Dream job as a trap
The BACS describes it in their half year report as the “Dream Job Playbook”: attackers use LinkedIn and other career platforms to specifically target victims. Fake recruiter profiles, tailored job offers, everything customized to the target person. Generated with AI and barely distinguishable from real messages.
What looks like a career opportunity is actually the entry point for a cyber attack.
How it works
The attackers create LinkedIn profiles that look like real recruiters from well known companies. Profile picture (AI generated or stolen), work experience, connections, everything checks out. Then they message people specifically, usually in IT, finance or management positions.
The first message is harmless: “We have an exciting position that matches your profile.” No link, no attachment, just a normal conversation. Trust is built over several days. Only then comes the next step: a link to a “job description” or a “coding challenge” for the application process.
The link leads to a professional looking website that installs malware. Or the victim is asked to download an “assessment tool” that is actually a trojan. In some cases personal documents are requested: ID, tax records, bank details. For the “onboarding” of course.
Who is behind it
The most well known group using this method is the Lazarus Group, a North Korean APT group. Their “Operation Dream Job” has been running since around 2020 and has already worked on defense companies, crypto firms and technology corporations. But the method is now being copied by very different groups; it is no longer just a state actor doing this.
The BACS confirms in their current report that such attacks are also increasing in Switzerland. The report does not give concrete numbers but the warning is clear enough.
Why it works
LinkedIn is an environment where you expect messages from strangers. Recruiters write to you, that is normal. Exactly this makes the platform so attractive for attackers. On top of that: AI makes the fake messages perfect. No spelling mistakes, right tone, appropriate industry terminology. The days of bad phishing are over (at least with the professional groups).
And the victims are often people in responsible positons with access to sensitive systems. A compromised IT director or CFO is significantly more valuable to the attackers than a random employee…
How to spot it
A few indicators that can help:
- The profile was created recently and has few genuine connections
- The offered position is too good to be true (above average salary, remote, flexible)
- Personal data or downloads are requested relatively quickly
- The “recruiter” switches to other channels (WhatsApp, Telegram) to avoid LinkedIn monitoring
When in doubt: google the recruiters name and the company. Contact the company directly and ask whether the position exists. And never install software you received from an unknown contact.
If you want to test your own employees resilience: we simulate exactly such scenarios in social engineering assessments and phishing simulations.
More on this topic in the BACS half year report 2026.
And whether the next LinkedIn recruiter is real..