The Fake Job Offer That Only Wants Your Work Password
Here's how it works, and one detail gives the whole thing away.
Security researchers at Zimperium spent a year tracking something worth telling your staff about: a phishing operation built specifically for phones. Here's how it works, and one detail gives the whole thing away. You get a message about a job. The link opens what looks like a careers page at a company you've heard of — the researchers found sites imitating Amazon, Apple, Boeing, Deloitte, Lego and Louis Vuitton, among others. Those companies are victims here too; their names are being borrowed. On a computer the page looks unremarkable. On a phone it opens full-screen with the browser's controls stripped away, including the address bar. So the standard advice — check the web address before typing anything — doesn't apply. There is no address showing. Then it asks you to sign in, and turns away personal email addresses. A Gmail address is rejected. It only accepts a work one. That's the tell, and it tells you who the target is: not the person reading the message, but whoever employs them. The technical part — you can skip this box Zimperium zLabs tracked 46 previously unpublished recruitment-themed lookalike domains across a year of telemetry. The kit fingerprints the device and serves a chromeless full-screen credential harvester to mobile clients. Submitted credentials are filtered server-side, rejecting consumer email domains. Successful captures yield OAuth tokens permitting access to internal communications and cloud applications. What that actually means "Lookalike domains" are web addresses built to resemble a real company's. New ones appear constantly, and there's a window — sometimes days — before security software learns they're bad. These operations live in that window on purpose. "OAuth tokens" are the part worth understanding. Signing in often doesn't hand a password to each app; you get a pass, and apps check the pass. Steal the login, get the pass, and it opens company chat and cloud files without asking again — which is why changing the password afterward doesn't always end it. The pass has to be cancelled too. Why phones specifically On a phone almost every defense people were taught is unavailable. You can't hover over a link to preview it. The address bar hides. A logo fills the screen. And people read messages walking, distracted, between other things — the exact state this relies on. It also arrives where company security barely reaches: not the filtered work inbox, but a text or a networking app, often on the employee's own device. What we'd actually do Send one sentence round your office this week: never sign in with your work login on a site you reached from a message about a job. That rule asks nobody to spot anything, which matters, because on a phone it will look right. A real recruiter has no use for those credentials and would find it strange you offered. Two things on your side. Make sure MFA is on for company email — a stolen password alone gets much less far. And make clear who to tell: the useful window after someone enters their work login somewhere they shouldn't is the next hour, not the next week, and people only speak up that fast if they're sure the response won't be a lecture.