Skip to content

Applicant Beware - Who Is Recruiting You?

  • Knowledge Level: All Levels
  • Protection Stage: Operate & Detect
  • Time to read:

This guidance helps you to recognise suspicious adverts and recruiter behaviours and understand how you can protect yourself and your organisation by reporting concerns and ceasing engagement if something doesn’t look right

Last Updated: 28 May 2025
Share this article:

This guidance is also available as a PDF: Applicant Beware - Who Is Recruiting You?

Spotting the Signs of Online Targeting

Why are you a target?

The UK is a target for Foreign Intelligence Services (FIS) who use a variety of methods to collect information that they believe will give them advantage over the UK. We have previously warned about the use of direct approaches over professional networking sites. A new method deployed at scale by FIS and third parties acting on their behalf is the use of online job platforms to attract applicants who have direct or indirect access to privileged information. 

This guidance helps you to recognise suspicious adverts and recruiter behaviours and understand how you can protect yourself and your organisation by reporting concerns and ceasing engagement if something doesn't look right.

We recommend that you use the 4Rs when reviewing jobs adverts and throughout the application process: 

  1. Realise the evolving threat,
  2. Recognise the signs of suspicious adverts and recruiter behaviours,
  3. Report your suspicions without delay, and
  4. Remove them from your online network and cease engagement.

Realise: the evolving threat

Our Think Before You Link campaign highlights direct approaches over professional networking sites by FIS with the goal of accessing information that harms UK national security and economic wellbeing. This type of approach still occurs. Our experts have identified that this tactic has evolved, and FIS are also posting job adverts to online platforms to attract applicants with direct or indirect access to sensitive and protected information. Thousands of suspicious job adverts have been posted to online job platforms, with more appearing daily.

Information sought by FIS may not necessarily be “classified” or an obvious target for espionage. Your insights and network of contacts can form valuable ‘pieces of the jigsaw’ when brought together with other information. Desirable information includes non-public, sensitive, or protected information on a wide range of topics, for example:

  • UK HMG policy
  • Geopolitical issues
  • Western military capabilities and alliances

Applicants bear the consequences

This includes prosecution under the National Security Act (2023) for offences such as disclosing protected information or obtaining a material benefit from or assisting a Foreign Intelligence Service.

Who is of Interest?

Job adverts target a wide range of individuals: 

  • UK government and parliamentary employees
  • Military employees
  • Current or former clearance holders
  • Academics
  • Think tank employees
  • Private defence firm and consultancy employees
  • Former staff, and individuals who can provide access to the categories identified above

How do Foreign Intelligence Services hide their identify?

A variety of techniques are used to covertly post job adverts online, for example:

  • Using headhunters and recruitment consultants to act on their behalf
  • Setting up fake companies
  • Spoofing legitimate companies

It will never happen to me - navigating tactics used at scale

When an unsolicited email arrives in your inbox, you are more likely to be suspicious as it can bear the hallmarks of a scam: urgency, high reward, too good to be true… 

This evolving tactic is effective because you make the initial approach in applying for a job opportunity, and are unaware that you are at risk of engaging with a state actor. 

In a legitimate recruitment process, the person you’re talking to assesses your background and quality of work because they are considering if you’re the right candidate. A FIS is assessing whether the access and information you could provide will be useful to them.

Case study 

A UK-based consultant, Adam, applied for the following freelance analyst role advertised online by a consultancy company via a job seeker website:

  • Part-time, remote working role with flexible hours
  • Report writing and insights into international politics and geopolitical issues
  • Desirable experience: freelance analyst, with experience of government, security or military sectors
  • Payment: US$500 per project
  • Company details referenced a consulting firm  in Singapore

Adam provided a CV and cover letter detailing his professional experience and previous UK government employment. The email response from a company representative requested further information about his UK government experience. The company expressed the need for ‘exclusive information and high-quality analysis’ and interest in his government-related professional connections. Adam recognised the recruitment process as suspicious and reported it to the online platform and his department’s security team without delay. 

Subsequent research indicated the ‘consultancy company’ was a Chinese Intelligence Service’s cover company who hid this using Western names and false information on a company website.

