# The Job-Scam Signal Reference, and Which Tells Survive AI Polish

*You can sort a recruiter message into legit or fraud using signals that still work after AI polish, and finish verification touching nothing the sender supplied.*

- Canonical URL: https://www.refolk.ai/candidates/guides/job-scam-signal-reference
- Pillar: Applying at volume
- Format: Reference
- Published: 2026-09-03
- Last reviewed: 2026-09-03
- Reading time: 15 min
- Keywords: is this recruiter a scam, how to spot a fake job posting, verify a recruiter is legit, job offer scam red flags, fake job offer warning signs, recruiter asking for bank details

## Key takeaways

- Typos, grammar, and tone are dead tells: generative AI now produces recruiter outreach indistinguishable from a real talent acquisition professional's writing, so surface quality no longer discriminates.
- The one check a scammer cannot defeat is channel-independence: every link, number, and document inside their message routes back to them, so verification must use sources they do not control.
- Timeline is a near-binary signal that survives AI polish: the FTC fixes SSN at the interview or background-check stage and bank details at post-offer onboarding, so any earlier request is anomalous regardless of how clean the message reads.
- In Refolk's index there are 132,056 current US recruiter identities and only 9,302 in the UK, a 14.2x gap, and that large US pool is exactly the set of real people scammers borrow.
- Senior TA leaders are only about 2.8% of the US recruiter pool (3,674 of 132,056), so an unfamiliar recruiter contacting you is statistically normal and cannot itself be a red flag.
- Urgency is the mechanism, not decoration: a 2026 study tied time-pressure cues directly to payment behavior, so same-day deadlines should raise verification effort, not lower it.

A recruiter message or a job posting just landed, and you have to decide, before you share a document or a dollar, whether it is a real opportunity or a fraud. This reference is for job seekers running an active search across many companies, where inbound outreach is constant and every contact needs a fast, repeatable ruling. It gives you a fixed table of signals, tells you what each one actually proves versus how it misleads, and lays out a verification path that never trusts a link, number, or document the sender supplied.

The framing matters because the usual "red flags" lists are now wrong at the top. They lead with typos, bad grammar, and unprofessional tone. Those tells are dead. What follows keeps only the signals that still discriminate and pairs them with a procedure you can run with your hands.

## Why the classic red flags stopped working

The traditional shortcut of scanning for typos and awkward phrasing has effectively stopped working, because generative AI tools now produce outreach with polished subject lines and professional structure indistinguishable from a real talent acquisition professional's writing. Scams riddled with typos, bad translations, or low-quality graphics are a thing of the past. Treat grammar, tone, and formatting as carrying zero signal.

The reason is economic. What used to take a criminal organization months can now be assembled over a weekend by a single operator with a laptop and a few cheap subscriptions. When the cost of polish drops to nothing, polish stops correlating with intent. So the discriminating signals moved from surface to structure. Only three things still carry information: the channel a request comes through, where a data request falls on the hiring timeline, and the direction any money flows.

**95% - Job seekers who have encountered a suspicious job offer**

From Monster's 2026 Job Scam Report; 53% say they were directly targeted, so this is a routine part of any active search, not an edge case.

Exposure is near-universal. Monster's 2026 report found 95% of job seekers have encountered a suspicious job offer and 53% were directly targeted. A separate survey of 1,254 US job seekers found 4 in 10 fell for a scam, and half of those victims had personal data or money stolen. The FTC reports that job-scam reports tripled from 2020 to 2024 while reported losses jumped from $90 million to $501 million. This is a high-volume environment, which is exactly why you want a fixed procedure rather than a gut call each time.

> **Rule:** Judge structure, not writing quality
>
> A clean, professional, well-formatted message tells you nothing about whether it is legitimate. Rule on channel independence, timeline fit, and payment direction only.

## The signal table: what each tell proves and how it lies

Below is the reference proper. Each signal is marked live or dead, with what it proves when present and how it misleads. A dead signal is one AI polish has neutralized. Jump to the row you need.

| Signal | Status | What it proves | How it misleads |
|---|---|---|---|
| Typos, grammar, tone | Dead | Nothing | AI writes flawless outreach; absence of typos proves nothing |
| Data request before its stage | Live | Timeline anomaly, near-binary | A clean message makes a premature ask feel normal |
| In-message link or phone number | Live | Sender controls the channel | A "verified" badge or logo makes the link look safe |
| Public-provider sending domain | Live | Not a corporate address | A look-alike domain passes a glance |
| Any payment from you | Live | Fraud, no exceptions | "Refundable" or "reimbursed" framing softens it |
| Same-day urgency | Live | Pressure to skip verification | Framed as a hot role or limited slots |
| New or thin recruiter profile | Weak | Less history to lean on | Also fits a real recent hire; not proof of fraud |
| Role listed on careers page | Weak | The job exists | Scammers copy real listings verbatim |

The three live signals with the most weight are the premature data request, the payment demand, and channel dependence. They survive AI polish because they are about what is being asked and through what path, not how it is written. The weak signals are still worth noting but must never carry a ruling alone.

