By Jackson Godwin. Cybersecurity Analyst & Penetration Tester.

By Jackson Godwin. Cybersecurity Analyst & Penetration Tester.
I Visited the Company’s Official Website
Instead of sending the payment immediately, I decided to verify one simple detail.
I opened a new browser window and typed the company’s official website address myself.
I didn’t use the link the recruiter had sent.
I wanted to see whether the recruiter actually worked there.
Within a few minutes, I noticed something strange.
Her name wasn’t listed anywhere.
The Email Address Didn’t Match
I went back and looked at the recruiter’s email carefully.
At first glance, it appeared legitimate.
But when I compared it with the email addresses published on the company’s official website, I noticed a small difference.
The company used:
@companyname.com
The recruiter had contacted me from:
@companyname-careers.com
It looked convincing.
But it wasn’t the same domain.
That small difference changed everything.
I Contacted the Real Company
To remove all doubt, I contacted the company’s HR department using the contact information published on their official website.
I explained that one of their recruiters had offered me a job and asked me to pay a refundable equipment shipping fee.
The HR representative replied later that day.
Their answer was short.
“The individual you mentioned does not work for our company.”
Then came another sentence.
“We never ask candidates to pay recruitment, processing or equipment fees.”
At that moment, I realised the entire recruitment process had been fake.
The LinkedIn Profile Wasn’t What It Seemed
After learning the truth, I looked at the recruiter’s LinkedIn profile again.
This time, I paid closer attention.
Several warning signs became obvious.
Many of the posts had very few genuine interactions.
Some profile photos looked like stock images.
Several recommendations appeared unusually similar in wording.
The profile had been carefully built to appear trustworthy.
It wasn’t created overnight.
It had likely been developed over months to gain credibility.
The Scam Was Built Around Excitement
The criminals understood something important.
Job seekers become excited when they receive an unexpected offer.
Especially when the role promises:
- Remote work.
- International opportunities.
- Excellent pay.
- Fast hiring.
Excitement can reduce caution.
Instead of questioning the process, victims focus on the opportunity.
That’s exactly what the scammers wanted.
Then Came the Payment Request
The equipment fee wasn’t very expensive.
It was just small enough to sound believable.
The recruiter explained that it covered:
- Laptop shipping.
- Security token registration.
- Employee onboarding.
Everything sounded professional.
The promise that the money would be refunded with my first salary made the request seem even more reasonable.
But legitimate employers rarely require candidates to pay upfront fees simply to start a job.
One Verification Saved Me
Looking back, one decision protected me.
I didn’t rely only on LinkedIn.
I verified the information independently.
Instead of trusting the profile, I trusted the company’s official website.
Instead of trusting the email, I contacted the organisation directly.
That simple verification exposed the scam before I lost any money.
The Attack Wasn’t Technical
The criminals never tried to hack my computer.
They never sent malware.
They never asked for my passwords.
Instead, they relied on something much simpler.
Trust.
They built a believable story, created a convincing online identity and waited for excitement to overcome caution.
That’s what made the attack so effective.
In the final part of this article, I’ll explain the biggest warning signs of fake LinkedIn recruiters, share practical tips for verifying job offers, and reveal the simple rule I now follow whenever an unexpected recruiter contacts me online.
Continue Reading: The LinkedIn Recruiter Who Was Actually a Scammer (Part 3)






