Someone is impersonating us in a recruiting scam
kapwing.com
kapwing.com
About a year ago I was on the job market and multiple recruiters reached out to me with the exact same job listing, just with the company name removed. All of them claimed to have an exclusive relationship with the company and they were working directly with the hiring manager. With 5 minutes of Googling I found the original position and the company that posted it.
Do they get penalized if they present a candidate for the job and the company says "No recruiters" and they remove the candidate from their candidate pool?
Enough hiring companies only care about getting a seemingly qualified applicant in for an interview and will ignore what ever shady things recruiters do.
It takes like four seconds.
If neither a renter or the landlord have an agreement to pay an agent, why would the agent be owed any money?
The person that agreed to pay agent is still the landlord. In times when supply of apartments exceeds demand from renters, landlords have to pay the agent from their pocket.
But the point is that in all cases, someone agreed to pay an agent. The agent did not simply materialize and obtained a right to collect money from someone.
Meanwhile in the past when we were looking, a mediocre one tried to get us to sign an exclusivity deal that we'd agree to use him until we chose to cancel (no stipulations there at least, though legally I don't know if he could have, but still, into perpetuity unless we canceled) for -any house in the entire state-.
>most will show you homes for free
I'm still looking for that real estate agent that does anything "for free".
In a nutshell: a real state agent is an agent, which has a specific legal meaning and legal requirements, and that relationship can't just be hijacked by posting someone else's listing.
A friend asked me if he could use me as a reference, and I said sure.
A few days later I got a call asking about my friend, and I readily engaged because I took being a reference seriously. As we were winding up, he suddenly asked if I was looking for a position. I then began to realize it was the recruiter - who was recruiting off the reference list of my friend. I was gracious (but pissed off, because I think the whole thing might have not been about my friend but recruiting).
Recruiters who merely repost the same listing that the company posted without adding any value, deserve to go out of business. Mind you, if every listing contained the hourly rate or pay range, they'd have a much harder time inserting themselves where they don't belong.
There's also the downside that some scummy person is representing themselves as being affiliated with you, when they're not. So if they do scummy things to the candidate (which they likely would, given what they're doing to you), then you are painted in a bad light. Think of situations that HNers complain about here, and then imagine that it's your company being (wrongfully) dragged for having lousy interviewing practices.
I generally respond (as a candidate) to get a sense of the problem. I can assure you that bad representation is the biggest problem. It’s not uncommon for recruiters to say something really problematic (bluntly racist or sexist) or impose excessive interview steps to filter candidates, without knowledge of the industry. I often know the hiring manager well enough to give feedback and they are generally horrified.
I'm actively interviewing for new positions, and the amount of stuff that startups (most out of Silicon Valley) are doing is absolute batshit. From 2-hour tech screens to 19-hour unpaid interviews WORKING ON THEIR OWN CODE BASE, I will not be surprised when the DoL does a crackdown on the interview process. I have been in the software development industry for decades. If you can't tell if a candidate qualifies after 45-90 (tops!) minutes of interviews, you may want to look internally for problems. All they are really doing is rejecting a ton of super smart developers, many who may have disabilities.
Oh, and then there was that one company who told me I had no knowledge of a language and framework I am actively contributing to, and have built robust, scalable enterprise apps out of. "We are looking for experts of <language x> and also <framework y> and <framework z>." That was literally the message they sent me. They did NOT know about my contributions because my dumb ass tries not to show off stuff like that when looking for employment as I want to be weighed on my ability to write awesome code and not weighed on a popularity contest.
I know you likely learned from this, but it's worth repeating especially for people who don't often go looking for jobs.
Getting hired is a sales process. You are the product. It doesn't really matter what you can do - that's probably not what you are selling to the interviewer.
What you are selling is the fact that _you_ (and you alone) are the best choice for the position. That means a combination of skill set and personality.
So specifically, being "popular", or "known", or "admired" in the tech community is a feature, one which is very valuable to potential employers. Being popular means you're (probably) not a dick, and that's worth knowing.
I say this with respect, but there were likely a bunch of folk they interviewed who can write code just as awesome as yours (at least in their eyes). I don't mean that to demean you, but clearly a) it's impossible to determine code awesomeness in an interview - it takes months for awesome code to even surface - and b) there are a _lot_ of people out there writing awesome code.
In Western culture it is considered polite to be modest, but being modest in an interview, or on a CV is a bug, not a feature. You need to sell, and sell hard, every possible accomplishment - without being a dick.
