Manav.id
Workforce ยท 17 min read

The company was real. The recruiter was not.

Job seekers reported close to $363 million in employment scam losses in 2025. The reason the scam works is structural: hiring requires the candidate to prove everything about themselves, and requires the employer to prove nothing at all. Here is what a verifiable employer would look like, and why the first company to sign its offers will quietly win.

The message arrives on a Tuesday afternoon, on the platform where you keep your professional profile, from a recruiter whose account is three years old and has four hundred connections in your industry. The company is one you have heard of. You look it up anyway. Real website, real product, real leadership team, a careers page listing the exact role described in the message.

The first conversation happens over chat, which is slightly unusual but not alarming, because plenty of companies screen that way now and the recruiter mentions a hiring push and a compressed timeline. The questions are competent. They ask about your last project in enough detail that you have to think. Two days later there is a video call with someone introduced as the hiring manager, and the call is short, and the connection is poor, and they apologise for the camera.

The offer arrives as a PDF. Your name is spelled correctly. The salary is a little above market but not absurdly so. There is a start date, a reporting line, a benefits summary, and a signature block with a name and a title that match a real person on the company's real leadership page.

Then comes the last step, and it is always presented as logistics rather than as a request. Onboarding needs your bank details for direct deposit, which is normal. It needs a scan of your passport for the background check, which is normal. And it needs you to order your laptop and monitor through the company's approved equipment vendor, for which they will reimburse you in the first payroll run, and here is the link.

Every single element of that story is ordinary. That is the point. There is no moment where a careful person should obviously stop, because the scam is not built out of red flags. It is built out of the exact sequence a real job offer follows, and the only thing missing is any way for you to check whether the company knows this conversation is happening.

Short answer: You cannot reliably verify a job offer today, because employers publish websites and email domains but never sign the individual artifacts they send. The fix is a verifiable employer: interview invitations, offers, and any request for money or bank details carry a signature from an enrolled human at the company, under a scope that cannot express a payment request, and the candidate checks it offline against the employer's published key.

How much do job scams actually cost?

The FBI's Internet Crime Complaint Center tracked employment fraud as its own crime type in its 2025 annual report, recording roughly 24,688 complaints and close to $363 million in reported losses, which placed it around tenth among tracked categories by both complaint volume and dollar loss (FBI IC3 2025 Internet Crime Report). Separately, Federal Trade Commission data on job and employment agency scams has shown reported losses climbing steeply across recent years, with figures for 2024 reported in the region of half a billion dollars and a large share of cases originating in contact made through social media (FTC consumer protection data).

A smaller line item is worth pulling out because it is the leading edge rather than the bulk: reporting on the IC3 figures has described losses in the region of $13 million tied specifically to schemes using deepfake video or synthetic voice within employment scams. Treat that number as directional. It is a first year of measurement for a category that did not previously have a box to tick, and first year measurements of new fraud types are almost always low.

Every one of these totals understates the problem, and the reason is not methodological sloppiness. It is shame. Fraud research has consistently found that victims under report, and job scam victims have a particular reason to stay quiet: the scam targets people who are unemployed, or underemployed, or in a visa situation where a job offer is not just income but status. Telling someone you lost two thousand dollars to a fake recruiter means telling them you were desperate enough to be fooled. A great many people simply do not file.

Who actually loses

There are three distinct victims and the coverage almost always names only one.

The candidate loses money, and worse, loses identity documents. A passport scan, a national identity number, a bank account and routing number, and a signed offer letter with a home address is a complete kit for opening credit in someone else's name. The financial loss is recoverable in the sense that it is bounded. The document loss is not bounded, because those documents do not expire on any schedule that helps.

The employer loses candidates and reputation and has no way to fight back. A company whose brand is being used in a scam campaign discovers it through support tickets from strangers, publishes a warning notice on its careers page, and then watches the campaign continue, because the notice is a page nobody reads before they are already three conversations deep.

The platform loses the thing it sells. A professional network's entire value proposition is that a message from a recruiter is worth reading. Every scam message degrades that, and the platform's tools for the problem are reporting queues and verification badges, which arrive after the damage and prove the wrong thing respectively.

What does a modern job scam actually look like?

It helps to see the funnel as the operator sees it, because the design is genuinely good and dismissing it as obvious is how careful people get caught.

The outreach

The operator does not invent a company. Inventing a company is expensive and fails the first search. The operator borrows a real one, ideally a mid to large employer with a known remote hiring programme, a distributed workforce, and enough staff that no candidate expects to recognise every name. The recruiter profile is either fabricated on a real platform, which costs nothing, or is a compromised account belonging to an actual recruiter, which costs a phishing email and is far more effective because the account history is genuine.

The interview

The interview is where a scam used to fall apart and no longer does. Chat based screening became normal, which removes the need for any live impersonation at all. Where a call is required, a short low quality video call with an apology about the camera is unremarkable, and synthetic video and voice have moved the floor on how convincing a live impersonation can be for the length of a screening call. The interviewer asks real questions because the questions are copied from the real job description, which is public.

The offer

The offer letter is the artifact that closes the psychological loop, and it is a PDF. A PDF with a logo, a name, and a signature image. There is no technical property of that document that a candidate can check. It is a picture of trustworthiness, and it has been a picture of trustworthiness since long before anyone was faking them at scale, which is why nobody thought to fix it.

The ask

The extraction has four common shapes, and the sophisticated operators use the ones that do not feel like a payment at all:

The task scam variant

Worth naming separately because it is the fastest growing shape and it does not look like a job scam at all. The victim is recruited into what is described as flexible remote work: rating products, optimising apps, completing sets of simple online tasks. Early tasks pay small real amounts, which builds trust and produces a visible balance in a dashboard. Then the tasks begin requiring the worker to deposit their own funds to unlock the next tier or to cover a negative balance, and the dashboard shows growing earnings that cannot be withdrawn. Victims frequently deposit repeatedly, chasing a balance that was never real, and losses in this variant run far higher per victim than in a classic equipment scam.

Why does hiring leave the candidate defenceless?

Here is the structural observation that this whole post exists to make, and it is rarely said out loud because it is uncomfortable for an entire industry.

Hiring is an asymmetric trust relationship. The candidate is required to prove, at their own cost in time and privacy: their identity, their right to work, their education, their employment history, their references, their criminal record in many jurisdictions, and in some sectors their credit history and their medical fitness. There is a multi billion dollar background screening industry devoted entirely to verifying the candidate. Read our comparison of that industry in Manav versus Checkr, HireRight and Sterling for how thorough that machinery is.

The employer is required to prove: nothing.

The employer provides a website, an email domain, a logo, and the good name of a company that in most cases genuinely exists. None of these is a proof. All of them are copyable in an afternoon. The verification industry points in exactly one direction, and it is not the direction where the individual with the least power and the most to lose is standing.

Once you see the asymmetry, the fraud statistics stop being surprising. Scams flow toward whichever party cannot verify the other, the way water finds the low point in a floor. We have spent twenty years hardening the candidate side of the hiring relationship and zero years hardening the employer side, and then we express surprise that fraud concentrates on the unhardened side.

Why do warnings, badges and domain checks not work?

Every existing control fails in an instructive way, and the failures are not about effort.

Warnings verify nothing

The standard employer response is a notice on the careers page: we will never ask you to pay for equipment, we will never conduct interviews solely over chat, we will never request bank details before an offer. These are true, useful, and structurally too late. The candidate reads the careers page at the start of the funnel, when they are checking that the company is real, and encounters the fraudulent ask at the end of the funnel, days later, in a different channel, under time pressure, in a state of hope. A warning is a general statement about the world. It cannot tell you anything about the specific message in front of you.