> Grammar stopped correlating with intent the day a scammer could buy fluent English for the price of a subscription.

### Where sensitive data legitimately belongs

The single hardest, most durable signal is timeline. Because the FTC and standard payroll practice fix when each piece of data is legitimately requested, a request that arrives earlier is anomalous regardless of how convincing the message reads. Memorize this table.

| Item | Earliest legitimate stage | Source |
|---|---|---|
| SSN | Interview stage, for a background check | FTC |
| SSN (alternate) | After signed written offer, onboarding I-9/W-4 | iHire |
| Bank / direct deposit | After hire or signed offer, payroll setup | FTC |
| Government ID | After signed contract, right-to-work check | scamchecker |
| Any payment from you | Never | FTC |

The FTC states plainly: if a company asks for your SSN or banking information before you even interview, it is probably a job scam. iHire adds that most employers request your SSN only after you accept a written offer, during onboarding, to complete an I-9 or W-4. So SSN before any interview, or bank details or ID before a signed written offer, is the anomaly you are looking for. It does not matter how professional the surrounding message is.

> **Watch out:** The role being real does not make the offer real
>
> Scammers copy legitimate listings word for word. Finding the job on the company careers page confirms the job exists, not that your contact represents the employer. Still contact the company through a channel you found yourself.

## The one check a scammer cannot defeat

Channel independence is the check no scammer can beat, because it draws on sources they do not control. A scammer who controls the posting also controls the phone number and email address inside it, so calling the number in a fraudulent listing simply connects you to the person running the fraud. Every link, every number, every attachment inside their message routes back to them.

The fix is to separate verification from communication. Instead of clicking a link in a recruiter email, open the company's website from your own search results. Instead of calling a number in a message, use the number published on the organization's official site. No single profile, email address, calendar invitation, team page, or website proves legitimacy on its own, so triangulate: verification works best when several independent sources support the same identity.

#### The independent verification path

1. **Extract** - Pull only the company, recruiter, and role from the message, then quarantine it
2. **Locate** - Open the employer's real site from your own search and find the careers page
3. **Confirm person** - Match the recruiter to the employer across two independent sources
4. **Check domain** - Compare the sending address character by character to the real domain
5. **Ask the employer** - Contact HR through a channel you found and confirm the requisition

*Every stage uses a source the sender does not control, which is the property that defeats a scam.*

This path is cheap because the impersonation target list is short and predictable. Scammers most commonly impersonate Amazon, Google, FedEx, UPS, and Walmart, and disproportionately target people seeking remote or flexible work. You only need one habit to defeat the highest-volume plays: confirm the specific requisition on the real careers page and through a channel you looked up yourself.

## How big the real recruiter pool is, and why that matters

To impersonate a recruiter, a scammer needs a real identity to borrow. In Refolk's index of professional profiles there are 132,056 current people in the US with recruiter or talent-acquisition titles, and 9,302 in the UK. That large US pool is the exact set of real names a scammer can claim to be.

| Country | Recruiter identities | Share of the two | US multiple |
|---|---|---|---|
| United States | 132,056 | 93.4% | 14.2x UK |
| United Kingdom | 9,302 | 6.6% | 1.0x |

Two practical conclusions follow. First, the US pool is 14.2 times the size of the UK's, so US job seekers face a far deeper bench of borrowable identities and should lean harder on independent confirmation rather than name recognition. Second, the pool is dominated by front-line recruiters, not senior leaders.

| Band | Count | Share of US recruiters |
|---|---|---|
| All recruiter / TA titles | 132,056 | 100% |
| Senior leaders (Director/VP) | 3,674 | 2.8% |
| Front-line (remainder) | 128,382 | 97.2% |

In Refolk's index, senior TA leaders are only about 2.8% of the US recruiter pool, 3,674 of 132,056. This is why "a recruiter I've never heard of messaged me" cannot be a red flag: unfamiliar front-line recruiters are the overwhelming majority of real outreach. The entire burden falls on independent verification. This is also the place where Refolk earns its keep during an active search: [Refolk](/candidates) writes your resume from your own history, tailors it to each posting, and scores your fit, which keeps your applications moving so a suspicious inbound is a rare interruption to a running process rather than the only lead you have.

Ask me this: `Talent acquisition recruiters who currently work at Amazon in Seattle` - [run the search](https://www.refolk.ai/start?q=Talent%20acquisition%20recruiters%20who%20currently%20work%20at%20Amazon%20in%20Seattle).

