Blog/Phishing

Phishing Aimed at HR and Recruiters

HR and recruitment teams open attachments from strangers every day, which makes them ideal phishing targets. Fake CVs, fake candidate portals, payroll diversion and how to stay safe.

CyberWatch AI1 October 2026 · 2 min read
A smiling professional at a desk with a laptop

Most people are told not to open attachments from strangers. Recruiters and HR teams do it all day: CVs, cover letters, portfolios, references. Attackers exploit that with malicious applications, fake candidate links and requests to change payroll details.

Common attacks on HR and recruiters

  • Malicious CVs: attachments that carry malware, especially documents asking you to enable content. See the macro warning.
  • Portfolio links to fake login pages or downloads.
  • Payroll diversion: "employee" emails asking to change salary bank details.
  • Fake job board or platform alerts leading to credential theft.
  • W-2 or tax form requests from a fake executive asking for staff tax data.

Safer recruiting habits

  1. Receive applications through your careers portal or applicant tracking system.
  2. Preview CVs in the browser or protected mode; never enable macros. See opening files safely.
  3. Be cautious with archives, HTML files and shortcut files labelled as CVs. See dangerous attachments.
  4. Log in to job platforms through bookmarks, not email links.

Payroll change controls

  • Accept bank changes only through the employee self-service system, or confirm in person or by a known phone number.
  • Notify the employee through a separate channel whenever their bank details change.
  • Require a second approver for payroll changes.

Requests for bulk employee data, such as tax forms or salary lists, must always be verified with the requester in person or by phone.

Unsure about an application email? Paste the text into CyberWatch AI Scan for a free check.

For all the types of phishing, read our complete guide.

Frequently asked questions

Why do attackers target recruiters?

Because opening CVs and links from strangers is part of the job, and HR holds personal data and can change payroll details.

How can recruiters receive CVs safely?

Through an applicant tracking system or careers portal rather than email attachments, and by viewing files in preview or a protected mode.

What is payroll diversion?

A request, apparently from an employee, to change their salary bank details, which actually routes pay to an attacker.

Sources

  1. Suspicious email actions, UK National Cyber Security Centre
  2. Small business guide: cyber security, UK National Cyber Security Centre
  3. Malware: How To Protect Against, Detect, and Remove It, US Federal Trade Commission
Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.