Domain authentication proves a domain, not a message

Email authentication using SPF, DKIM and DMARC genuinely reduced a category of fraud, and the analogy to what needs to happen here is close enough to be worth studying. But what DMARC establishes is that a message came from a domain authorised to send for that domain. It does not establish that the human who sent it had authority to make the offer it contains, and it does nothing when the operator uses a plausible lookalike domain, or a free mail account with the company name in the display field, or an account genuinely belonging to a real recruiter at the real company that has been compromised. We wrote about this progression from domain trust to human trust in verifiable humanity is the new verifiable email.

Badges prove a profile, not an artifact

Platform verification badges establish that an account holder completed an identity check with the platform at some point. That is a real improvement over nothing. It says nothing about whether the specific offer letter attached to a specific message was authorised by the employer, and it does not travel: the badge exists inside the platform, while the offer arrives by email and the payment request arrives by chat on a different service entirely. Fraud is a cross channel activity and the badge is a single channel signal.

Detection has the same arms race problem it has everywhere else

Platforms run classifiers over recruiter messages looking for scam patterns, and those classifiers work on the crude campaigns and fail on the careful ones, and generate false positives that suppress legitimate recruiters. This is the same structural loss described across this series and catalogued in detection debt: when the adversary can iterate against the classifier and the cost of generating a plausible message has collapsed, the classifier's job gets harder every quarter while its budget grows.

What would a verifiable employer actually look like?

Turn the machinery around. Everywhere else in this series, an organisation asks a human to sign something so the organisation can trust the human. Here, the organisation signs so that the human can trust the organisation. The mechanism is identical and the direction of verification is reversed.

The analogy worth holding is the difference between a company letterhead and a company seal. Letterhead is a claim about origin that anyone with a printer can reproduce, and for a century that was fine, because printing was mildly inconvenient and most people were honest. A seal was a physical object held by specific people with specific authority, and its whole value was that possession was restricted. We have spent thirty years moving business communication onto letterhead and we never built the seal.

The structure

An employer holds a signing key, published at a well known location on its own domain, the way an organisation already publishes DNS records and email authentication policy. That key is the root.

From that root, the employer issues scoped delegations to the humans who are authorised to conduct hiring: internal recruiters, hiring managers, and the external agencies acting on its behalf. A delegation is not a password and not an account. It is a signed object that says exactly what this human may do, for how long, and it can be revoked. We covered the general shape in how delegation tokens work and the depth and attenuation rules in delegation chain depth.

Every hiring artifact that matters then carries a signature from an enrolled human, under that delegation, over the contents of the artifact:

{
  "artifact": "offer_letter",
  "employer": "example-corp.com",
  "candidate_ref": "sha256:9f2c...",     // hashed, not the name
  "role": "Senior Platform Engineer",
  "start_date": "2026-10-19",
  "compensation_hash": "sha256:41ab...", // terms bound without publishing them
  "issued_at": "2026-09-22T14:05:11Z",
  "expires_at": "2026-10-06T23:59:59Z",
  "signed_by": "recruiter:d41d8c",       // delegated key, not a name
  "delegation": "chain:8a3f...",
  "scope": ["issue_interview", "issue_offer"]
}

The interesting part is the scope, not the signature

Most people reading the object above will focus on the signature. The important field is scope, and specifically what is absent from it.

A recruiter delegation contains issue_interview and issue_offer. It does not contain, and in a well designed scheme cannot contain, anything resembling request_payment or collect_bank_details. The employer defines a scope vocabulary in which the fraudulent ask is not an expressible operation. That means a candidate does not have to make a judgment call about whether this particular payment request is legitimate. The request is either unsigned, in which case it is not from the employer, or it is signed under a scope that does not permit it, in which case verification fails loudly for a structural reason rather than a suspicious one.

This is worth sitting with, because it is a stronger property than authentication. Authentication tells you who sent something. A scope vocabulary tells you that the category of thing you are being asked to do is not a thing this relationship can contain. It is the difference between checking whether the person at your door is really from the water company, and knowing that the water company never asks for cash.

