real online and what is not.
Young adults are among the most heavily targeted groups. Nearly 3 in 10 people ages 18 to 24 (28%) report receiving conversational scams that begin with casual outreach such as โHey, how are you?โ or a โwrong numberโ text. Those same tactics increasingly appear in fake recruiter messages, LinkedIn outreach, and texts promoting remote job opportunities.
Todayโs job scams can look highly professional. Scammers build polished LinkedIn profiles, clone legitimate company websites, and even use AI-generated interviews to appear credible. Many scams unfold quickly, with nearly half completed in less than an hour, creating pressure to act before candidates have time to verify what is real.
Thatโsย where tools likeย McAfeeโs Scam Detectorย come inโflagging suspicious emails, texts, links, and messages before you engage, so you can tellย whatโsย real before you click.ย
Hereโsย how to avoid jobย scamsย and stay safe with McAfee:ย
How Job Scams Actually Work
|
Step |
What Happens |
Red Flags |
What Scammers Want |
|
1. The Outreach |
Youโre contacted via email, text, or social media about a job |
Unsolicited offer, vague role, overly enthusiastic recruiter |
Your attention |
|
2. The Build-Up |
They walk you through interviews or onboarding steps |
No video calls, inconsistent details, fast timeline |
Your trust |
|
3. The Ask |
They request personal info or payment |
SSN requests, bank info, โtraining feesโ |
Identity + money |
|
4. The Trap |
They escalate the situation or disappear |
More payment requests or sudden silence |
Continued financial gain |
A Real Example: How People Get Pulled In
Even experienced professionals fall for these scams.
In one case, a tech expert with decades of experience lost $13,000 after accepting what looked like a legitimate part-time role reviewing products.
The opportunity seemed real:
- A polished website
- Structured onboarding
- A small initial payout
Then came the shift. He was told he needed to deposit money to continue working and kept paying more to โunlockโ earnings that never came.
This type of advance fee scam is increasingly common in job fraud, and it works because it builds trust first.
What the Data Says
Recent graduates are entering the workforce at a time when scams are more sophisticated, more personalized, and harder to spot than ever before. McAfeeโs 2026 State of the Scamiverse report highlights why younger job seekers should be especially cautious.
Young Adults Face Higher Risk
- Younger adults report the highest rates of repeat scam victimization. McAfeeโs research found that scam victims under 35 are more likely than older adults to be targeted again, suggesting that early-career professionals may be especially vulnerable as they navigate job searches, salaries, and onboarding for the first time.
Scam Messages Are Constant
- Americans receive 14 scam messages per day on average.
- 76% of Americans say they have encountered an online scam.
- People spend 114 hours per year, nearly three full workweeks, trying to determine what is real and what is fake online.
Professional Platforms Are Not Immune
- 7% of respondents reported encountering scams on LinkedIn.
- 44% have replied to suspicious messages that contained no link at all.
Many modern scams begin with a simple message such as โI came across your profileโ or โWeโd like to discuss an opportunity,โ rather than an obviously suspicious URL.
Job Scams Move Fast
- The average scam unfolds in just 38 minutes.
Scammers often create urgency by claiming a role is limited, an offer will expire quickly, or onboarding must begin immediately.
AI Makes Fake Recruiters More Convincing
- 35% of Americans are not confident they can spot deepfake scams.
- McAfee predicts job scams will become increasingly personalized as scammers use AI to create tailored outreach, onboarding documents, and contracts that closely match a candidateโs background.
Job Scams Are a Growing Financial Threat
- FTC-reported job scam losses rose nearly 40% year over year, increasing from $543 million in 2024 to $752 million in 2025.
For new graduates eager to land their first job, the lesson is simple: if an opportunity seems rushed, asks for money, or feels too good to be true, take a step back and verify before you respond.
Where McAfee Comes In
Job scams donโt just happen in one moment. They unfold in stagesโfirst a message, then a conversation, then a request for information or money.
