Fake Job Interviews Are Stealing Google and Facebook Logins

A phishing operation called RecruitTrap uses realistic pop-up windows to grab passwords and even one-time codes from job seekers.

ThreatVectr Newsdesk· 4 min read
Full frame, photoreal news-editorial image of a laptop screen showing a generic corporate sign-in code entry page in a dimly lit office, with a smartphone besid
Share

Key points

  • CTM360 has identified more than 3,000 phishing web addresses used in a recruitment scam it calls RecruitTrap.
  • The scam lures people with fake interview invitations, then shows a counterfeit Google or Facebook login window drawn inside the attacker's own page.
  • The more advanced pages can pass a victim's multi-factor code to the real site in real time, letting the criminals walk straight in.
  • Job seekers on LinkedIn, WhatsApp and email have been targeted worldwide, across recruitment, marketing and freelance work.
  • Security researchers say the trick, known as Browser-in-the-Browser, is very hard to spot with the naked eye.

Security firm CTM360 has uncovered a global phishing operation aimed at people looking for work. It dresses up as a friendly recruiter and ends with the victim's Google or Facebook account in someone else's hands.

The company's RecruitTrap report counts more than 3,000 web addresses tied to the campaign. That number alone tells you this is not a small side hustle. It is an assembly line.

How does the scam actually work?

The criminals contact people through LinkedIn messages, WhatsApp and email, posing as recruiters offering interviews or freelance gigs. Victims are sent to a slick scheduling page that looks like a normal booking tool.

To confirm the appointment, the page asks the victim to sign in with Google or Facebook. Up pops what looks like the familiar Google login window, complete with address bar and padlock.

It is not a real window. It is a picture of one, drawn inside the attacker's page using ordinary web code. Researchers call this trick Browser-in-the-Browser, or BitB, and it was first demonstrated publicly in 2022. First reported in detail by The Hacker News, the technique fools people because the fake window can be dragged around and even shows a convincing web address at the top.

Anything the victim types goes straight to the criminals.

What about two-step login codes?

Some of the pages go further and defeat two-step logins in real time. The moment a victim types their password, the attackers feed it into the real Google or Facebook site from their own server. That site then sends the victim a one-time code, and the fake page asks for it.

When the victim types the code, the attackers pass it along within the few seconds it stays valid. They are now signed in as the victim.

This kind of live relay attack, sometimes called adversary-in-the-middle, is exactly why the industry has been pushing passkeys, which are login credentials tied to your specific phone or laptop and cannot be typed into a fake box. A standard six-digit text or app code, sadly, can be phished. A passkey cannot be.

Who is being targeted?

Job hunters, freelancers and marketing contractors across many countries. The lures lean on urgency ("the recruiter is waiting") and on the emotional weight of a possible job offer, which is exactly the state in which people click without thinking.

Once inside a Google or Facebook account, the criminals can read private messages, reset other accounts through password-recovery emails, and, in Facebook's case, hijack business advertising accounts to run scam ads on someone else's card.

What should ordinary people do?

A few plain habits go a long way.

Sign of trouble What to do
A "recruiter" you did not apply to Verify the company and person on their official site before clicking
A login window that appears inside another web page Close it; open a new browser tab and sign in to Google or Facebook directly
Requests to "confirm" your identity with a code Never type a one-time code into a page you reached from a message
Your account is available for passkeys Turn them on in your Google or Facebook security settings

If you think you were caught out, sign in to your Google or Facebook account from a device you trust, change the password, review recent sign-ins, and revoke any unfamiliar app access. Then check your email for password-reset messages from your bank and other services, because that is where the criminals will head next.

© 2026 Threat Vectr