Disclaimer

This lab uses public incident reporting and sanitized synthetic artifacts for defensive OSINT training. Real incidents are referenced for educational context only. The interactive data is fictionalized and must not be used to identify, contact, expose, or accuse real people.

← Back to Incident Lab
Case 06 / Phishing / Social Engineering2025

Fake Recruiter Package

Unravel a fake job-offer phishing chain built around a lookalike company domain and a bogus meeting-verification host, without ever clicking a live link.

Source Assessment

Good. The pattern is documented in official consumer-protection and CISA guidance; the specific company, domains, and messages here are entirely fictional training data.

Last Audited:2026-07-02

Incident Brief & Analytical Mission

A candidate reports seeing a 'Senior OSINT Analyst' posting attributed to the fictional firm Northline Analytics Ltd. The recruiter messages arrive over a professional networking site, email, and a messaging app, and push the candidate toward an interview link that hops from a lookalike careers domain to a fake meeting-verification host. This mirrors a widely documented 2023-2025 pattern in which threat actors impersonate recruiters, register lookalike hiring domains, and route victims through fake calendar or meeting-verification pages to harvest credentials. All names, domains, and messages in this case are synthetic.

Investigative Mission

Work as a passive analyst: compare the lookalike hiring domain against the company's real domain using WHOIS/RDAP metadata, check whether the posting exists on the official careers page, reconstruct the full phishing chain from message to final host, and write defensive advice for candidates, all without visiting any live attacker infrastructure.

Evidence Console#01 / 03

Recruiter Message Metadata Summary

Sanitized summaries of the three recruiter messages the candidate received. All domains are defanged with .test TLDs; no live links.

OKTA CUSTOMER SUPPORT INBOX (MOCK SIMULATION)ONLINE

Investigative Checklist Tasks

  • 01

    Compare the WHOIS/RDAP records to state the difference between the real northlineanalytics[.]test domain and the lookalike hiring domain.

  • 02

    Determine whether the advertised role exists on the company's official careers page and label the posting accordingly.

  • 03

    Write the phishing chain end to end: recruiter message → shortener → lookalike careers domain → final verification host.

  • 04

    List three defensive actions a candidate should take when a recruiter pushes an off-domain interview link.

Analyst Notebook

Evidence Notebook

Use this panel to log individual threads of evidence. Your entries are saved locally in this browser only.

No evidence records logged yet.

Report Desk

Report Drafting Board

REPORT PREVIEW
# CSINT Incident Lab Report

## Research Question
Is the 'Senior OSINT Analyst' recruitment package a legitimate Northline Analytics hiring process or a phishing chain?

## Summary
No analyst summary provided yet.

## Fact
- No forensic facts recorded in the notebook.

## Signal
- No analytical signals logged.

## Inference
- No alternative explanations recorded.

## Recommendation
- No next-pivot recommendations recorded.

## Confidence
Low

## Limitations
No limitation notes entered.

## Source reliability
Not assessed. Annotate each source with its reliability tier before publishing.

## Information validity
Not assessed. Confirm whether each item is directly observed, reported, or inferred.

## Missing context
Not recorded. List what data is missing or could not be verified from public sources.

## Next safe steps
- No next safe steps specified.

## Sources used
- No source references listed.

---
Generated at: 2026-07-24T18:30:26.714Z