LinkedIn jobs adverts targeted in new scam campaign

linkedin
(Image credit: Shutterstock / Ink Drop)

Posts on LinkedIn are being  abused to post fake job listings on behalf of virtually any legitimate company, cybersecurity experts have claimed.

Harman Singh, a security expert and managing consultant at security company Cyphere, shared details of the scams with BleepingComputer, noting that, "Anyone can post a job under a company's LinkedIn account and it appears exactly the same as a job advertised by a company."

There’s no dearth of fake LinkedIn job scams, but while these were orchestrated from fake recruiter accounts, Singh’s technique post the fake job on behalf of a genuine company, adding a whole new level of legitimacy to the scam. 

Feature or faux pas?

To test Singh’s claims, BleepingComputer used a LinkedIn account unconnected with its website to advertise a fake job listing. 

The listing didn’t identify who posted the job, making it appear as if it was posted by BleepingComputer itself. Furthermore, all applications sent in response to the fake listing, were sent to the non-BleepingComputer-owned email address.

Even more worryingly, BleepingComputer was unable to take down the fake listing posted on behalf of the website, as the platform prevented it from exercising admin control on the content.

The only option for businesses to prevent others from fraudulently posting jobs on their behalf is to rope in LinkedIn.

"You can manually email to the LinkedIn trust and safety team to get those options enabled that allow you to block unauthorised posts, and only allow authorised team members to post jobs," shared Singh.

A LinkedIn representative didn't directly comment on Singh's workaround, but shared the following statement with TechRadar Pro:

"Posting a fraudulent job is a clear violation of our terms of service. We use automated and manual defenses to detect any fake job posting and quickly take action to remove them. We’re constantly investing in new ways to improve detection, including providing tools for companies to require work email verification before posting to LinkedIn."

Via BleepingComputer

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
Hacker silhouette working on a laptop with North Korean flag on the background
North Korean hackers are targeting LinkedIn jobseekers with new malware - here's how to stay safe
linkedin
Watch out - that LinkedIn email could be a fake, laden with malware
Red padlock open on electric circuits network dark red background
CrowdStrike warns of fake job offer scam that is actually just malware
A padlock resting on a keyboard.
Understanding and avoiding malvertizing attacks
Fraude en ligne phishing
Google Search ads are being hacked to steal account info
Smartphone with new logo X twitter app background. Application twitter old blue bird change X black and white new.
Phishing campaign targets prominent X users, accounts at risk
Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring