Audience page
Scams targeting remote workers
Remote workers are targeted through the tools and workflows they depend on: fake IT support requests, VPN and login phishing, equipment purchase scams, and HR impersonation. Working outside an office means fewer in-person checks and more reliance on digital trust.
Common searches
Why this audience gets targeted
- Remote workers rely on digital communication for everything, making email and chat impersonation more effective.
- IT support, HR, and equipment requests are routine in remote work, so fake versions blend in easily.
- Working alone at home means there is no colleague nearby to double-check a suspicious request in person.
What to check first
- Verify IT support and HR requests through your company's internal directory or Slack channel, not the message itself.
- Never enter credentials on a login page reached through an email or chat link. Navigate to the tool directly.
- Treat any request to buy equipment and submit for reimbursement as suspicious until confirmed by your manager.
Fake job offer advance payment scam
A victim receives what looks like a legitimate remote job offer and is asked to pay upfront for equipment, training, or background checks.
Verify the recruiter and company domain independently.
Job seekers
Global
Malicious browser extension data harvest scam
A seemingly useful browser extension captures browsing activity, credentials, or payment behavior after a short period of benign use.
Review permissions before installing.
Remote workers
Global
Airport Wi-Fi captive portal scam
A fake Wi-Fi portal at an airport asks for payment details, email credentials, or identity information before granting access.
Use a hotspot or VPN and confirm the exact airport network name.
Travelers
Global
Cloud storage password reset scam
A fake cloud-storage notice says files were shared suspiciously and captures the victim's account credentials or approval codes.
Use the storage provider app or website directly to review security alerts.
Remote workers
Global
Coding test malware job scam
A fake tech employer sends a take-home exercise or coding test that installs malware or steals credentials from the candidate's device.
Open interview files in a sandbox and never disable device protections for a candidate task.
Developers
Global
software license subscription scam
A website sells fake or unauthorized software licenses at a discount, then charges recurring fees for products the buyer never receives or cannot activate.
Buy software only from official vendor websites or authorized resellers.
Small business owners
U.S.
cloud storage upsell scam
A pop-up or email warns that cloud storage is full and directs the user to a fake upgrade page that charges for storage never delivered.
Check storage usage directly in your device settings β not through email links.
App users
U.S.
short-term rental scam
A listing for a short-term rental β often targeting business travelers β takes payment but the property does not exist or is not as described upon arrival.
Book through established platforms that hold payment until check-in is verified.
Business travelers
U.S.
military spouse job scam
Scammers target military spouses with fake work-from-home job offers that require upfront fees for training materials or equipment, exploiting the challenges of frequent relocations.
Never pay upfront for a job β legitimate employers cover training and equipment costs.
Military spouses
U.S.
hotel WiFi phishing scam
A fake hotel WiFi login page mimics the hotel's branding and asks for your room number, name, and credit card to provide internet access, stealing your payment information.
Verify the exact WiFi network name and login procedure at the front desk before connecting.
Travelers
U.S.
coffee shop man-in-the-middle scam
An attacker on the same coffee shop WiFi network intercepts communications between your device and the router, capturing sensitive data or injecting malicious content.
Always use a VPN on public WiFi β it encrypts all traffic and prevents interception.
Remote workers
U.S.
fake captive portal scam
A rogue WiFi network presents a convincing login page that mimics a legitimate business, collecting your email, social media credentials, or payment information.
Never enter social media or email passwords on a WiFi login page β legitimate portals do not require them.
Public WiFi users
U.S.
fake mobile hotspot scam
An attacker shares a mobile hotspot with a generic name like 'Free WiFi' in a public area, capturing all traffic from users who connect.
Be suspicious of generic open WiFi networks, especially in areas without advertised free internet.
Travelers
U.S.
WiFi Pineapple attack scam
A WiFi Pineapple device is used to automatically impersonate saved WiFi networks on your device, tricking it into connecting and exposing your data to the attacker.
Regularly clear saved WiFi networks from your device, especially open networks from hotels, airports, and cafes.
Business travelers
U.S.
public library WiFi spoofing scam
An attacker creates a fake WiFi network mimicking a public library's hotspot, targeting patrons who use library computers and WiFi for banking, email, and job applications.
Confirm the exact WiFi name with library staff and look for posted network information at the help desk.
Public WiFi users
U.S.
event venue fake network scam
A fake WiFi network at a conference, concert, or sporting event mimics the venue's official network to capture data from thousands of attendees simultaneously.
Check the event program, app, or organizer's website for official WiFi network details before connecting.
Travelers
U.S.
password reset phishing scam
A fake password reset notification urges the recipient to click a link and enter their current credentials, which are captured by attackers.
Never click password reset links you did not request β navigate directly to the service's website.
Office workers
U.S.
shared document notification phishing scam
A fake notification claims someone has shared a document with you via Google Drive, OneDrive, or Dropbox, leading to a credential-harvesting login page.
Hover over the link to inspect the URL before clicking β legitimate shares come from official domains.
Office workers
U.S.
account suspension notice phishing scam
A fake email warns that your email, bank, or streaming account will be suspended unless you verify your identity immediately, directing you to a credential-stealing page.
Log into your account directly by typing the URL in your browser β never use links from warning emails.
Office workers
U.S.
two-factor authentication bypass phishing scam
Attackers use real-time phishing toolkits to capture both passwords and two-factor authentication codes simultaneously, defeating standard MFA protections.
