By Jackson Godwin. Cybersecurity Analyst & Penetration Tester.

I Started Investigating the Recruiter
Instead of sending my passport immediately, I decided to verify who I was dealing with.
I searched for:
- The recruiter’s name.
- Their email address.
- Their LinkedIn profile.
- The company’s official recruitment page.
Something didn’t add up.
The company was genuine.
The recruiter wasn’t.
I couldn’t find any evidence that this person actually worked there.
Then I Looked at the Email Address
At first glance, the email looked professional.
It contained the company’s name.
But when I examined it more carefully, I noticed a subtle difference.
One extra word.
A slightly different domain.
It wasn’t the company’s official email address at all.
It was designed to look almost identical.
That small difference could easily fool someone who was excited about getting a job offer.
The Offer Came Too Easily
Looking back, the hiring process had been unusually fast.
Within two days I had supposedly:
- Applied.
- Completed a questionnaire.
- Passed the assessment.
- Received a job offer.
There had been:
- No technical interview.
- No video meeting.
- No discussion with a hiring manager.
- No detailed verification of my experience.
For a professional cybersecurity position, that should have raised immediate questions.
Legitimate employers normally take time to evaluate candidates.
Then the Requests Became More Personal
After asking for my passport, the recruiter sent another email requesting additional information.
This included:
- My home address.
- My date of birth.
- A scanned identification document.
- Banking information for “salary setup.”
I hadn’t even signed an employment contract.
Yet they were already requesting highly sensitive personal information.
That didn’t feel right.
I Contacted the Real Company
Rather than replying to the recruiter, I visited the company’s official website.
I found their verified contact details and sent an email asking one simple question.
“Does this recruiter work for your organisation?”
The reply arrived the next day.
Their answer was clear.
They had never heard of the individual.
The email was fraudulent.
Someone was impersonating the company’s recruitment team.
The Goal Was Never Employment
The criminals weren’t trying to hire me.
They were trying to collect personal documents.
Copies of passports and identity documents can be valuable to criminals for identity-related fraud.
The fake job offer was simply the bait.
The real objective was obtaining sensitive personal information.
Excitement Almost Overruled Caution
What made the scam effective wasn’t sophisticated hacking.
It was hope.
The salary looked attractive.
The company appeared genuine.
The opportunity matched my career.
For a moment, I wanted the job to be real so badly that I nearly ignored the warning signs.
Scammers understand that emotions can cloud judgment.
One Verification Saved My Identity
In the end, I didn’t expose the scam through advanced technical skills.
I exposed it by asking one simple question.
“Does this recruiter actually work for this company?”
That independent verification stopped me from sending copies of my passport and other personal documents to criminals.
Sometimes, cybersecurity begins with slowing down long enough to verify before you trust.
In the final part of this article, I’ll explain the biggest warning signs of fake remote job offers, share practical ways to verify recruiters safely, and reveal the simple rule I now follow before sending any personal documents during a recruitment process.
Continue Reading: The Fake Remote Job That Asked for My Passport (Part 3)