Writing awesome code is not enough. Fitting in with the team (ie demonstrating social skills), having deep knowledge of some framework (enough to contribute, and have those contributions accepted), publishing or presenting at conferences (ability to communicate and articulate), are all huge box ticks in the recruiting process.
Don't. Be. Shy.
How many good candidates were scared away by the sketchy recruiter? There's no way to know.
Of course, with that said, there was some service a few years ago (maybe it's Doordash?) that was generating landing pages and buying domains pretending they were the restaurant. But that's also very shady.
From what I head, the various delivery services have been setting up websites that pretend to be the actual restaurant's site, but list their own phone number. So they're committing fraud, too.
See:
https://www.forbes.com/sites/forbeshumanresourcescouncil/202...
Incidentally, the search for "recruiter (fraud|scam)" turns up a distressingly high number of hits, many from companies targeted:
It wasn't until the recruiter tell me to proceed with the on-site interview would I learned that in fact, the company the recruiter is seeking candidates for is the same company I applied and failed earlier. This leaves me scratch my head why the company didn't respond to job posting I applied directly, but decided to pick me up when I was referred to by recruiter. They could have turned down recruiter's referral about me and I won't be surprised one bit.
He did a better job, and maybe that is worth the additional money? Do you think your employer would have found the same candidate by just relying on the job listing on Indeed?
So they provided no positive value; in fact they provided negative value by adding duplicate listing and making them harder to navigate. I don't thin
A person with a linkedin profile, that looks very legit saying they work for Nike at a senior level position reached to my gf for a job role. Well, at first she was excited and then she forwarded me their profile. It was really good presentation, however, few things were way off. Like the timelines on their profile were not accurate. The related experience was shady and more. As I dig deep I was convinced its a scam.
I reported the profile to Linkedin.
It appears that LinkedIn has a problem not only with the tsunami of everyday recruiter spam flooding out their primary value proposition (real biz connections), but now criminal scams exploiting their platform.
Seems like one of those tipping point phenomena, that doesn't seem critical, until it is, and by then, it's too late and mostly all of the customers have decided they're done with it.
I finally had to resort to blatant Twitter shaming to get LinkedIn to address the problem.
All I can say is that while legit "cold" recruiting outreach happens all the time, if you are a job seeker take the time to verify these contacts. Don't give out personal or contact information until you are absolutely sure you know who you are talking to! A professional will not mind you taking this extra step.
Thanks for writing about all this and warning people :-)
I wonder how much the actions Kapwing took has reduced the amount of scam attempts -- if you happen to know? Maybe hard to measure
The email almost got shitcanned, because it was so scruffy.
The subject was just "Hello From Apple." There was no HTML in the email, and the letter was really short.
It may have been an auto-generated one.
It never turned into anything, but it was a legit contact.
It was legit. Didn't see it until someone reached out a different way. A bit funny how their own platform failed them.
This is all bullshit. Companies should accompany any request for personal information with a document signed by their private key, so I can verify it with the company's public key. Wasn't PKI invented in the 1980s?
(Without messing up other things the company is doing)
Rewarded... Maybe profit sharing? Then could pay back to do what's good for the company?
Look: https://news.ycombinator.com/item?id=32094120
I asked how to fix that (what are your thoughts?)
I'd like to try that :-)
(among some other things, like profit sharing for everyone, so that doing what's good for the company is good for oneself)
The con really preys on people's hopes - promise them a higher paying job, hopes of a better life, then casually extort them right at the end.
I don't understand what scammers get out of doing this. How do they make money?
> For example, in this case, candidates received the “offer letter” with our old company logo in the letterhead instead of the new logo we introduced recently. The offer letter was also signed by a random "Advisor" named Tom Gahm (who actually doesn't exist) rather than the CEO.
The reported heist of $xxx in Axie crypto by takeover of the majority of nodes, was organized N Korean group that created an entire fake company in linkedin and related story and web presence... The group used the mark - a senior engineer at axis - as a gateway to the nodes themselves, under the pretense of recruitment.
The engineer went thru a very formal interview process, during which he received a PDF with sophisticated malware trojan.
Food for thought.
How does a senior engineer have control over millions of dollars without review?
I also am somewhat skeptical of this one-click PDF hack. They used a zero-day for this attack? In Chrome? Why hasn't this been discussed if so?
We had an employee compromised by a similar attack-executable linked in a Pdf.
