Disclaimer

This lab uses public incident reporting and sanitized synthetic artifacts for defensive OSINT training. Real incidents are referenced for educational context only. The interactive data is fictionalized and must not be used to identify, contact, expose, or accuse real people.

Case 06Phishing / Social Engineering

Fake Recruiter Package

Unravel a fake job-offer phishing chain built around a lookalike company domain and a bogus meeting-verification host, without ever clicking a live link.

Difficulty: Beginner25 mins100 ptsBadge: Recruiter Skeptic
Source Assessment

Good. The pattern is documented in official consumer-protection and CISA guidance; the specific company, domains, and messages here are entirely fictional training data.

Last Audited:2026-07-02

01Incident summary

A candidate reports seeing a 'Senior OSINT Analyst' posting attributed to the fictional firm Northline Analytics Ltd. The recruiter messages arrive over a professional networking site, email, and a messaging app, and push the candidate toward an interview link that hops from a lookalike careers domain to a fake meeting-verification host. This mirrors a widely documented 2023-2025 pattern in which threat actors impersonate recruiters, register lookalike hiring domains, and route victims through fake calendar or meeting-verification pages to harvest credentials. All names, domains, and messages in this case are synthetic.

02Analyst mission

Work as a passive analyst: compare the lookalike hiring domain against the company's real domain using WHOIS/RDAP metadata, check whether the posting exists on the official careers page, reconstruct the full phishing chain from message to final host, and write defensive advice for candidates, all without visiting any live attacker infrastructure.

03Review the evidence

Evidence Console#01 / 03

Recruiter Message Metadata Summary

Sanitized summaries of the three recruiter messages the candidate received. All domains are defanged with .test TLDs; no live links.

OKTA CUSTOMER SUPPORT INBOX (MOCK SIMULATION)ONLINE

04Tasks

4 steps
  1. 01

    Compare the WHOIS/RDAP records to state the difference between the real northlineanalytics[.]test domain and the lookalike hiring domain.

  2. 02

    Determine whether the advertised role exists on the company's official careers page and label the posting accordingly.

  3. 03

    Write the phishing chain end to end: recruiter message, shortener, lookalike careers domain, and final verification host.

  4. 04

    List three defensive actions a candidate should take when a recruiter pushes an off-domain interview link.

05Log your findings

Analyst Notebook

Evidence Notebook

Use this panel to log individual threads of evidence. Your entries are saved locally in this browser only.

No evidence records logged yet.

06Write the report

Report Desk

Report Drafting Board

REPORT PREVIEW
# CSINT Incident Lab Report

## Research Question
Is the 'Senior OSINT Analyst' recruitment package a legitimate Northline Analytics hiring process or a phishing chain?

## Summary
No analyst summary provided yet.

## Fact
- No forensic facts recorded in the notebook.

## Signal
- No analytical signals logged.

## Inference
- No alternative explanations recorded.

## Recommendation
- No next-pivot recommendations recorded.

## Confidence
Low

## Limitations
No limitation notes entered.

## Source reliability
Not assessed. Annotate each source with its reliability tier before publishing.

## Information validity
Not assessed. Confirm whether each item is directly observed, reported, or inferred.

## Missing context
Not recorded. List what data is missing or could not be verified from public sources.

## Next safe steps
- No next safe steps specified.

## Sources used
- No source references listed.

---
Generated at: pending