What to Do After a Suspected Job Recruitment Scam
Realising that a recruiter or job offer was fraudulent can be frightening. The next useful step is to identify what you shared or paid, then act through the relevant bank, platform and official reporting channel. Avoid further conversation with the scammer while you are trying to verify the situation. This guide is for the period after a suspected recruitment scam; our employer verification guide explains earlier warning signs.
Make a quick record of what happened
Write a short timeline while the details are fresh: where you saw the vacancy, the profile or email used, dates of messages, what you sent, what you paid and how. Keep screenshots, transaction references, the advertisement URL and any documents you received. Do not edit the evidence or publicly post another person's private information. A record makes it easier to explain the incident to a bank, job platform or investigator.
If the message contains a link or attachment, do not reopen it merely to capture a better screenshot. Save what you already have and move on to securing accounts. A trusted person can help you review the timeline without blaming you. Scams are designed to create pressure and confusion, and taking a moment to organise facts can improve your response.
Stop contact and secure the accounts involved
Do not send additional identity files, one-time codes, passwords or “verification” payments. Block or report the account after you have preserved the evidence you need. If you entered a password on a suspicious page, change it from the genuine service's website or app, using a device you trust. Change reused passwords on other accounts and enable multi-factor authentication where available. Review recent sign-ins, forwarding rules and recovery details on your email account, because email access can be used to reset other accounts.
If you gave remote access to your computer, disconnect it from the network and seek help from a reputable local technical support service. Do not accept a follow-up offer from the same contact to “clean” the device for a fee. If you installed an app, document its name and remove it with trusted guidance; consider professional help when financial or identity data was accessible.
Contact the payment provider promptly
If you paid by card, bank transfer, mobile wallet, cryptocurrency service or payment app, contact the provider through its official app, card number or published website. Explain that the transaction may be fraudulent and ask what dispute, recall or account-protection steps are available. The possibilities differ by payment method and country, and a refund is never guaranteed. Acting quickly gives the provider the best chance to assess available options.
The US Federal Trade Commission's what to do if you were scammed page describes steps according to how money or information was shared. Its US reporting routes are examples for US readers; elsewhere, use your own bank, consumer authority and police reporting channels. Never share a banking password or one-time code with someone claiming to recover your money.
If you deposited a cheque from a supposed employer and then sent money onward, tell the bank immediately and explain the full sequence. A displayed balance is not proof that a cheque has finally cleared. Keep the bank's case reference and any deadlines it gives you. Do not assume that deleting the messages will reverse the transaction.
Respond to information exposure by type
An ordinary CV may include a name, email and phone number. That can lead to more targeted messages; watch for follow-ups that cite your application history and verify each new contact independently. If you sent a government identity number, passport scan, bank details or an ID photo, ask your local identity, passport, bank or consumer authority about appropriate protective steps. Procedures vary widely. In the United States, IdentityTheft.gov provides a recovery plan for eligible situations. Use the equivalent official service in your country where one exists.
If you shared only a portfolio link, check its access permissions and whether it contains private information. If you disclosed a one-time login code, treat the related account as potentially compromised even if the scammer says the code was “for verification.” Secure the account and review activity. The response should match the actual exposure; do not panic over an item you never sent, but do not ignore a sensitive document because no money has disappeared yet.
Report the listing and the incident
Report the profile or vacancy to the job board or social platform where you encountered it. Provide the listing URL, account name, messages and other evidence through that platform's report function. This may help remove the listing and can preserve a trace for an investigation. Separately, use the official fraud-reporting or police channel for your location if appropriate, especially if money or identity information was taken. In the US, the FTC directs consumers to ReportFraud.ftc.gov for suspected fraud.
Do not assume one report automatically reaches every bank or authority. Ask each organisation what information it needs and keep case numbers. If the fake recruiter impersonated a real employer, notify that employer through contact details you find on its official site. They may be able to warn other candidates or confirm that the posting was unauthorised.
Watch for a second scam
Someone who knows you lost money may later claim to be a recovery agent, government officer, lawyer or platform specialist. They may quote the exact amount you lost, display an official-looking document or promise a refund if you pay an advance fee. Verify any such contact independently. The FTC warns about refund and recovery scams, a useful reminder that details of an earlier loss can be used to build a convincing second approach.