Basic flow was-phisher asked employee to sign a document relating to customs. The phisher had gathered that this employee works with shipping claims and returns, and surmised that they need to deal with customs documents requiring signature. There was a link to an exe hosted on a European cloud service in the PDF titled "install fake signature certificate company to sign this document". This directed to a download of a basic ransomware executable. This did get past our AV to the point of encrypting the employee's machine, but thankfully was blocked from spreading to the rest of the network.
The employee's machine was toast, but I was able to restore from the prior day's backup and no major harm occurred. I was able to see the phishing attack since we use gsuite email so the ransom ware didn't erase the employee's inbox, but they did lose a half-day work and I updated our training. The attack itself was clever from a social engineering perspective, but the technical exploit was something any script kiddy could have downloaded from the open web, nothing advanced at all. But Gmail doesn't always scan links in PDFs, so a clever ruse was able to bypass Google's scanning as well as our local scanning.
I have no idea if they successfully scammed anybody.
One thing I did that is not mentioned in this article is that I contacted the police. The police took a statement and collected all the relevant files (e.g., the PDF job offers I had been sent).
There was, unfortunately, not much the police could actually do. But having an official police report helped in my next step, which was to start an internet-wide game of whack-a-mole with the scammer's website. I'd identify the hosting company, send them an abuse report, citing the police report, and request the website be taken down. The hosting company would usually comply within 24 hours, then a week or so later the website would reappear using a different host. Lather, rinse, and repeat several times until the scammer gave up (or moved to a different domain that I have not discovered yet).
This is why the Nissan.com guy could keep the domain, since he wasn't selling cars. If he'd been using the domain that could be argued to be impersonating Nissan the car company, he would have lost ownership.
Why is she calling this "elaborate"? It's typo-ridden, done from random gmail addresses, and worse. I get "Nigerian Central Bank need you help transfering $40 million to you account" spam that looks better-done than this scheme.
Edit: 's/is he/is she'
Seriously though - a big focus of corporate phishing training is “watch out for typos”, which is insane. If that’s our main indicator of phishing we’re toast.
It's been a combination of fake linked accounts reaching out to unsuspecting people and getting them to pay in return for getting priority access to the recruitment queue. Sadly, it works - we have had people show up at our offices for their non-existent interview. They tend to get very irate when you explain that they were scammed.
The important thing is to educate people (for example do not give your bank information over the phone ever, except if you are the one who called maybe) and have good insurances in case something like this happens. And I believe it could happen to any of us, even people who think they're not gullible.
Every now and then I'll read about an online phishing/spear-phishing scam and think "Wow, that is really good. I definitely may have fallen for that!" (e.g. the "delayed disconnect" phone scam - TBH I didn't even realize some landlines worked like that.) This is not one of those times.
Many years ago now but I did get a job offer out of grad school on the basis of a mass mailed job application cover letter/resume. (And this was with a major aerospace company.) Only did a site visit/interview after I asked for it.
When we conversed about non-technical things, the interviewee spoke clearly and fluently. But when we'd ask a targeted technical follow-up to something on their resume, they would always repeat the question slowly, and then robotically with several pauses say their answer back. Another interviewer said they could hear the voice in the earpiece talking in between their pauses.
I'm not sure what their end goal was with getting hired, but we ended up cutting the panel short.
Especially young folks, excited by their great new gig, are likely to be unclear on where, exactly, the line is, or not think through the implications of things happening in the wrong order. (At my current gig, one of the first things HR did after we signed was ask me for direct deposit info.)
Sorry if it came out that way, that wasn't my intent. Fake jobs were not a thing that I encountered when entering the market, but I almost certainly would have fallen for anything that wasn't utterly incompetent.
> We just often don't have a choice.
This isn't new. I grew up very poor, and it wasn't until my mid-30's that I had things paid off and could start thinking about what economic security might feel like someday.
What's new is that middle-class young people are starting to have that experience, too.
Short of it is that, no, they do not need your specific authorization to initiate a withdrawal. Here's how ACH works:
1. One banking institution is the ODFI - originating depository financial institution, that makes the request. The other is the RDFI - receiving depository financial institution. In order to make a withdrawal, the ODFI sends the RDFI an ACH request that says "For this routing number (which determines the RDFI), for this account number and account holder name, debit $XXX amount and send it to me, the ODFI." No other authorization is necessary from the account holder.
