Scams

Recruiting Scams: Compromised Accounts and the AI-Text Tell

By Nick · Updated
recruiting scamjob scamaccount takeoverAI-generated text detectioncrypto mixermoney laundering

Definition

A recruiting scam of this type compromises the account of a real, currently-employed recruiter at a legitimate company, posts genuine-looking job openings under that identity, and pressures applicants who respond into an upfront crypto payment — which then gets run through a mixing service as part of a standard laundering playbook.

How It Compares

Legitimate recruiter Scam (via compromised account)
Payment requests Never asks a candidate for money at any stage Asks for a fee (e.g. $250) to "improve your resume" or get it "ATS-optimized"
Programs offered Refers candidates only to their employer's own hiring process Pushes a side "program" the recruiter claims to run personally, outside their employer
Payment method N/A — no legitimate recruiter payment flow exists Requests cryptocurrency, a strong standalone red flag regardless of context
Account status Active, employer-verified Often a real person's account, compromised — not a fake profile created from scratch

The Evidence

In a documented case, a scammer took over the LinkedIn account of an actual Amazon recruiter, posted several real-looking openings, and replied to applicants pushing paid resume help. The reply included this sentence:

"The main issue isn't your background — it's that your resume isn't fully ATS-optimized…"

That sentence carries two independent statistical tells of AI-generated text:

  • Em-dash frequency: the em-dash appears considerably more often in AI-generated writing than in human-authored writing.
  • "It's not X, it's Y" construction: this negative-parallelism pattern is roughly three times more likely to appear in AI-generated text than in human writing (see The Atlantic's coverage of this phenomenon).

Because the underlying account belonged to a real, compromised person rather than a fabricated identity, the scam was reported to the platform and the employer for account recovery rather than published with identifying details.

Following the money: once a victim sends cryptocurrency, the standard laundering playbook has three steps — (1) use social engineering, ideally through a compromised legitimate account for added credibility, to get the victim to send crypto; (2) run the proceeds through a mixer (a pooling service that combines many people's coins and redistributes equivalent amounts, minus a fee, making the original source harder to trace); (3) spend or cash out, checking first that the mixer isn't on OFAC's sanctioned-counterparty list. In this case, the bitcoin wallet the scammer provided was empty by the time it was investigated — a single-use wallet, which is common scammer tradecraft that makes blocking individual wallets less effective. From there, the funds were consolidated with 59 other inputs and pushed into a pooling service, the mixing step of the playbook above playing out in real time.

What To Do About It

  1. Never pay to be considered for a job, including for resume review, ATS optimization, or "onboarding" fees — no legitimate employer or recruiter charges an applicant money at any stage of hiring.
  2. Verify independently. Confirm an opening through the company's own careers site or a colleague inside the company before treating any inbound recruiting message as fully trustworthy, even from an account that looks real.
  3. Treat a request for cryptocurrency payment as a hard stop and report the account to the platform immediately — crypto is used specifically because it enables the mixing/laundering step described above.
  4. Watch for AI-text tells as a soft signal, not proof. Frequent em-dashes and "it's not X, it's Y" phrasing show up more often in AI-generated messages, but they don't confirm a scam on their own — use them alongside other red flags like payment requests.
  5. Report compromised accounts to both the platform (LinkedIn) and the employer whose recruiter account was taken over, so the account can be locked and reclaimed.
  6. If you've already sent crypto, report it immediately — a wallet reported quickly, before it's consolidated and mixed, gives investigators the best chance of tracing it.

Caveats & Edge Cases

The AI-generated-text tells above are probabilistic, not diagnostic — plenty of human writers use em-dashes and parallel construction naturally, and plenty of AI-assisted legitimate business writing exists. Don't treat an em-dash alone as evidence of a scam; the actual disqualifying signal in this case was the payment request, which no legitimate recruiter makes.

Think you've spotted a scam?

Send it to us and we'll investigate it for free — the findings help build pages like this one.

← Back to Security Research