Back Express Fake job adverts posing as Disney and Coca-Cola 'steal your digital life'
Fraudulent job interview invitations purporting to be from Disney and Coca-Cola are being deployed to harvest passwords and workplace credentials in a phishing operation utilising over 800 fake domains. Cybersecurity experts at NordVPN have identified 813 phishing domains connected to a scheme mimicking recruiters from more than 75 prominent corporations, including Disney, Nike, Coca-Cola, Nvidia, Adidas, Adobe and Booking.com.
The deception typically commences with an email , message or from an individual masquerading as a recruiter. In certain instances, criminals have seemingly replicated the name and profile picture of an authentic employee from .
Prospective candidates are subsequently redirected to a branded webpage resembling Calendly to schedule an interview before being prompted to authenticate using Google or . NordVPN reports the simulated login window, including its address bar and security padlock, can be convincingly falsified.
Passwords and verification codes submitted by the target can then be captured in real time, potentially compromising workplace email, advertising accounts and corporate social media profiles.
One sector particularly targeted
The campaign seems to have specifically focused on individuals employed in marketing and communications roles, where a hijacked account could provide fraudsters with entry to important corporate systems and advertising funds. Adrianus Warmenhoven, cybersecurity adviser at NordVPN, explained that job interviews offered scammers an exceptionally persuasive cover story because candidates anticipate communicating with unfamiliar individuals, following directions and sharing personal details.
He said: "A branded page can closely resemble a genuine Calendly invitation before presenting what appears to be a Google or login window. In reality, that window is built into the scam page, meaning even the address bar and security padlock can be faked."
Daniel Mohacek, CEO of Truth Engine , explained the fraud operated by exploiting the trustworthiness of brands and actual individuals that candidates already know. A corporate logo, authentic staff photograph or seemingly legitimate profile can reduce a job hunter's vigilance before they have verified who is truly behind the .
Andy Burnham is to rain hell on state pensioners - triple lock is just the start
HMRC confirms £60,000 rule in 2026 as households face extra charge
Mohacek said: "Something looking credible is not proof that it is genuine. Fraudulent recruiters operating on may even have fake endorsements to add a layer of credibility."
He encouraged job hunters to verify unexpected approaches independently, including establishing that the position features on the organisation's official website and utilising information obtained themselves rather than those provided by the purported recruiter.
Kate Underwood, founder and chief people strategist at Southampton-based Kate Underwood HR and Training , explained that recruitment scams were growing ever more elaborate and targeted individuals exhausted by their employment . The use of real recruiters' names and photographs, convincing company branding and realistic login pages makes that initial approach particularly difficult to question, she explained.
She continued: "This isn't phishing for your CV. It's phishing for your whole digital life."
She recommended candidates should never utilise a Google or login window that emerges within another site, but rather open a fresh tab and navigate straight to the organisation's recruitment page. Francis West, CEO at Security Everywhere , revealed he encountered variants of recruitment scams monthly, featuring recruitment firms alongside well-known employers.
He continued: "These scams are very common, I see variations every month, not just with big brands but recruitment agencies too. They work because job hunting puts people in exactly the mental state scammers want: hopeful, anxious, and moving fast so they do not miss out. Nobody double-checks a login page when they think Disney just offered them an interview.
"It targets anyone job hunting, but hits hardest with people newer to the market or out of work a while, where the excitement of a big name wanting them overrides caution. My advice: never log in via a link in an unsolicited message, go straight to the company careers site instead.
"Real interview scheduling almost never asks you to log in, just to pick a time. If in doubt, call the company switchboard and ask if they really invited you. In phishing tests we run at Security Everywhere, a fake booking page skinned like Calendly is the one that catches people even when they know it is a test."
Make sure you report it
Career coach Amelia Brooke, of Amelia Brooke Career Vision , revealed she had flagged a suspected recruitment scam on only the week.
She continued: "It's extremely common. Just last week, I reported one to . Scammers exploit the excitement of an interview from a major global brand. The most common technique I have spotted is typo-squatting, where scammers deliberately alter company names by a letter or two – like Deloitte, PwC-Global-Careers, or KPMG-Jobs to catch the attention of candidates who might not realise the domain or name is slightly off.
"Advice: Don't just scroll past them when you see them. Just because you notice a scam doesn't mean others will. So, on , click "Report Post" > "It's suspicious or spam" > "Scam or fraud" to alert their security team to take down the posts, links, and burner profiles before other job seekers get lured in."
The ramifications may stretch far beyond the individual pursuing the fraudulent vacancy. Harvey Dhillon, founder and CEO at Zmartly, warned that a hijacked work login from someone in marketing or communications could similarly compromise company advertising accounts holding saved payment information.
He continued: "Job scams work because the login matters, not the person. Reporting on the campaign says those approached work in marketing and comms, whose login often opens an ads account with a payment method on it.
"Spotting the fake page is a security specialist's call, not mine, but the bill afterwards isn't. Under Meta's terms you are charged for any orders placed through your ad account, so the bill starts with the employer.
"Cap the ad account's total spend and store no card on it. If you are the one job hunting, never sign in to an interview booking page with the work account that has ads access. The person who clicked isn't the one who pays."
Check if it makes sense
Kelly Smallcombe, fractional chief people officer at Meliorem HR Consultancy , advised candidates should verify whether an approach aligns with the employer's standard hiring procedures.
She continued: "Recruitment scams like this are everywhere, and job seekers are an easy target. Desperation does the scammer's work for them, when someone's chasing a well-known employer, name recognition switches off their scepticism. To spot these, check how that employer actually recruits.
"Large companies list their applicant tracking system on their careers page, so a booking link that doesn't match is a red flag straight away. Genuine recruiters aren't sourcing candidates through , they're on or major job boards, and that's also where they'll have found your details.
"Ask yourself how they could plausibly have found you and why. Then verify the role itself, is it live on the company website, do you actually meet the requirements. Big employers get hundreds of applicants per vacancy, they are not chasing candidates down frequently."
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