*Returns real people with current Amazon recruiting titles, so you can check whether the person claiming to recruit for them actually appears among the employer's real staff.*

Because Amazon leads the impersonation list, a query like this is one of the cheapest confirmations you can run: if the person messaging you does not appear among the real recruiters at the named employer, that is a concrete finding rather than a hunch.

## The procedure: run any contact through this in fifteen minutes

Here is the full sequence. It never touches a link, number, or document the sender supplied. Once several independent details align, you do not need to keep going forever.

#### Verify before you share anything

1. **Freeze before you respond** - Do not click links, call numbers, or open attachments the sender supplied. Extract only the company, recruiter, and role, then quarantine the message. Done when you have those three facts and have touched nothing else.
2. **Independently locate the employer** - Search the company yourself, open its official site from your own results, and find the careers page. Done when you have confirmed the role is posted there or flagged the listing as unverified because it appears nowhere.
3. **Verify the recruiter as a person** - Check the recruiter's professional profile and whether they actually work at the employer, treating the person separately from the message. Done when at least two independent sources agree on identity and employer.
4. **Check the sending domain** - Confirm the email ends in the company's actual corporate domain, not a public provider, comparing it character by character to the real domain. Done when it matches exactly.
5. **Contact the company through a channel you found** - Use the official careers email, HR form, or switchboard number from the site to ask whether the outreach is legitimate. Done when the employer confirms or denies the requisition.
6. **Map the request against the timeline** - Place any data request on the hiring timeline: no SSN before interview or background check, no bank or ID before a signed written offer. Done when the request either fits the stage or is flagged as premature.
7. **Run the escalation-pattern test** - Score for off-platform moves, same-day urgency, upfront fees, and overpayment or check-forwarding. Done when none are present or the contact is abandoned.
8. **If already engaged, contain** - Stop responding, contact your bank to freeze or rotate the account, and report to the relevant authority. Done when the account is secured and the report is filed.

You can copy this note to send when you contact the employer through their own channel:

**Independent confirmation note to an employer**

```
Subject: Confirming a recruiter outreach

Hello,

I received outreach for a [role title] position from someone identifying themselves as [recruiter name] at [company]. Before I proceed or share any documents, I would like to confirm this is a genuine requisition from your team and that this person is authorized to recruit for it.

Could you confirm or let me know who to check with? Thank you.
```

*Send this to the careers email or HR form you found on the company's own site, not to any address in the original message.*

## How this goes wrong: false positives and traps

This is the most valuable part of the reference. A signal that misfires costs you a real job; a trap you miss costs you data or money. Read every row.

| Failure mode | What happens | What to do instead |
|---|---|---|
| Careers-page false positive | Scammer copied a real listing; passing this confirms the job exists, not your contact | Still contact the employer through a channel you found |
| Corporate-domain spoofing | A look-alike domain (rn for m, extra hyphen) passes a glance | Compare character by character against the real domain |
| "Confidential search" excuse | Total opacity used to justify skipping detail | Confidentiality limits detail; it should not block explaining the broad opportunity |
| Thin profile read as fraud | A recent profile or job change treated as proof | Weight independent confirmation, not profile richness |
| Deepfake video passes "I saw them" | A live face reassures you falsely | Verify the requisition through the employer, not the call |
| Early small payout builds trust | Task scams pay small amounts first | Receiving money is not proof of legitimacy |
| "Deposit this check for equipment" | Check clears provisionally, then bounces | Any request to receive and forward money is fraud |
| Recovery / double-dip scam | Fake FBI or recovery agents contact victims | IC3 never messages directly or charges fees |

A few of these deserve elaboration.

**The confidential search excuse.** Legitimate confidentiality limits how much detail a recruiter shares, but it should not make it impossible to explain the broad opportunity, the recruiting process, or the reason for contacting you. Total opacity paired with urgency is the tell, not confidentiality itself.

**The thin profile.** A new profile, limited activity, or a recent job change is not proof of anything improper. It simply gives you less history, which makes other verification sources more useful. Conversely, AI headshots and recycled descriptions make fakes look full, so profile richness is not reassurance either. Weight the independent confirmation, not how complete the profile looks.

**The deepfake interview.** Deepfake fraud attempts in hiring jumped roughly 1,300% from 2023 to 2024, and Gartner projects that by 2028 one in four candidate profiles worldwide will be fake. You often cannot tell for certain whether a video call is genuine, which is why the channel matters more than the face. Verify the requisition through the employer; do not let a live face substitute for that.

> **Watch out:** Urgency is the mechanism, not decoration
>
> A 2026 study tied time-pressure cues directly to payment behavior. Scammers manufacture same-day deadlines specifically to prevent you from completing verification. Treat urgency as a reason to slow down and verify harder, never a reason to move faster.