What the candidate does

Nothing that requires an account, and nothing that requires understanding any of the above. The candidate pastes the offer, or drops the PDF, into a public verifier, or the platform displays the result inline. The verifier fetches the employer's published key, walks the delegation chain, checks the signature over the artifact contents, checks expiry and revocation, and returns one of three answers: signed by an authorised representative of this employer, not signed at all, or signed but with a scope that does not cover this request. Verification is offline in the sense that matters, which is that it does not require asking Manav or asking the employer, only the employer's published key. We explain that property in can you verify a credential without phoning the issuer.

$ manav verify offer.pdf

  employer     example-corp.com          [key published 2025-11-02]
  signer       recruiter:d41d8c          [delegation valid, expires 2026-12-31]
  scope        issue_interview, issue_offer
  artifact     offer_letter              [signature valid]

  REQUEST IN MESSAGE: purchase equipment via third party vendor
  -> NOT COVERED BY SCOPE. No authorised representative of
     example-corp.com has signed a payment request.

Where does this leave the candidate, step by step?

The table below is the practical core of the post: every point in the funnel where a candidate is currently exposed, and what changes when the employer signs.

Funnel stepWhat the candidate can check todayWith a verifiable employer
Recruiter outreachProfile age, connections, company page. All copyable or compromisable.Signed invitation naming the employer and the delegated recruiter. Unsigned outreach is not proof of fraud, but it is not proof of anything.
Interview schedulingWhether the calendar invite comes from a plausible domain.Signed invitation with scope issue_interview, bound to a time and a role.
Offer letterNothing. A PDF has no checkable property.Signature over the role, start date and a hash of the terms, from a key that traces to the employer.
Bank details requestWhether the email looks right.Verification fails structurally: no hiring delegation carries a scope permitting collection of payment data.
Equipment or fee paymentWhether the vendor site looks professional.Same structural failure. The employer cannot sign it because the scope cannot express it.
Identity documentsWhether the portal has a padlock.Signed request naming the collecting party and purpose, so the candidate knows who holds the passport scan.

Notice that the last three rows all resolve the same way. The extraction steps, which are the only steps where the candidate actually loses something, are precisely the steps that a legitimate hiring delegation has no authority to perform. That is not a coincidence. It is the reason this control is well shaped for this problem.

Why would an employer bother?

Because it is a recruiting advantage before it is a security control, and that is the honest commercial argument.

Consider the candidate's position in a market where some employers sign and some do not. The signing employer's outreach carries a verifiable claim. The non signing employer's outreach is indistinguishable from a scam campaign impersonating them. Candidates learn quickly, in the way they learned to look for the padlock, and the asymmetry becomes a hiring cost for the employer that does not sign.

The same enrollment does further work later. The recruiter enrolled to sign offers is the same enrollment used for internal approvals. The candidate who verified an offer can carry that same enrollment into day one binding and into the continuity thread described in the person you interviewed is not always the person at the keyboard. Hiring fraud runs in both directions, and the two problems share machinery. The employer that solves the candidate facing half has already built most of what it needs for the candidate side verification described in the deepfake hiring playbook.

There is also a support cost argument that will land with any large employer's talent operations team: brand impersonation generates a steady stream of inbound from strangers who were scammed in the company's name, each of which requires a human response and none of which the company can prevent. A published key and signed artifacts convert an unbounded support problem into a link.

What are the honest limits?

This control is narrower than it first appears, and pretending otherwise would be exactly the overclaiming this series criticises elsewhere.

What to do this week

If you are a job seeker:

  1. Treat any request for money, in any direction, at any point in a hiring process, as disqualifying. Legitimate employers do not have you buy your own equipment through a link they send you.
  2. Contact the company through a channel you found yourself, not one they gave you. Search for the company's main number, call it, ask for the recruiter by name. The operator controls every channel they hand you.
  3. Delay giving bank details until you have verified the employer independently, and give identity documents only through a portal you reached from the company's own domain that you typed yourself.
  4. Ask the recruiter directly whether the company signs its hiring artifacts and can provide a verifiable offer. The answer is informative either way, and asking costs you nothing.
  5. If you were caught, report it to IC3 and the FTC anyway. The under reporting problem is why the funding to fix this is smaller than it should be, and your report is a data point that argues for it.

