Dodgy Dave creates a fake recruitment account¶
Dave creates a recruitment profile for a company that does not exist and advertises well-paid remote work. Applicants are asked for identity documents, bank details and a £95 “security-vetting fee”. Dave thinks the respectable logo and a job title containing the word “consultant” will do most of the heavy lifting.
This card follows Dave’s recruitment-fraud method and the account evidence it creates. The investigator walkthrough explains how a reported account should be preserved, developed and attributed.
Dave invents a respectable employer¶
RC-41726hiring@northgate-careers.example3038Dave supplies the name “Martin Cole”, uploads a copied company logo and writes a profile describing offices in three cities. The profile is what applicants see; the account is the provider’s continuing record. The service assigns stable account ID RC-41726, which Dave does not control and cannot make more distinguished by adding “Ltd” to the display name.
The registration details are claims. They are still useful claims because the recovery address, mobile number, creation time and later changes can be tested against other services and devices. Provider account records may contain substantially more than the public page.
The account begins collecting people¶
Dave publishes two adverts and directs applicants to an online form. The form requests a passport image, driving licence, selfie and bank details “to prepare payroll”. It also asks successful applicants to pay £95 for security vetting.
RC-41726JOB-9021 · 4 Sep · 09:06 UTCAPP-73Dave now has more than a false profile. He has created records of adverts, applicant messages, document access, bulk downloads and account sessions. The files supplied by victims have their own provenance and may later appear on a device or another service.
Dave delegates the dull bits¶
Dave gives an associate access to answer routine questions. Several sessions can therefore exist against one account, and not every message must have the same author. Dave considers this efficient management; the criminal enterprise has apparently acquired a help desk.
RC-41726 published the adverts and accessed the applications.Who controlled the account is tested through session times, recurring application identifiers, security changes, possession of devices, local copies of applicant documents and communications allocating work. Shared access complicates attribution to a particular action, but it may also expose the structure of the offending and identify another participant.
Dave changes the name and closes the adverts¶
Complaints appear, so Dave renames the account “NGR Talent Solutions”, deletes the adverts and changes the recovery email. Public searches for Northgate Renewables become less useful. The provider’s stable account ID, earlier content IDs, change events and existing victim records remain connected to the same account.
The timing of the changes soon after complaints may be relevant conduct. More importantly, the same device identifier appearing during document downloads and deletion strongly links those events within the provider’s records.
What Dave changed - and what he did not¶
RC-41726 and recorded adverts, applications, sessions and changes.Dave’s employer was fictional. The service account, victim applications, access events and downloaded files were not. When independent provider records and device material agree, they create a strong route from the false employer towards the people operating it.