By Jackson Godwin. Cybersecurity Analyst & Penetration Tester.

The Job Never Existed
A few days after contacting the real company, I received confirmation that the recruitment email was fraudulent.
The organisation had not advertised the position.
The recruiter did not work for them.
The employment offer was fake.
Everything had been carefully designed to earn my trust long enough for me to hand over sensitive personal documents.
Fortunately, I verified the opportunity before sending anything.
The Biggest Warning Signs I Almost Missed
Looking back, several warning signs should have made me question the offer much earlier.
Here are the biggest lessons I learned.
đźš© I Was “Hired” Too Quickly
The entire recruitment process happened within a couple of days.
There was:
- No live interview.
- No technical assessment.
- No meeting with a hiring manager.
- No discussion about the role in detail.
While hiring processes vary between organisations, professional positions—especially technical roles—normally involve more than a simple questionnaire.
If an offer arrives unusually quickly, take time to verify it.
đźš© The Recruiter Asked for Sensitive Documents Too Early
The recruiter requested:
- My passport.
- National identification.
- Proof of address.
This happened before:
- Signing an employment contract.
- Verifying the company’s identity.
- Speaking with anyone from the organisation.
Many legitimate employers request identity documents during recruitment or onboarding, but you should first confirm that you’re dealing with the genuine organisation and understand why the documents are required.
đźš© The Email Address Was Slightly Different
The display name looked genuine.
The company logo looked genuine.
But the email address wasn’t the company’s official domain.
That tiny detail almost fooled me.
Always check the complete email address—not just the sender’s name.
đźš© I Wanted the Opportunity to Be Real
Perhaps the biggest warning sign wasn’t technical.
It was emotional.
The position matched my experience.
The salary was attractive.
The chance to work remotely sounded perfect.
Because I wanted the opportunity to be genuine, I almost overlooked the warning signs.
Scammers understand that excitement can reduce caution.
đźš© I Didn’t Verify the Recruiter Immediately
The easiest step would have been the first step.
Instead of assuming the recruiter was genuine, I should have verified their identity before continuing the recruitment process.
Fortunately, I eventually contacted the real company.
That single email prevented a potentially serious case of identity theft.
How to Protect Yourself From Fake Remote Job Scams
Today, I follow a simple checklist whenever I receive an unexpected job opportunity.
Research the Company
Before responding:
- Visit the company’s official website.
- Confirm the vacancy appears on official career pages where appropriate.
- Look for verified contact information.
Verify the Recruiter
If someone claims to represent a company:
- Check whether they appear on the company’s official website or verified professional profiles.
- Contact the company directly using official contact details if you are unsure.
Never rely solely on information provided by the recruiter.
Be Careful With Personal Documents
Don’t rush to send:
- Passports.
- National identity documents.
- Driver’s licences.
- Banking information.
First confirm:
- The employer is genuine.
- The recruitment process is legitimate.
- You understand why the documents are required.
Watch for Unrealistic Hiring Processes
Be cautious if:
- You’re hired without a meaningful assessment.
- The salary seems unusually generous.
- The recruiter avoids phone or video conversations.
- You’re pressured to act immediately.
One warning sign alone doesn’t prove fraud, but several together deserve careful investigation.
Trust Independent Verification
Whenever something feels unusual:
- Visit the organisation’s official website yourself.
- Contact the company directly.
- Verify before responding.
Independent verification is one of the simplest and most effective defences against recruitment scams.
Frequently Asked Questions
Do legitimate employers ask for passports?
Sometimes.
Employers may request identity documents during later stages of recruitment or onboarding, particularly where proof of identity or work eligibility is required.
Before sharing such documents, confirm that the request genuinely comes from the organisation.
How can I verify a recruiter?
You can:
- Check the company’s official careers page.
- Verify the email domain.
- Contact the organisation through official contact details.
- Look for consistent professional information from trusted sources.
If you’re uncertain, ask the company directly.
Is a quick job offer always a scam?
No.
Some organisations have fast recruitment processes.
However, if the process lacks reasonable verification, interviews, or communication—and is combined with requests for sensitive information—you should proceed carefully.
What should I do if I have already sent my passport?
If you believe you’ve shared identity documents with scammers:
- Contact the organisation whose document you shared (where appropriate) for guidance.
- Monitor your accounts and financial activity.
- Report the incident to the relevant authorities in your country if identity theft is suspected.
Acting promptly can help reduce the impact.
Final Thoughts
The criminals didn’t need to compromise my computer.
They didn’t need malware.
They didn’t need to hack my email.
They simply offered me something I genuinely wanted.
A remote job.
Fortunately, one habit protected me.
I verified the recruiter independently before sending my personal documents.
Today, I follow one simple rule whenever someone requests sensitive information during recruitment:
Trust the company’s official website—not the recruiter’s email alone.
In cybersecurity, protecting your identity is just as important as protecting your passwords.
Sometimes the most valuable document in your possession isn’t your CV.
It’s your passport.
About the Author
Jackson Godwin is a Cybersecurity Consultant specialising in Vulnerability Assessment and Penetration Testing (VAPT), Governance, Risk and Compliance (GRC), ISO/IEC 27001, PCI DSS, Cloud Security, AI Security, and Digital Risk Management.
With years of experience helping organisations identify vulnerabilities, strengthen security controls, and improve cyber resilience, Jackson is passionate about making cybersecurity practical, easy to understand, and accessible to everyone.
Through JacksonTechnology.com.ng, he publishes cybersecurity awareness stories, ethical hacking tutorials, compliance guides, cloud security insights, AI security resources, and practical online safety tips to help individuals and businesses stay protected against evolving cyber threats.
His mission is to educate, empower, and inspire safer digital habits—one cybersecurity story at a time.









