Job boards have an asymmetric fraud problem. The scammer is a poster, but the victims are applicants: people sharing their address, ID documents and bank details with an employer they think is real. A fake posting that stays up for even a day can collect a large number of applications. Every one of those is a person whose data or money is now at risk, and whose trust in your platform is gone.
This post covers how recruiter scams work and how to catch the people running them, who tend to come back again and again under new employer names.
The common schemes
Data harvesting. The posting exists to collect CVs, phone numbers, addresses and sometimes ID documents. The data is used for identity theft or sold on.
Advance-fee scams. The “employer” interviews by chat, makes an offer, then asks the applicant to pay for training, equipment, a background check or a visa process. Remote and work-from-home roles are favourites.
Fake check and reshipping scams. The new hire receives a check to buy equipment from a “vendor,” deposits it, sends money on, and the check bounces. Or they’re asked to receive and forward packages, unknowingly handling goods bought with stolen cards.
Off-platform steering. The posting moves applicants to a messaging app as fast as possible, away from your moderation.
In every case, the scammer needs an employer account that looks real long enough to collect applicants. When you ban it, they need another.
Why moderation alone keeps losing
Content moderation catches postings with obvious red flags: unrealistic pay, vague duties, personal email domains, requests for payment. Experienced scammers copy real postings from real companies, word for word, and change only the contact path. Their text is clean.
What doesn’t change between their first and fifth employer account is the person and the equipment. They post from the same few laptops, through the same proxies, often during the same hours. That is where detection gets durable.
Signals that link scam employers
Device reuse across employer accounts
Identify the device at employer sign-up, at login, and when a posting is published. Link each event to the employer account with linkedId. On the next employer sign-up, accountsOnDevice tells you every employer account that device has used:
import { PryntServer } from '@prynt/node';
const prynt = new PryntServer({ secretKey: process.env.PRYNT_SECRET_KEY });
async function screenEmployerSignup(requestId) {
const ev = await prynt.getEvent(requestId);
const priorIds = ev.accountsOnDevice.accounts.map((a) => a.linkedId);
const prior = await db.employers.findMany({ where: { id: { in: priorIds } } });
const banned = prior.filter((e) => e.status === 'banned_scam');
if (banned.length > 0) return { action: 'block', reason: 'device_linked_to_banned_employer' };
if (prior.length >= 2) return { action: 'review', reason: 'many_employers_on_device' };
if (ev.decision !== 'allow') return { action: 'review', reason: 'risk_signals' };
return { action: 'allow' };
}
A recruiter or agency may legitimately manage a few employer accounts from one machine, so “many employers on one device” is a review trigger, not a ban. A device tied to an employer you already banned for scams is a different matter. That is banned user re-registration in its purest form.
Network context
Scam operations often run from places they don’t claim to be. A “US logistics company” whose every session comes from a residential proxy, a VPN, or a hosting range is worth a look. Signals to weigh:
RESIDENTIAL_PROXY,DATACENTER,VPNandTORon employer sessions.LOCATION_SPOOFINGwhen the browser’s timezone and language don’t fit the network location.- The company’s stated location against the IP country of every session.
Any one of these has innocent explanations. Several together on a brand-new employer posting high-paying remote jobs is a pattern.
Velocity
Real employers post a few jobs, then wait for applicants. Scam accounts often publish many postings quickly, across categories and cities, to maximise reach before the ban. VELOCITY on the device and posting counts per account in the first 24 hours both help.
Your own outcomes
When an employer is confirmed as a scam, label it. Reporting the outcome through /v1/outcomes (or a console case) marks the device and linked accounts, and the KNOWN_ABUSER reason code shows up on the next event from that device. If you opt into the cross-customer reputation network, a device confirmed bad elsewhere can surface as NETWORK_REPUTATION on its first visit to you.
Respond before applicants see the posting
The most important design choice is timing. Removing a scam posting after two hundred people applied doesn’t help those two hundred people. Make new employers earn visibility:
- New employer, clean signals: publish normally.
- New employer, risk signals or device linked to several employers: hold postings for review before they go live, or publish with restricted reach and no direct contact details until verified.
- Device linked to a banned scam employer: refuse the account, quietly. Don’t name the reason.
Verification for held accounts can be proportionate: confirm a corporate email domain, check a company registry, or call a listed business number. Legitimate employers pass in minutes; scammers have to burn a real identity.
Protect applicants during the conversation
Scams often run through your messaging system before moving off-platform. Watch for employer accounts whose device or session signals changed abruptly, such as a takeover of a legitimate employer account, and for messages containing payment requests or external contact details from new employers. A taken-over real employer account is the most convincing scam vehicle there is, so treat a new device plus changed contact details on an established employer as a step-up event. The account takeover page covers those signals.
Measure it
Track how many postings were held for review, the share later confirmed as scams, and, most importantly, how many applications reached confirmed scam postings before removal. That last number is the one your applicants feel. It should fall sharply once repeat posters are caught at sign-up instead of after their postings go live.
Related reading: marketplace listing spam detection for the content side, and community abuse and harassment detection for repeat bad actors in messaging. The fraud rings page shows how linked devices and accounts appear as clusters. Start by linking every employer account to its devices today; the next time you ban a scammer, you’ll see who they were before, and catch who they become next.
Try it free
Prynt is device intelligence with a free tier — visitor IDs, bot & fraud Smart Signals, and behavioral biometrics, powered by a cross-site network. Start free.