Job fraud works because it targets people at their least sceptical. A candidate four months into a search, watching their savings fall, is sent an offer letter with a real company's logo on it and asked for ₹2,500 as a refundable registration fee. The amount is small enough to seem reasonable and the moment is the worst possible one to be careful.
The reassuring part is that these scams are not sophisticated. There are perhaps six scripts in circulation and they all leave the same marks. Learn them once.
The one rule that eliminates most of it
A legitimate employer never asks you for money.
Not a registration fee. Not a security deposit. Not a training or certification charge, a laptop deposit, a courier fee for your welcome kit, a background verification fee, a “processing” charge, or anything described as refundable. Not payment to a consultant who “guarantees” placement in a named company.
Real recruitment costs the employer money and they pay it. If anyone in the process asks you to pay, transfer, deposit or buy something, the process is fraudulent. There is no exception worth entertaining, and the word “refundable” is a feature of the script, not a protection.
Red flags in the posting itself
- Pay far above the market for the work described. “Data entry, work from home, no experience, ₹35,000/month” describes a job that does not exist. Data entry is among the most commoditised work there is.
- No named company, or only “a leading MNC” / “our reputed client.” Some genuine consultants withhold the client name early on, so this alone is not proof — but combined with anything else here, treat it as decisive.
- Vague responsibilities and no real requirements. A genuine JD is specific because a real manager wrote it about real work.
- Unlimited openings, permanent urgency. “Hiring 500 candidates, immediate joining” is a funnel, not a role.
- A free email domain for a corporate role. An “HR Manager” at a large company writing from a Gmail, Outlook or Yahoo address is a serious flag. So is a near-miss domain: @tcs-careers.com, @infosys-hr.net, or a name with a letter swapped that you will not notice unless you look for it.
- Language errors throughout. Not the odd typo, but consistently broken phrasing in what claims to be corporate communication.
Red flags in the process
- An offer with no real interview. Selection after a five-minute chat, or purely over text, does not happen for salaried work.
- The entire process on WhatsApp or Telegram. Recruiters do use WhatsApp for scheduling. They do not conduct hiring in it, and Telegram in particular is used because the accounts are disposable.
- An offer letter within hours. Real approvals take days. Instant offer letters are template documents with your name pasted in, and the accompanying urgency exists to stop you checking.
- Interviews at odd hours from personal numbers, with no calendar invite, no company video platform, no email trail.
- Pressure and deadlines. “This slot closes in two hours.” Manufactured scarcity is the core mechanism of the whole category.
- Sensitive documents requested too early. Aadhaar, PAN, bank account details, a cancelled cheque, your date of birth — all legitimately needed after you accept a written offer, for payroll and PF. Never during screening. Your Aadhaar and PAN together are enough to attempt loans and accounts in your name.
- Anyone asking for an OTP. No employer needs one, for anything, ever. An OTP request is always an attack in progress.
- Being asked to install remote-access software — screen sharing tools you have not heard of, or an APK sent over chat — to “complete verification” or receive your salary.
The specific scripts to know
Recruiter impersonation
The most convincing variant, because the company is real. Someone registers a lookalike domain, copies a genuine JD, and runs an entire process using a real firm's name and branding. The fee request arrives at the offer stage, when your guard is lowest.
The defence is simple and absolute: go to the company's own careers page and confirm the role exists there, then contact the company through a number or address you found yourself. Never through the contact details in the message.
Task and commission scams
Marketed as “online part-time work,” “digital marketing” or “app reviews.” You complete simple tasks, earn ₹150, and get paid — which is the hook, because now it seems real. Then the tasks require you to prepay to unlock a higher tier, or to fund a “merchant order” you will be reimbursed for with commission. Early withdrawals succeed; the large one never does.
Any arrangement where you send money in order to earn money is not employment, whatever it is called.
The placement consultancy that charges candidates
Charges ₹5,000 to ₹25,000 for “registration” and a promised number of interviews. Some are outright fraud; others technically deliver worthless interviews and are therefore hard to pursue. Genuine recruitment consultants are paid by the employer, as a percentage of the placed candidate's salary. That is the entire business model.
Data harvesting
Some fake postings do not want your money at all — they want a verified resume with a working phone number, which sells. If you applied to something that then went silent and you began receiving loan and insurance calls, you have probably found the reason. Keep your full postal address off your resume, and treat any “application form” asking for Aadhaar number, salary slips or family details before an interview as a collection exercise.
Ten minutes of verification
Before you invest any further effort in a suspicious posting:
- Search the company name with “fraud,” “scam” and “review.” Trivial, and it resolves a surprising share of cases immediately.
- Check the company exists on the MCA register. The Ministry of Corporate Affairs runs a free master-data lookup at mca.gov.in. You can confirm the CIN, incorporation date, registered address and directors. A company claiming twenty years of operation and incorporated eight months ago has answered your question.
- Look at the website properly. Is there a registered address, a landline, a GSTIN in the footer? Are the team photographs reverse-image-searchable to a stock library? Was the domain registered three weeks ago?
- Cross-check the role on the careers page — the company's own, reached by typing the domain yourself.
- Check the recruiter on LinkedIn. An account created last month, with few connections and no history at the company, is not a recruiter. Also sanity-check the company page: a firm claiming 5,000 employees with eleven on LinkedIn is not real.
- Call the company's published switchboard and ask whether the person and the role exist. Two minutes, and it defeats impersonation entirely.
- Read the email headers if you can. Reply-to addresses on a different domain from the sender are a common tell.
If you have already paid
Act the same day — recovery odds fall sharply with time, and this is worth doing even for small amounts, because the reports are what build cases.
- Call 1930, the national cybercrime financial fraud helpline. Reporting within the first hours materially improves the chance that the receiving account can be frozen.
- File a complaint at cybercrime.gov.in, the Government of India portal. Keep the acknowledgement number.
- Notify your bank in writing and ask them to raise a dispute. If you paid by card there may be a chargeback route; UPI and IMPS transfers are harder but the beneficiary account can still be flagged.
- Preserve everything — screenshots of the chat, the posting, the offer letter, transaction references, phone numbers, UPI IDs. Do not delete the conversation, however much you want to.
- If you shared Aadhaar or PAN, check your credit report for enquiries you did not make, and keep checking for a few months.
- Tell the real company whose name was used. They generally have a fraud reporting address and an active interest in shutting the lookalike domain down.
And do not carry it as a personal failure. These scripts are built by people who run them thousands of times and refine what works. Being deceived by a professional deception says very little about you.
What we do at our end
Every listing on this site is reviewed by a person before it is published, and we remove roles that go quiet or turn out to be misrepresented. We will never ask you to pay to apply, and no employer listed here is permitted to.
That review is not infallible. If a listing you found through us asks you for money, requests documents before an offer, or does not match the company it claims to be from, please tell us — with the listing link and a screenshot if you have one. We investigate the same week, and one report usually protects a lot of people who would have applied after you.