Recognise the Signs

They may (initially at least) look legitimate, but it is possible to spot the signs that job adverts and recruiter behaviours are suspicious, as illustrated by the graphics below.

When reviewing jobs, look out for signs of suspicious adverts


An accessible version can be found in the downloadable PDF


Who is of interest?
  • Applicants with access to non-public information
  • Applicants seeking remote or part-time roles
Company Background
  • Limited history, website or online presence
  • Stock imagery and generic descriptions of services
  • No link to physical addresses provided
Account Posting Job
  • New account, or lacks activity prior to posting
What is of interest?
  • Your network and connections
  • Topics, e.g.:
    • Western military capability
    • UK government policy
    • Geopolitical issues including tensions in the Indo-Pacific region
Look and feel
  • Spelling or grammar errors
  • Names and emails similar to well-known consulting companies
  • Broken website links
  • Generic job titles, e.g.:
    • “geopolitics”
    • “international affairs”
    • “political risk”
  • Buzz words, e.g.:
    • “unique insights”
    • “hot topics”

If applying, look out for signs of suspicious recruiter behaviour

  • You spot and apply for an opportunity you find on an online job platform
  • They quickly move communications onto an encrypted platform
  • They may not use video capability and may claim connectivity issues in interview
  • They ask questions about your suitability, probing about your access to sensitive information, including through your contacts
  • They provide little information about the company or its clients
  • They set a test report. Further report topics may focus on geopolitical and international matters. These may not relate to the services the company claims to offer
  • The pace develops quickly, with increasing requests for non-public, exclusive and sensitive information in reports
  • They ask you to gather information from your networks and connections
  • They pay through unconventional means e.g. online payment platforms and cryptocurrency
  • Payments from accounts which do not share the company name or clear links to the company
  • Tiered salary, with ‘insider’ information garnering higher pay
  • They may request in-person meeting in a non-Western country

Report

If you recognise signs associated with suspicious adverts and recruiter behaviours, report concerns to the online platform without delay. If you currently hold, or used to hold, a security clearance or have access to sensitive information (which can include academic research or bulk customer data) inform your department’s security team. Include the following details:

  • URL of the profile
  • Screenshot of the job advert and messages exchanged
  • Brief explanation of why you think the approach is suspicious
  • Any other relevant details

Remove and cease engagement

If you start an application process and notice suspicious recruiter behaviours, remove them from your network, and cease engagement immediately. Keeping malicious profiles in your network gives them legitimacy and puts colleagues and other contacts at risk.

General Tips 

  • Don’t advertise your security clearance publicly online – publicising this will mean you are of interest to malicious actors
  • Don’t reveal details of sensitive job roles and/or projects, either publicly or to unknown contacts
  • Don’t make your CV and /or social media profile information publicly available
  • If absolutely necessary, only include details of your security clearance in direct correspondence with genuine contacts
  • If it’s necessary to share sensitive details, such as a complete CV, or details of specific projects, do so one-to-one over trusted networks or in person with verified contacts
  • Check your organisation's guidance and policy on the management of your digital footprint
  • Use account settings to maintain your privacy and control who can view your profile (seek out the guidance on the relevant platforms you use). The more personalised these settings are, the more control users have over their information. NCSC has guidance on how to use social media safely

Further guidance

Keep up to date with National Protective Security Authority (NPSA) and National Cyber Security Centre (NCSC) guidance. It’s especially important to seek advice from your security department about declaring second jobs or consultancy work you may wish to undertake.

For further guidance on how you can help protect yourself and your organisation from this type of threat, download the Think Before You Link app.


Disclaimer 

This document has been prepared by the National Protective Security Authority (NPSA). This document is provided on an information basis only, and whilst NPSA has used all reasonable care in producing it, NPSA provides no warranty as to its accuracy or completeness. To the fullest extent permitted by law, NPSA accepts no liability whatsoever for any expense, liability, loss, damage, claim, or proceedings incurred or arising as a result of any error or omission in the document or arising from any person acting, refraining from acting, relying upon or otherwise using the document. You should make your own judgment with regard to the use of this document and seek independent professional advice on your particular circumstances. 

© Crown Copyright 2025

Did you find this page useful?
helpfulness rating