Thatโs why protection needs to work the same way: across the entire experience. McAfeeโs comprehensive protection helps you stay ahead of job scams at every step:
McAfee+ Advanced gives you multiple layers working together so you are not left figuring it out after the damage is done:
- Identity Monitoring alerts you if your personal info shows up where it should not, so you can act fast
- Personal Data Cleanup helps remove your information from data broker sites, making you harder to target in the first place
- Scam Detector flags suspicious texts, emails, links, and even deepfake videos before you engage
- Safe Browsing helps block risky sites if you do click
- Device Security helps detect malicious apps or downloads
- Secure VPN keeps your data private, especially on public Wi-Fiย ย
The Biggest Red Flags to Watch For
These patterns show up again and again in job scams:
|
Red Flag |
What It Looks Like |
Why Itโs a Problem |
What to Do Instead |
|
Requests for Sensitive Information Too Early |
Asked for your Social Security number, banking info, or ID details early in the process |
Scammers use this to steal your identity or access your accounts |
Only share sensitive info after accepting a verified jobโand through secure onboarding systems |
|
Youโre Asked to Pay to Work |
Fees for training, equipment, onboarding, or background checks |
Legitimate employers donโt charge candidates to get hired |
Walk away immediatelyโthis is one of the clearest signs of a scam |
|
The Job Sounds Too Good to Be True |
High pay, low hours, minimal experience required, vague responsibilities |
Designed to hook attention and lower your guard |
Research typical salaries and ask detailed questions about the role |
|
The Hiring Process Moves Too Fast |
Immediate job offers or rushed decisions without interviews |
Real hiring processes involve multiple steps and evaluations |
Be cautious of offers that skip standard hiring steps |
|
No Real Interaction |
Communication only via email or chat, refusal to do video or phone calls |
Scammers avoid real-time interaction to stay anonymous |
Request a video call or verify the recruiter through official company channels |
How to Protect Yourself
You donโt need to overcomplicate it. Stick to a few grounded habits:
- Verify the company independently: Search the company, check official sites, confirm recruiter identities
- Keep communication on trusted platforms: Be cautious with offers coming from unexpected channels
- Never pay upfront for a job: Thatโs a dealbreaker
- Pause before sharing personal information: Especially early in the process
- Use tools that flag risks automatically: Scam Detector helps catch what looks legitimate, but isnโt
What to Do If You Think Itโs a Scam
If something feels off:
- Stop communication immediately
- Do not send money or personal information
- Report the scam to the FTC
- Monitor your accounts for suspicious activity
If youโve already shared sensitive information, act quickly to secure your accounts.
With McAfeeโs comprehensive protection, youโre not left to figure it out on your own.
From blocking risky links to monitoring your identity and helping you respond quickly, itโs designed to help you stay one step ahead, and recover faster if needed. Because job searching is stressful enough without scammers, and you deserve to land your next job with confidence.
The post The New Gradโs Guide to Job and Recruitment Scams appeared first on McAfee Blog.
Cache-poisoning caper turns TanStack npm packages toxic
-
The Hacker News
- Webinar: What the Riskiest SOC Alerts Go Unanswered - and How Radiant Security Can Help
Webinar: What the Riskiest SOC Alerts Go Unanswered - and How Radiant Security Can Help
-
The Hacker News
- Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages
Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages
Why Agentic AI Is Security's Next Blind Spot
Apple, Google drag cross-platform texting into the encrypted age
-
/r/netsec - Information Security News & Discussion
- Curl lead developer Daniel Stenberg provides insightful feedbacks from Mythos analysis results
New ipTIME Pre-Auth RCE in CWMP
A pre-auth remote code execution vulnerability was found in the CWMP implementation of ipTIME routers, allowing unauthenticated attackers to execute arbitrary code remotely.
[link] [comments]
Postmortem: TanStack npm supply-chain compromise
Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak
-
The Hacker News
- OpenAI Launches Daybreak for AI-Powered Vulnerability Detection and Patch Validation
OpenAI Launches Daybreak for AI-Powered Vulnerability Detection and Patch Validation
-
The Register - Security
- Japanโs PM orders cybersecurity review to stop Mythos going full CyberZilla
Japanโs PM orders cybersecurity review to stop Mythos going full CyberZilla
-
The Hacker News
- iOS 26.5 Brings Default End-to-End Encrypted RCS Messaging Between iPhone and Android
iOS 26.5 Brings Default End-to-End Encrypted RCS Messaging Between iPhone and Android
Welcoming the Bangladesh Government to Have I Been Pwned
Today, we welcome the 43rd government onboarded to Have I Been Pwned's free gov service, Bangladesh. The BGD e-GOV CIRT department now has full access to query all their government domains via API, and monitor them against future breaches.

Bangladesh joins a growing list of national governments using HIBP to help protect their public sector digital assets, and we look forward to supporting their efforts to identify exposure of government email addresses in data breaches and respond quickly when new incidents appear.