All stories
Fraud Investigation11 min read

How a Trust and Safety Team Dismantled a Fake-Recruiter Scam

The recruiters seemed legitimate, the offers seemed real, and jobseekers were handing over documents. Here's how a trust and safety investigator used Expose to connect the fake profiles into one operation - and shut it down.

How a Trust and Safety Team Dismantled a Fake-Recruiter Scam
On this page

The reports that didn't add up

The first ticket arrived on a Tuesday. A jobseeker had applied for a remote customer success role at what looked like a legitimate mid-sized software company - the right logo, a professional-sounding recruiter, a job description pulled almost word-for-word from the real company's public listings. The recruiter, who called herself Priya Mehta, had conducted a video interview, praised the candidate enthusiastically, and extended a conditional offer. The condition: a refundable equipment deposit of four hundred dollars, to be paid in gift cards, to cover the cost of the home-office kit the company would ship once onboarding was complete.

The candidate paid. No kit arrived. Priya Mehta's profile disappeared. The candidate filed a report in the investigators website, described the recruiter by name, and attached a screenshot of the profile that no longer existed. It was the kind of ticket that looks, in isolation, like a single bad actor - a scammer who built a fake profile, ran a quick con, and moved on. Alice, a trust and safety investigator on the integrity team, had seen enough of these to know that single bad actors almost never work alone.

By the end of that same week, five more reports had come in. Different recruiter names, different companies, different candidates - but the same basic shape: a plausible offer for a remote role, a warm interview, a conditional extension, and then a demand for money or documents before the candidate ever started. One victim had been asked to submit a scan of their passport and national ID "for background verification purposes." Another had been directed to transfer a crypto deposit - a "salary escrow" that would be returned after ninety days. A third had received a DocuSign-style contract for a company she later confirmed had no record of ever hiring her.

Opening the investigation

Alice pulled all six reports into a working file and began with the most basic question: were these the same operation, or six coincidental, unrelated scams? The answer would determine everything - her approach, her evidence standard, and how she packaged the results for action. A scattered handful of solo scammers gets handled one profile at a time. A coordinated network gets reported to authorities and actioned in a sweep. The difference matters, because the sweep is what actually ends something.

She opened Expose and started feeding it what she had - recruiter LinkedIn, profile photos, company domains, email addresses, and every contact artifact the reports had surfaced. The platform's job was to do what a human analyst cannot do quickly alone - correlate fragments across open sources fast enough to see whether the fragments belong to the same whole.

The photos told the first story

The recruiter profiles had been built to look distinct. Different names - Priya Mehta, James Okafor, Sandra Bryce, Leo Harrington, Mei-Ling Chu, Tom Velden - different companies, different profile bios, different levels of apparent career experience. The photographs, though, were a different story. Expose flagged a match between two of them almost immediately: the profile photo used for "Priya Mehta" and the photo used for "Sandra Bryce" resolved to the same source image - a stock photograph available on a commercial image library, cropped differently but unmistakably identical beneath the framing.

That match is not, by itself, proof of coordination. A coincidence is possible: two separate scammers could independently pull the same stock image. But it is a hypothesis that demands to be tested. Alice ran reverse image searches on the remaining four profile photos. Two more matched images she could confirm as stock or previously published photographs; one matched a profile on a defunct social account under a different name. None of the six recruiter profiles were using photographs of real people behind those identities. The faces were borrowed - assembled from public sources and reassigned to invented personas.

"The photograph is often the laziest part of a fake persona," Alice said. "People spend real effort on the backstory and the pitch. They underestimate how much the image itself reveals - or they assume that because the photo is publicly available, nobody will think to check where it came from."

Domains registered in a batch

Each fake recruiter had claimed to represent a specific company. The companies themselves were real - established firms with genuine recruiting activity and real employees - but the email addresses and career-site links the scammers provided pointed somewhere else entirely. Alice extracted every domain artifact from the six reports and fed them into Expose. What came back clarified the picture considerably.

The six "company" domains the scammers had used were lookalikes: close enough to the real firms' domains that a candidate distracted by an exciting job offer might not notice the difference. Novaris-careers.net instead of novaris.com. TallonGroup-jobs.org instead of tallongroup.io. Each fake domain had been registered recently - all of them within the same six-week window - and several had been registered through the same domain registrar, with WHOIS privacy protection engaged. The registration dates aligned closely enough to suggest the domains hadn't been opportunistically grabbed over time but had been created together, in preparation for the campaign.

  • Six fake recruiter profiles, each using a different name and claimed employer
  • Six lookalike career domains registered within a six-week window, several through the same registrar
  • Profile photographs sourced from stock libraries or repurposed from other public accounts - none depicting the actual person behind the persona
  • A shared set of contact email addresses that recurred across supposedly independent recruiters
  • Interview scheduling links that resolved to a shared infrastructure - the same calendar tool, the same confirmation-email domain
  • Payment instructions pointing to the same crypto wallet address and the same gift-card payout instructions

That last item was the structural tell. Gift cards and crypto wallets, unlike bank accounts, don't require identity verification to receive funds. Alice found, buried in the candidate reports, that two of the six recruiters had provided the same wallet address and the same gift-card instructions - presented in different wording, formatted slightly differently, but pointing to identical endpoints. Six apparently distinct personas. One receiving address.