**The payment traps.** Two patterns recur. Task scams pay small amounts early to build confidence before the deposit demand, so receiving money proves nothing. And the "deposit this check for home office equipment" play relies on a check that clears provisionally, then bounces after you have forwarded the funds. The FTC's rule is absolute: never pay anyone to get paid, and any request to receive and forward money is fraud.

## Verify before you share, and what to do if you already shared

Before you hand over any personal data, ID, or money, everything below should be true. If any item fails, do not proceed.

#### Clear before you share anything

- [ ] You opened the employer's site from your own search, not a link in the message
- [ ] You found the specific role on the company's real careers page, or flagged the listing as unverified
- [ ] At least two independent sources agree on the recruiter's identity and employer
- [ ] The sending domain matches the real corporate domain character by character
- [ ] You confirmed the requisition through a channel you found yourself
- [ ] Every data request fits its legitimate stage on the hiring timeline
- [ ] No off-platform move, same-day urgency, upfront fee, or check-forwarding is present
- [ ] No one has asked you to pay anything at any point

If you have already engaged and shared details, contain it the same day. Stop responding to the "employer." Contact your bank, tell them you may have shared details with a fraudster, and ask whether to freeze the account or rotate the account number. In the US, report at IdentityTheft.gov and file at ic3.gov and reportfraud.ftc.gov; in the UK, report to Action Fraud.

Then watch for the second wave. After a scam, fake "FBI," "IC3," or "recovery" agents contact victims offering to retrieve lost money. IC3 will never directly communicate via phone, email, social media, or public forums, and it never charges fees. If someone contacts you claiming to recover your funds, that is a fresh scam.

## Keeping this reference current

The signals in this document are structural, so they are stable, but the environment around them moves. Two things are worth re-checking rather than trusting a fixed value. First, the impersonation target list shifts with brand recognition; the current leaders are Amazon, Google, FedEx, UPS, and Walmart, but confirm against a live tracker before assuming a brand is or is not being spoofed. Second, deepfake capability is rising fast, so the "verify the requisition, not the face" rule will only grow more important, not less.

The habit to keep is the one that does not depend on any current value: confirm the specific requisement through a channel the sender does not control, and place every data request on the timeline before you say yes. When you run a search with your applications already moving under their own power, a suspicious inbound becomes a five-minute check rather than a lead you are tempted to trust because you need it. That is the safest posture: verification driven by discipline, not by scarcity.

## Frequently asked questions

### Is this recruiter a scam if they messaged me out of nowhere from a company I never applied to?

Unsolicited outreach is not itself a red flag. In Refolk's index there are 132,056 US recruiter identities, and senior gatekeepers are only about 2.8% of them, so most real outreach comes from front-line recruiters you have never heard of. Do not judge the message on how it reads. Verify the specific requisition through the employer's own careers channel and check the sending domain before you share anything.

### A recruiter is asking for my bank details for direct deposit before I have signed anything. Is that normal?

No. The FTC and standard payroll practice place bank details and government ID after a signed written offer, during onboarding and payroll setup. A request for banking information before you have a signed offer is anomalous regardless of how professional the message looks, and it survives as a hard signal even against AI-polished outreach. Stop, verify the requisition independently, and do not send the details.

### How do I verify a recruiter is legit without tipping off a possible scammer?

Verify through channels the sender does not control. Search the company yourself, open its official site from your own results, find the careers page, and contact the employer through the published HR form or switchboard number to confirm the requisition. Check the sending domain character by character against the real corporate domain. You never have to reply to the original message to complete this.

### The job is listed on the real company careers page. Does that prove the offer is real?

No. Scammers copy real listings, so a match on the careers page confirms the job exists, not that your contact represents the employer. Treat it as one signal, then still contact the company through a channel you found yourself to confirm the specific outreach. Triangulate across independent sources, because no single artifact proves legitimacy on its own.

### Are typos and bad grammar still a reliable way to spot a fake job posting?

No, they are dead tells. Generative AI now produces recruiter outreach with polished subject lines and professional structure indistinguishable from a real talent acquisition professional's writing. Reorganize your judgment around signals that still discriminate: channel independence, where a data request falls on the hiring timeline, and the direction of any payment. Grammar no longer correlates with intent.

### I already shared my bank details with a fake recruiter. What do I do now?

Contain it the same day. Stop responding, contact your bank, tell them you may have shared details with a fraudster, and ask whether to freeze the account or rotate the account number. In the US, report at IdentityTheft.gov and ic3.gov; in the UK, report to Action Fraud. Watch for follow-up recovery scams: IC3 never messages victims directly or charges fees.

---

*From the Refolk guide library. I revise these guides rather than replacing them, so the current version is always at https://www.refolk.ai/candidates/guides/job-scam-signal-reference*