2. The RDFI will send the ODFI (basically, the ACH process is more complicated) the money, BUT the RDFI has 90 days I believe (maybe longer) to pull the money back (search for "R10 ACH response code). If they do, the ODFI is left "holding the bag" and must return the funds. Thus, it's up to the ODFI to ensure that the user who initiated the withdrawal in the first place is authorized to do so.
Thus, a common ACH scam is:
1. Bad guy opens account at some financial institution with a stolen identity.
2. Many fintechs and online banks use Plaid to link to an account at an external institution to transfer funds. If the bad guy somehow has stolen credentials, then they link Plaid to that external account.
3. Bad guy initiates the ACH. Most ODFIs will then hold the funds for 2-5 days (depends on how long the account has been open, there are banking rules about how long they can hold it) specifically because of this return possibility.
4. Bad guy then tries to withdraw the money as soon as they can. If the original account holder doesn't notice the money missing from their account for, say, 2 weeks, the bad buy will have gotten the money and the ODFI is the one that has to make good on the stolen funds.
Google "ACH Fraud". It's a common problem with startups that don't realize all the intricacies and problems of the NACHA rules.
Thank you for taking the time to share this information about ACH scams.
I once got an offer letter with typos, after just a phone screen.. and it was totally legit! I worked there for a while
1. Asking you for a fee if you are hired. Staffing fees should be paid by the employer on top of agreed to compensation to the employee. In fact, if you a direct hire, you shouldn't even know what the recruiter is getting, but they should tell you they are getting paid.
2. Asking you to pay for or buy equipment that will belong to the company. Telling you we'll give you money to buy a Mac and other gear. Any legit company will simply ship the equipment to you, usually pre-configured.
3. A non-company domain for emails.
4. Unrealistic compensation. Who wouldn't want to edit video for $187K/year ($90/hr)? This is very high.
Had the scammers linked back to a domain or website that looks similar to your brand, THAT is detectable and there are services that can help here.
It could last about 45 days. After the first missed paycheck, they could drag 2 more weeks on "bank transfer issues".
Depending on the person, even 60 days...
They could potentially get 2 months of senior video editing free of charge. Sell this on Fiverr and make more money they were asking the candidates.
Did they copy part of this list of perks from a 15-year-old scam script?
Neither in the linked article nor in the comments here I found a real financial damage - other than huge waste of your time and loss of personal data.
Anyone any clue on this?
https://www.cnet.com/personal-finance/crypto/a-fake-job-offe...
The other way I fought back was to create a bunch of fake gmail addresses and keep in touch with them and waste their time. They hate it when you waste their time. But time wasted for them means money saved for someone.
A scam would need to ask e.g. my credit card data, but at this point it's pretty clear that it's not to send me money.
I am not in the US. Is that different there? Like do you use the same numbers for both? Or do people just not know the difference?
> Please note that, on acceptance of this employment offer, the following equipment will be deliver to you to set up your home office, the funds for the purchase of the equipment will be made available to you prior to purchase and delivery.
They will send you a $15k check, you'll buy the equipment, and Venmo them back the remainder. Meanwhile, the check bounces.
The government is supposed to come after any fraud here with heavy criminal charges, it's essentially a check forgery but I don't think it's too busy or too successful doing this.
I can allow a company to withdraw directly, but still it's clear I'm doing it (and I don't use that, I hate that feature).
Feels like it just prevents such scams. Of course then you can still convince people to "lend" you money ("send me 5k to leave my country and when I'm safe I send you 2M"), but that's slightly different.
Not sure if this is the origin, but wiktionary lists it as "(rare) the sound of a bullet richochet"... KA-PWING!
is this how the company name is pronounced?
Also check out our blog post about the name :) https://www.kapwing.com/blog/why-we-chose-an-onomatopoeia/
I laughed for a good 2 minutes at this one. You have to admire the chutzpah of some of these scammers.
I’d expect that to happen sometime around Christmas :p
Also not fond of hosts that put watermarks on media as it contributes to a kind of bit-rot.
We used to make it free to remove the Kapwing watermark, but needed to up our conversion recently to extend runway and fund R&D. Just shot every creative tool in our space leverages watermarks as a conversion lever because it means we can offer most things for free.
I'm trying to find some examples, but naturally there's none to be seen as soon as I look.
The comments contain unusual English, perhaps computer generated, and consist of an initial sentence, followed by a quoted hyperlinked sentence linking to kapwing.
I assumed these were an attempt by kapwing, and if that's not the case, I apologise for my accusation.