NordVPN’s Threat Intelligence exposes recruitment phishing campaign impersonating top global brands

NordVPN’s Threat Intelligence exposes recruitment phishing campaign impersonating top global brands

NordVPN’s Threat Intelligence research unit reports on a sophisticated phishing campaign targeting job seekers by impersonating some of the world’s most recognisable employers.

The operation exploits the names of Meta (and its subsidiaries), Disney, Coca-Cola and Spotify to steal victims’ Facebook credentials and hijack their accounts.

The investigation revealed a multi-stage operation that goes far beyond typical phishing attempts. Attackers deploy hidden ‘HUB’ domains, referral-link activation mechanisms and realistic job listing interfaces to guide victims through a carefully constructed path. The final step redirects them to a fake Facebook login page designed to capture their credentials.

“Job seekers are uniquely vulnerable because they’re already in a mindset of sharing personal information and following instructions from unfamiliar contacts,” said Domininkas Virbickas, Product Director, NordVPN. “Such campaigns take advantage of that trust using polished communications and convincing fake career portals that are nearly indistinguishable from the real thing.”

The campaign begins with a cold email, often sent through legitimate services like Google AppSheet to bypass spam filters. These messages appear polished and professional, with clean grammar and a tone that mirrors real recruitment outreach. Contact lists are likely compiled through automated scraping of platforms like LinkedIn or sourced from previous data breaches.

Browse our latest issue

Intelligent CISO

View Magazine Archive