If you are an employer:

  1. Find out how many brand impersonation reports your talent team receives per quarter. Most companies have never counted, and the number is usually higher than leadership expects.
  2. Write down your hiring scope vocabulary: the complete list of operations a recruiter is authorised to perform on the company's behalf. The exercise is valuable even if you never sign anything, because most companies discover the list has never been written down.
  3. Publish a plain statement of what your hiring process never includes, and put it in the offer email rather than only on the careers page, so it arrives at the moment of risk instead of at the start.
  4. Review agency delegations. Ask which external firms can send outreach in your name today, through which channels, and how you would stop them by Friday if you needed to.
  5. Start with the offer letter. It is one artifact, produced by a small number of people, at a low volume, at the highest stakes moment in the funnel. It is the correct pilot.

For the mechanics of signing and verifying artifacts, the developer documentation covers the signature format and the delegation chain structure.

Frequently asked questions

How can I verify that a job offer is really from the company? Today, with difficulty: contact the company through a phone number or address you found independently, never one supplied in the message, and confirm the recruiter and the role. The durable fix is a signed offer that you can check against the employer's published key, which proves an authorised representative issued it rather than someone who copied a logo.

How much did people lose to job scams in 2025? The FBI's Internet Crime Complaint Center recorded roughly 24,688 employment fraud complaints and close to $363 million in reported losses for 2025. Federal Trade Commission data shows a steep multi year rise, with 2024 figures reported in the region of half a billion dollars. All of these understate the total, because job scam victims report at low rates.

Do real employers ever ask you to pay for equipment? No. Legitimate employers buy their own equipment and ship it, or reimburse through payroll after you are employed and on the books. Any request to purchase through a specified vendor with a promise of later reimbursement is the single most reliable indicator of a scam in the entire funnel.

What are the signs of a fake recruiter? Interviews conducted only over chat, pressure to move quickly, a compensation figure slightly above market, requests for bank details or identity documents before a signed offer, and any payment in any form. Be aware that sophisticated operators produce none of these signals until the final step, so absence of red flags is not evidence of legitimacy.

Does a verification badge on a recruiter's profile mean the offer is real? No. A badge indicates that the account holder completed an identity check with that platform. It does not establish that the specific message, invitation or offer was authorised by the employer, and it does not travel to email or chat, where the extraction step usually happens.

What is a task scam? A variant where the victim is recruited into simple online work that pays small real amounts at first, then requires them to deposit their own funds to unlock further earnings. The dashboard shows a growing balance that cannot be withdrawn. Losses per victim are typically far higher than in equipment or fee scams because victims deposit repeatedly.

Could an employer sign offers today? The cryptographic machinery exists and is demonstrated in the hiring and verification labs, but connectors into applicant tracking systems do not. A company could pilot signed offer letters as a standalone artifact now. Full integration into the hiring stack is a reference design at this stage, not a shipped product.

Sources

  1. FBI Internet Crime Complaint Center, annual Internet Crime Reports, including 2025 employment fraud complaint and loss figures. ic3.gov/AnnualReport/Reports
  2. FBI Internet Crime Complaint Center, public service announcements on employment and task scams. ic3.gov/PSA
  3. Federal Trade Commission, consumer protection data and guidance on job scams. consumer.ftc.gov/articles/job-scams
  4. Federal Trade Commission, Consumer Sentinel Network data books and data spotlights on fraud reporting. ftc.gov/news-events/data-visualizations/data-spotlight
  5. RFC 7489, Domain-based Message Authentication, Reporting, and Conformance (DMARC), for the domain authentication analogy. rfc-editor.org/rfc/rfc7489
  6. W3C Verifiable Credentials Data Model 2.0, for the credential format prior art. w3.org/TR/vc-data-model-2.0
We built an entire industry to verify the candidate and never once asked the employer to prove it was really them.