Truviss

GitLab’s Fake Recruiters Are Everyone’s Problem

Home/Blog/GitLab’s Fake Recruiters Are Everyone’s Problem
Social Media

GitLab’s Fake Recruiters Are Everyone’s Problem

Watch for fake recruiter profiles, not just fake storefronts

Truviss’s Social Media Monitor flags accounts and content trading on your brand’s identity, including impersonated hiring processes.

Book a demo
Fake recruiter brand impersonation cover
TL;DR
  • GitLab warned on 10 December 2025 about fake recruiter profiles, fake domains and fake hiring processes impersonating its own HR team.
  • This is structurally the same brand-impersonation pattern as the L’Oréal domain case, just running through LinkedIn and job boards instead of registered domains.
  • Reported tactics include real-time deepfake video interviews and malware disguised as onboarding software.
  • Fake recruiter profiles don’t reliably show up in marketplace, domain, or generic social-media impersonation monitoring — it needs its own watch.

On 10 December 2025, GitLab published a warning about a wave of fake job scams impersonating its own recruiters. Scammers were using the company’s name, logo and real team member identities, building fake recruiter profiles on LinkedIn and Teams posing as GitLab HR staff, registering lookalike domains including gitlab.careers and careers-gitlab.com, and referencing fake credentials like a “CPD USA Certification” to appear legitimate. This is a real, named, first-party disclosure from a company with genuine security resources, not a hypothetical warning written for a blog post.

Why this is the same problem, on a different channel

This is the identical underlying pattern behind L’Oréal’s 705-domain case, a brand’s name and identity borrowed to extract something valuable from someone who trusts it, just running through a different channel. There it was lookalike domains harvesting job applicants’ personal data. Here it’s fake recruiter profiles and job listings extracting money, credentials or, in some documented cases, malware installation, through an entire fabricated hiring process. Both are brand impersonation in the fullest sense, not just a copied logo but a copied identity, a real team member’s name attached to a fake conversation. The difference is where it lives, registered domains in one case, LinkedIn profiles and job boards in the other, and that difference is exactly why a brand watching only for lookalike domains would miss this pattern entirely.

How convincing this has gotten

This isn’t crude anymore. Reported 2026 tactics include scammers using real-time face-swap filters during video interviews to convincingly impersonate real company executives on camera, live, not just in a written message. In some documented cases, candidates who accept a fake offer are directed to install a “work-from-home security suite,” which is actually a remote-access trojan handing the scammer control over the victim’s own device. GitLab’s own published red flags are worth citing directly because they’re concrete and checkable: email addresses that aren’t on the company’s real domain, requests for payment for equipment or certifications, communication that stays in chat with no verified calendar invite, and job listings that don’t actually appear on the company’s own official careers page.

See how Truviss watches for impersonated hiring processes, not just fake storefronts and listings.

Explore Social Media Monitor

The scale context, honestly framed

The FTC’s April 2026 report found Americans lost $2.1 billion to social media scams in 2025, an eightfold increase, with roughly 30% of all scam-loss reports starting on social media. That figure covers social media scams broadly, shopping scams were the single most-reported category, not job scams specifically, but it’s still useful context for how large the delivery channel has become. A brand’s careers page and hiring process are increasingly competing for attention with a convincing fake version running on the exact platforms candidates already trust.

Why this needs its own monitoring surface

Fake recruiter profiles and fake job listings don’t reliably show up in marketplace monitoring, and they often don’t show up in domain monitoring either, some of these scams run entirely through legitimate job boards and LinkedIn’s own profile system without registering a single lookalike domain at all. They also don’t fit neatly into generic social-media impersonation monitoring built around fake product-selling accounts, since the target here is a hiring process, not a storefront. This is a specific, identifiable pattern, a real brand name combined with real team-member identities layered onto a fake hiring conversation, and it needs to be watched as its own thing rather than assumed to be covered by whichever monitoring already exists for other channels.

Getting started

The most direct defence is the same instinct GitLab itself acted on: publish and keep visible a single, canonical, up-to-date list of real open roles and the only legitimate domains and contact methods a candidate should ever expect to hear from. From there, monitoring for recruiter profiles and job listings using the brand’s name outside that canonical set is what catches the pattern early, before a candidate gets far enough into a fake process to hand over money, credentials, or control of their own device, and it complements the same continuous, evidence-first approach behind any well-built takedown request.