Do not post case details publicly alongside your contact information. A private report to the relevant organisation is usually safer. An unexpected “helper” asking for a fee, remote access or bank code is a new risk even if the original incident is real. A legitimate complaint process cannot guarantee recovery.
Rebuild a safer job-search routine
After immediate account and payment steps, review how the contact began. Did it move from a job board to a personal messaging app? Did the role appear on the employer's own careers page? Was there a demand for payment or sensitive details before a verified hiring stage? Write a short personal rule for the next application: open the employer's site independently, check the actual vacancy, and use a known contact channel before sharing sensitive information.
Our guide to finding legitimate vacancies gives a broader search routine, while the offer-verification guide covers suspicious offers. Neither can remove all risk. Keep copies of applications so you can distinguish a real response from a message about a role you never applied for. Use separate strong passwords and secure your primary email account.
It is reasonable to take a break from applications while you handle the incident. You do not need to tell every future employer what happened. Focus on concrete account protection, reports and a manageable search plan rather than repeatedly arguing with the scammer.
Match the first response to the exposure
If you paid by card but shared no identity documents, the most urgent contact is normally the card provider through its official number or app. Explain the transaction, ask whether the card should be replaced and follow its dispute instructions. If you sent a bank transfer, contact the sending bank quickly and ask whether a recall or fraud investigation is possible. If you used an online wallet, use that service's official fraud route. A social-media comment claiming it can reverse a payment is not a substitute for the provider.
If you sent an ID image but no payment, contact the relevant official identity or issuing authority about misuse precautions and monitor for suspicious accounts. If you shared a password, secure the account from a trusted device and all other accounts where that password was reused. If you gave a one-time code, review whether the account was accessed and change recovery settings. If you installed remote-control software, seek trusted technical help and tell your bank if financial accounts may have been visible. More than one of these may apply; work through the list rather than choosing just one.
If you supplied only a name, phone number and ordinary CV, you may not need the same response as someone who sent a passport scan. Still expect targeted follow-up messages. A scammer can refer to a real application, job title or interview time to sound credible. Keep a list of genuine applications and verify any future recruiter independently through the employer's published channels.
Keep a case log and watch for deadlines
Create a simple record with columns for date, organisation, official contact channel, case number, documents sent and next action. For example, record when you called the bank, what it asked you to provide and when it expects an update. Note any dispute deadline the provider gives you. This prevents repeated explanations and helps you distinguish a real follow-up from a new impersonator. Do not put passwords, full card numbers or identity scans in an unsecured spreadsheet.
When a platform removes the fake listing, save its confirmation. If an authority gives you a report number, store it with your timeline. If you speak to a real employer that was impersonated, record its confirmation without asking it to resolve bank transactions it does not control. Each organisation has a different role. Keep communications polite and factual so that the people handling the case can identify the relevant evidence.
You may need support from someone you trust, especially if several accounts or payments are involved. Share only the information needed for that help. A friend can sit with you while you call the bank or check official URLs, but do not hand over all your logins. If the incident affects your wellbeing, local support services can help; taking a break from the job search is reasonable.
Do not let urgency create a second mistake
Scammers often demand action “within minutes,” then send convincing follow-up messages when you hesitate. Official providers may also have real deadlines, but you can reach them through numbers and apps you find yourself. Pause long enough to verify the channel. Never read a one-time code aloud to someone who called you unexpectedly, even if they know your case number. If a person claims to be from a bank, end the call and dial the number on your card or the bank's official website.
No guide can predict whether money will be recovered or identity misuse will occur. The best available response is specific to what happened, documented and routed through organisations with actual responsibility. That approach protects your next steps even when the outcome is uncertain.
Frequently Asked Questions
Should I reply once more to demand a refund? Contact your payment provider and official reporting channels instead. Continuing the exchange may expose you to further pressure or requests.
Will reporting guarantee my money back? No. Recovery depends on the payment route, timing, local process and facts. Reporting can still help providers investigate and protect others.
What if I only sent my CV? Monitor follow-up messages and review what personal details the CV includes. Verify future contacts independently; more sensitive exposure requires additional steps.
Can I warn others publicly? Report through the platform and authorities first. If you share a warning, avoid publishing private identifiers, unverified accusations or information that could compromise an investigation.
The most useful sequence is evidence, account security, payment-provider contact, appropriate reports and careful follow-up. Take one step at a time and keep a record of what each organisation tells you.