Finding similarities is not the same as confirming a network. Alice was careful about this. Two profiles sharing a stock photo is suggestive; it is not proof. A cluster of recently registered lookalike domains is a serious pattern; it is not a court document. Her job at this stage was to test each apparent link against independent corroboration - to distinguish genuine structural connections from coincidences that only look meaningful because she was looking for them.

She ran each connection through a second and sometimes third layer of source verification. The shared wallet address was confirmed from two separate victim reports filed independently, by people who had never spoken to each other. The domain registration clustering was verified against public WHOIS archives. The stock photo matches were documented with source URLs and timestamps. She was equally careful on the other side: not every recruiter who worked at a company with a similarly named domain was suspect. Legitimate recruiters use similar-sounding email patterns, and real companies maintain multiple domains. She built a positive exclusion list - profiles that had passed enough independent verification to be set aside - so that the investigation didn't sweep up genuine recruiters in a net intended for fraudulent ones.

This is the discipline that protects the platform's integrity work from the credibility damage of false positives. A wrongly flagged recruiter is a real person whose professional reputation and livelihood have been harmed. The evidentiary standard has to hold at both ends: enough to act on the fraudulent profiles, rigorous enough to protect the legitimate ones.

The shape of one operation

By the time Alice finished the correlation pass, the picture had resolved from "six suspicious recruiter reports" into something much more structured. The six named personas were not six separate scammers. They were six faces of a single operation - built around shared infrastructure, shared payment endpoints, shared domain procurement, and a coordinated playbook that moved every target through the same sequence: warm contact, enthusiastic interview, conditional offer, document or money demand.

Expose had done the connective work - flagged the photo matches, surfaced the domain registration clustering, identified the recurrent contact artifacts across profiles that had been deliberately designed to look unconnected. The investigator had done the verification work: confirming each link from independent sources, excluding legitimate accounts that had triggered surface-level similarities, and assembling the corroborated findings into an evidence package that could support action.

She estimated, conservatively, that the operation had made contact with several hundred jobseekers. The six reports her team had received were almost certainly a small fraction of the actual targets - most victims of employment fraud don't report; they simply disappear, sometimes embarrassed, sometimes not knowing who to tell. The scale of the operation was larger than six reports suggested, which made the coordinated takedown more urgent.

Acting on the evidence

Alice packaged the investigation into two outputs. The first was an internal evidence brief for the enforcement team: the full correlation documentation, the list of confirmed fraudulent profiles with the evidence supporting each, the positive exclusion list of accounts that had been reviewed and cleared, and the recommended action - permanent removal of the fraudulent profiles and a platform-wide flag on the shared infrastructure artifacts so that any new accounts using the same email patterns, domains, or wallet addresses would be caught immediately.

The second output was a referral packet for the relevant authorities - the financial crimes unit with jurisdiction over wire fraud and identity theft, and the internet crime reporting infrastructure. That packet was more formal: a timeline of the operation, the documented evidence for each link, a description of the harm to victims, and a clear summary of what the OSINT investigation had established and what it hadn't. The OSINT built the lead. Enforcement acts on it. Alice was careful to frame the referral package accordingly - as documented evidence for investigators to pursue, not as a conclusion that bypassed their own process.

Why the reuse is the tell

Employment fraud at this scale - coordinated fake recruiter networks rather than lone scammers - depends on volume to work. A single fake recruiter account gets reported and removed quickly; a network of fifty, cycling new personas as old ones get flagged, sustains the operation across months. What the operators of such networks tend to underestimate is the degree to which volume forces reuse. You can generate many names. You cannot generate many believable photographs without either using real people's images - which creates its own traceability - or recycling from the same small pool of stock sources. You can register many domains, but if you're doing it in bulk it shows in the registration pattern. You can set up many receiving accounts, but directing funds to a single ultimate destination is often operationally simpler, and that simplicity leaves a trail.

The reuse is the tell. Each individual artifact - a photo, a domain, a wallet address - looks like a local detail when you're reviewing one profile report. Across thirty or fifty reports, the same artifact appearing in different profiles is no longer a local detail; it's a structural signature. The investigation doesn't require any single piece of evidence to be definitive. It requires enough overlapping, independently corroborated pieces that the network becomes visible as a network - and visible networks can be dismantled.

The quiet side of trust and safety work

Most of this work is invisible. The profiles come down and new ones don't appear because the infrastructure has been flagged. The jobseeker who would have received the warm recruiter message next Tuesday never knows they were protected because there's nothing to notice - just a search that returns legitimate results, a platform that feels safe, an opportunity that turns out to be a real one.

That invisibility is the goal. Trust and safety investigations succeed most completely when their outcomes are unremarkable - when the scam operation has been dismantled thoroughly enough that there's nothing left to report.

How many of those recruiters are actually real?

Expose connects lookalike domains, reused photos, and payment artifacts across profiles - so an impersonation network resolves into one operation you can shut down.