That request is a strong signal that the offer is fraudulent. In the campaigns described, victims may receive a fake paycheck or check, then be asked to forward part of the money for supplies, shipping, or fees. Once the check fails, the victim can lose their own funds and may also face involvement in a criminal scheme.
How this scam works when money is requested before day one
A legitimate employer does not need a candidate to front money to start work. In these scams, the payment request is usually part of a larger deception designed to make the offer feel real, create urgency, and move the victim into a financial transaction before they can verify anything.
The pattern often begins with a convincing job offer, then shifts to a request for a deposit, purchase, reimbursement, or fee. The ask can be framed as onboarding, equipment, shipping, or payroll cleanup, but the practical effect is the same: the candidate is pushed to send money to a stranger whose role has not been verified.
That matters because the payment request is not just suspicious, it is often the point at which the fraud becomes economically harmful. Once money leaves the candidate’s account, recovery is difficult, especially if the scheme relies on irreversible transfers or the sender acts under time pressure.
Why fake checks and “refund” requests are so common
One common variation uses a counterfeit or altered check to create a false sense of available funds. The candidate is told to deposit it, then forward part of the balance for supplies, shipping, or a vendor. By the time the check is reversed, the victim has already sent out real money.
This is effective because the scam borrows the appearance of normal payroll behavior while flipping the direction of cash flow. Instead of the employer paying the worker, the worker is made to act like a middleman for the fraudster’s funds, which can also expose them to bank account holds, fraud inquiries, or disputes over returned deposits.
The danger is amplified when the requester pressures the candidate to move quickly or to use payment apps, gift cards, wire transfers, or other hard-to-reverse methods. Those details are not incidental, they are usually chosen to reduce the chance of cancellation and increase the chance that the money cannot be recovered.
What a careful candidate should verify before sending anything
The key test is simple: if someone is hiring you, they should not need money from you to begin. Candidates should verify the employer through independent channels, confirm the company domain, and compare the request against the normal onboarding process for that organisation. A real employer can explain the charge, provide documentation, and route the request through a traceable finance or HR process.
It is also worth checking whether the contact details, job description, and interview process match the stated company. Scams often look polished at the surface but fail when you inspect email domains, payment instructions, the speed of hiring, or the demand for secrecy. If the ask cannot survive independent verification, treat the offer as unsafe.
For a useful external reference on scam mechanics and payment fraud patterns, see RFC 9700: Best Current Practice for OAuth 2.0 Security and RFC 9449: OAuth 2.0 Demonstrating Proof of Possession (DPoP) for examples of why sender verification and replay resistance matter when financial or account-related actions are being trusted.
Risk and Threat Considerations
This scam creates direct financial loss, but the bigger risk is that the candidate may also be pulled into laundering or other fraudulent movement of funds. The request can look like a normal hiring step while actually using the victim as a payment intermediary, which increases harm beyond the initial cash loss.
Failure mechanism: The scam depends on a fake hiring relationship, a false payment event, and a time-pressured request to forward money before the original payment is reversed or rejected.
Impact: The victim can lose personal funds, incur bank disputes or account restrictions, and in some cases become entangled in a criminal scheme without realising it.
Practitioner Guidance
What to prioritise: Treat any request for candidate-paid onboarding costs, reimbursement, or “purchase and refund” flows as a stop condition until independently verified. The first question is not whether the job sounds plausible, but whether the payment path is normal, documented, and issued through the employer’s own channels.
What to verify: Confirm the legal entity, recruiter identity, and payment instructions through contact information you source independently, not from the message thread that asked for money. If the employer cannot explain why it needs funds from a candidate, or if it insists on secrecy or speed, the risk is elevated enough to walk away.
Practitioner takeaway: A real employer pays the candidate, not the other way around, and any exception should be treated as a fraud review rather than a hiring decision.
Related resources from NHI Mgmt Group
- Why do attackers often check model availability before trying to generate content?
- How should suppliers prepare for Microsoft SSPA compliance before contract work begins?
- How should DoD suppliers prepare for CMMC certification before contract work begins?
- What happens when ransomware compromises backup systems before restoration begins?