Use hardware security keys (FIDO2/WebAuthn) which are resistant to real-time phishing proxy attacks.
IT administrators
U.S.
calendar invite phishing scam
Attackers send calendar invitations containing phishing links in the event description or location field, which automatically appear in the victim's calendar.
Change your calendar settings to not automatically add events from email invitations.
Office workers
U.S.
unsubscribe link trap scam
Phishing emails include a malicious unsubscribe link that, when clicked, confirms your email address is active and leads to credential theft or malware installation.
Do not click unsubscribe in emails from unknown senders β mark the email as spam instead.
Office workers
U.S.
video call then credential harvest scam
Scammers set up a video call posing as IT support, a vendor, or colleague, then share a screen link or chat message during the call that leads to credential theft.
Never enter credentials while sharing your screen in a video call.
Business professionals
U.S.
Teams meeting invite phishing scam
A fake Microsoft Teams meeting invitation arrives by email, and clicking the join link leads to a credential harvesting page disguised as the Teams login.
Hover over the meeting link before clicking to verify it points to a legitimate Microsoft domain.
Business professionals
U.S.
OneDrive sharing notification phishing scam
A fake OneDrive sharing notification email claims someone shared a document with you, but the link leads to a credential-stealing page.
Verify the sender by contacting them through a separate channel before clicking any shared document link.
Business professionals
U.S.
Craigslist job posting advance fee scam
Fake job postings on Craigslist require applicants to pay for training, background checks, or equipment before starting, then the job turns out to not exist.
Never pay money to start a job β legitimate employers cover the cost of training and background checks.
Job seekers
U.S.
fake campus job scam
Fraudulent job offers sent to student email addresses promise easy on-campus or remote work with high pay, then trick students into depositing fake checks or sharing personal data.
Verify campus job offers through your university's official career center or human resources office.
College students
U.S.
fake remote job posting scam
Scammers post attractive remote job listings on legitimate job boards, conducting fake interviews and collecting personal information or upfront fees from applicants before disappearing.
Verify any job offer by visiting the company's official website and contacting their HR department directly.
Remote workers
U.S.
remote job equipment purchase scam
New remote hires are told to purchase equipment from a specific vendor using a company check that later bounces, leaving the employee out of pocket for the full amount.
Legitimate employers provide equipment directly or reimburse after verified purchase β they never send checks to buy from unknown vendors.
Remote workers
U.S.
fake coworking membership scam
Scammers create fake coworking space listings or websites offering discounted memberships, collecting payments for spaces that do not exist or are not affiliated with the real location.
Verify coworking spaces by visiting the location in person or checking their verified profiles on Google Maps before paying.
Remote workers
U.S.
VPN phishing scam targeting remote workers
Phishing emails impersonate corporate IT departments and direct remote workers to fake VPN login pages that capture their corporate credentials.
Never click VPN login links in emails β always access your corporate VPN through the official application or bookmark.
Remote workers
U.S.
fake HR onboarding scam for remote workers
Scammers impersonate HR departments of companies and send fake onboarding documents to new remote hires, collecting tax forms, identification, and bank details for identity theft.
Verify the onboarding process by calling the company's main number and asking to speak with the HR contact who sent the documents.
Remote workers
U.S.
payroll redirect scam targeting remote workers
Scammers compromise or impersonate an employee's email and send payroll or HR a request to change direct deposit information, diverting paychecks to the scammer's account.
Always verify direct deposit change requests through a phone call to the employee using a known number, not the one in the email.
Remote workers
U.S.
fake home office stipend scam
Scammers posing as employers offer remote workers a home office stipend via check that is fraudulent, asking the worker to purchase items and return the excess funds.
Legitimate home office stipends are reimbursed after purchase or provided through corporate purchasing β never through personal check overpayment.
Remote workers
U.S.
Slack impersonation scam targeting remote workers
Scammers gain access to a Slack workspace or create convincing fake Slack notifications to trick remote workers into clicking malicious links or sharing credentials.
Never click links in Slack notification emails β open Slack directly through the app or bookmark.
Remote workers
U.S.
fake freelance platform scam
Scammers create counterfeit versions of popular freelance platforms like Upwork or Fiverr, tricking freelancers into creating accounts and accepting fake projects that lead to payment theft.
Always navigate to freelance platforms by typing the URL directly β never through ads or email links.
Remote workers
U.S.
time tracking malware scam targeting remote workers
Employers or scammers require remote workers to install time tracking software that secretly contains spyware, keyloggers, or cryptocurrency miners.
Only install time tracking software from verified developers β check reviews and the developer's reputation before installing.
Remote workers
U.S.
deepfake job interview scam
Scammers use AI deepfake technology to impersonate hiring managers during video interviews, collecting personal information and upfront fees from job seekers for positions that do not exist.
Verify the interviewer's identity by contacting the company directly through their official website.
Job seekers
U.S.
fake WiFi login QR code scam
QR codes posted in public spaces promise free WiFi access but lead to a fake login portal that captures email credentials and personal data or installs malware.
Ask staff for the official WiFi name and password rather than scanning posted QR codes.
Travelers
U.S.
MLM recruitment after job loss
MLM recruiters target people who have recently lost their jobs, framing the opportunity as a way to replace income quickly, when most participants earn less than minimum wage.
Remember that a legitimate employer pays you β you do not pay them to start working.
Job seekers
U.S.
Related audiences