FraudHIGH

Job Scams - Coca-Cola and Ferrari Offers Are Traps

Featured image for Job Scams - Coca-Cola and Ferrari Offers Are Traps
MWMalwarebytes Labs
Summary by CyberPings Editorial·AI-assisted·Reviewed by Rohit Rana
Ingested:
🎯

Basically, fake job offers from Coca-Cola and Ferrari are tricking people into giving away their passwords.

Quick Summary

Scammers are impersonating Coca-Cola and Ferrari with fake job offers to steal your passwords. Job seekers are at high risk as these scams become more sophisticated. Protect your personal information by verifying job offers directly with companies.

What Happened

As job seekers face increasing competition, sophisticated phishing campaigns are on the rise. Scammers are impersonating major brands like Coca-Cola and Ferrari, creating fake job offers that lure victims into revealing their credentials. These scams exploit the desperation of job seekers in a challenging labor market.

The Coca-Cola Scam

The Coca-Cola scam begins with a link to a seemingly legitimate scheduling page for a recruiter named "Tricia Guyer." Victims are asked to provide personal details and then prompted to log in using their Google accounts. However, instead of a genuine Google login page, victims encounter a simulated browser window that captures their credentials. This attack is particularly dangerous because it can bypass two-factor authentication by dynamically serving prompts based on the attacker's backend responses.

The Ferrari Scam

Similarly, the Ferrari phishing campaign presents itself as an official career portal. Victims receive a pop-up claiming they've been invited to apply for a marketing role. Whether they choose to log in via Facebook or enter their email, they are redirected to a fake login page designed to harvest their credentials. This scam targets a broader audience, aiming to compromise Facebook accounts that can lead to further social engineering attacks.

Who's Being Targeted

Both scams primarily target job seekers, particularly in a labor market where layoffs have surged. With over 1.17 million layoffs in 2025, the scams exploit the heightened anxiety and urgency among individuals seeking employment. The FTC reported a significant rise in job and employment scams, with losses escalating from $90 million in 2020 to over $501 million in 2024.

Signs of Infection

Victims may notice unusual requests for personal information or unexpected scheduling links from unknown recruiters. The fake browser windows can be particularly deceptive, making it hard for individuals to identify the scam.

How to Protect Yourself

To safeguard against these scams, consider the following:

  • Be suspicious of unsolicited job offers, especially if you didn’t apply.
  • Verify the recruiter and position by checking the company’s official careers page.
  • Learn to spot fake browser windows:
    • Try dragging the pop-up; a real one moves freely, while a fake gets stuck.
    • Minimize your browser; a real pop-up remains visible, while a fake disappears.
    • Inspect the URL bar; if it looks incorrect, it’s likely a scam.

By staying vigilant and informed, you can protect yourself from falling victim to these increasingly sophisticated phishing schemes.

🔒 Pro insight: As job market pressures mount, expect a surge in phishing schemes targeting desperate job seekers, leveraging familiar brand names for credibility.

Original article from

MWMalwarebytes Labs
Read Full Article

Related Pings

HIGHFraud

Device Code Phishing - Attacks Surge 37 Times in 2026

Device code phishing attacks have skyrocketed this year, with a 37x increase. Users of IoT and streaming devices are particularly at risk. New phishing kits like EvilTokens are making these attacks easier for cybercriminals. Stay alert and protect your accounts.

BleepingComputer·
HIGHFraud

FCC Proposes $4.5 Million Fine for Voxbeam's Fraudulent Calls

The FCC is proposing a hefty fine against Voxbeam for allowing fraudulent calls to reach American consumers. This could lead to stricter regulations on voice service providers. Stay alert to protect your personal information from scams.

The Record·
HIGHFraud

Windows Extortion Plot - Engineer Pleads Guilty to Charges

A former engineer has pleaded guilty to locking Windows admins out of servers in an extortion scheme. This incident underscores the risks of insider threats. Rhyne's actions could lead to a 15-year prison sentence. Companies must strengthen their cybersecurity measures to prevent similar attacks.

BleepingComputer·
MEDIUMFraud

Business Email Compromise - The New Threat Landscape Explained

A recent fraud attempt shows how business email compromise is evolving. Small organizations are now prime targets for these scams. Awareness is key to staying safe.

Cisco Talos Intelligence·
HIGHFraud

Vacant Homes - Adversaries Exploit Mail for Fraud

Criminals are exploiting vacant homes to intercept mail and commit fraud. This method targets sensitive information, leading to identity theft. Stay vigilant and monitor your mail to protect yourself.

BleepingComputer·
HIGHFraud

Customer Authentication - Why Are They Sending Money to Scammers?

Fraud expert Lenny Gusel reveals how separating identity management from fraud detection increases risks. Customers can still be scammed even after authentication. Integrating these systems is crucial for security.

Help Net Security·