Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security What should employees do when they receive a…
Cyber Security

What should employees do when they receive a job offer or recruitment message from an unknown sender?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 9, 2026 Domain: Cyber Security

Employees should avoid replying, clicking links, opening attachments, or continuing the conversation through unverified channels. Unknown recruitment messages should be treated as potential phishing until the sender, domain, and offer can be independently confirmed. If the message asks for personal data, upfront payment, or account details, it should be reported immediately and not engaged with further.

Why Unknown Job Offers Are a Common Phishing Pattern

Recruitment-themed messages work because they imitate a normal business interaction and lower the reader’s guard. The risk is not only credential theft but also social engineering that can pull an employee into a longer exchange, where the attacker can ask for personal details, payment, or access to a device or account. For organisations, that makes job-offer phishing a trust problem as much as a fraud problem.

If a message arrives through an unexpected channel, uses urgency, or offers unusually attractive terms, the safest assumption is that the sender is trying to create trust before asking for something sensitive. That is why employees should pause, verify the sender independently, and route the message through reporting channels rather than treating it as a genuine recruitment lead. In practice, many security teams only see the harm after an employee has already replied and the conversation has moved off-platform.

How Employees Should Verify a Recruitment Message

The right response is to verify the offer outside the message itself. Employees should check the sender’s domain, compare it with the company or recruiter’s real website, and use an independently sourced contact method if they want to confirm legitimacy. They should not use phone numbers, links, or reply addresses embedded in the message, because those are part of the same trust chain that may be fraudulent.

It also helps to slow down on any request that is unusual for legitimate recruitment. A real recruiter may ask for a CV, interview availability, or identity confirmation through a formal process, but an unknown sender should not be asking for bank details, passport scans, account credentials, or an upfront fee. The key judgement is whether the request matches normal hiring practice and whether it can be validated from a trusted source.

  • Verify the sender through the organisation’s public website or known corporate contact path.
  • Inspect the domain for lookalikes, added words, unusual spellings, or free email services.
  • Treat links and attachments as untrusted until confirmed through another channel.
  • Report suspicious messages so security teams can check whether others received the same lure.

If the only way to continue the conversation is to trust the original message, the process is already unsafe.

When a Job Offer Looks Legitimate but Still Needs Caution

Even convincing messages can still be deceptive, so the practical question is not whether the offer sounds professional but whether it can withstand independent verification. Tighter verification often adds friction for genuine hiring conversations, so organisations and employees have to balance speed against the cost of a bad trust decision.

One common edge case is a message that references a real employer or recruiter but comes from a personal mailbox, a misspelled domain, or a channel that the company does not normally use. Another is a message that is not overtly malicious but is designed to gather personal information before moving the candidate into a separate fraud step. Guidance is clear that employees should not pay, share account access, or disclose sensitive data until legitimacy is confirmed; there is no consensus that a polished message alone is evidence of trustworthiness.

OWASP Non-Human Identity Top 10 is useful here only as a reminder that modern fraud often chains multiple trust assumptions together, including identity, access, and verification steps.

Risk and Threat Considerations

Unknown recruitment messages are a common social-engineering lure because they exploit curiosity, hope, and the expectation that hiring outreach is ordinary business. The material risk is credential theft, personal-data harvesting, or movement into a payment scam or device compromise path after the victim starts engaging.

Failure mechanism: The attacker establishes credibility with a plausible job offer, then pushes the target toward unverified links, attachments, document submission, off-platform messaging, or payment requests. That sequence works because the initial contact feels low risk and the victim may not apply the same scrutiny they would use for a clearly malicious email.

Impact: The employee can expose personal data, transfer money, hand over account access, or become a foothold for further phishing against the organisation. Once the conversation leaves the original secure context, detection and recovery become harder.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v814 — Security Awareness and Skills TrainingEmployees need phishing recognition for recruitment-themed lures.
8 — Audit Log ManagementSuspicious recruitment messages should be reportable and reviewable.
Recommendation — Train staff to verify unsolicited offers before replying or sharing data. Log and review reported lures to detect repeat targeting across employees.
NIST CSF 2.0PR.AT-1 — Identities and roles are managedVerification hinges on trusting the claimed sender and role.
RS.AN-1 — Notifications from detection systems are investigatedReported fake offers need investigation and triage to limit spread.
Recommendation — Require independent validation of unfamiliar senders before any engagement. Investigate reported recruitment phishing quickly and contain any shared exposure.
MITRE ATT&CKT1566 — PhishingUnknown job offers are a social-engineering phishing lure.
Recommendation — Map recruitment lures to T1566 and alert on reply, link, and attachment abuse.

Practitioner Guidance

What to prioritise: Teach employees to treat any unsolicited job offer as untrusted until the sender, domain, and hiring path are independently confirmed. The most important judgement is not whether the role sounds attractive but whether the contact can be verified outside the message itself.

What to verify: Confirm whether the recruiter used a legitimate organisational domain, a known hiring portal, or a publicly listed contact route. If the message asks for payment, credentials, or highly sensitive personal information before a verified interview process, treat that as a strong exception condition rather than a normal hiring request.

Common mistake: Employees often assume that a polished message or a real company name makes the outreach safe. In practice, the security decision depends on the verification path, not the tone or presentation of the offer.

Practitioner takeaway: The safest rule is to verify first and engage later, because legitimate recruiters can be confirmed through trusted channels while phishing campaigns rely on the victim trusting the message that arrived first.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 9, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org