ArticleAug 05, 2026by Docurensic Team8 min read

The Job Offer That Wants Your Bank Details

A recruitment scam is a document operation. There is no job, so everything the victim receives is paper — and paper produced under time pressure by someone impersonating a company they have never worked for.

The Job Offer That Wants Your Bank Details
In this article
  1. Key takeaways
  2. Why the documents are weak
  3. The two asks
  4. The shape that gives it away first
  5. The checks, in order of how little they cost
  6. For employers: you are also the victim here
  7. If a document has already arrived
  8. Frequently asked questions

Most of what we write about here runs in one direction: a candidate or a supplier hands a company a document that is not what it claims to be. This one runs the other way. The victim is a person looking for work, the impersonated party is a real employer who has no idea it is happening, and the entire apparatus is documents — an offer letter, a contract, an onboarding pack, a direct-deposit form.

It works for a reason that has nothing to do with gullibility. Being offered a job is one of the few moments in adult life when a stranger sending you formal paperwork and asking for your bank details is completely normal.

Key takeaways

Why the documents are weak

The impersonator has never worked at the company they are impersonating. That is a bigger handicap than it sounds, because internal paperwork is full of conventions that outsiders cannot guess.

The letterhead is scraped, not sourced. A logo pulled off a website is the wrong resolution, the wrong colour profile, or the wrong version of a mark that changed two years ago. Real templates are built from vector assets by people with access to the brand kit.

The template is a word processor document. Real HR paperwork comes out of an HR system, and that system leaves consistent traces — the same producer string on every document the company issues, the same fonts, the same field structure. A one-off file assembled last night matches nothing.

The register is off. Real employment contracts are boring, specific and legally cautious. They name a legal entity precisely, cite the correct jurisdiction, and use the phrasing that company's lawyers settled on years ago. Scam contracts are enthusiastic. They oversell. They talk about the exciting opportunity in a document that should be discussing notice periods.

The details are internally inconsistent. A salary that does not divide into the stated pay periods. A start date before the offer date. A job title in the letter that differs from the one in the contract. A named signatory who does not hold that role, or who left in 2022. Each is small; together they are a document that nobody proofread because nobody expected it to be read twice.

The metadata is honest even when the content is not. Author fields, creation timestamps and producer strings survive far more editing than people expect, and they routinely name software and machines that have nothing to do with a corporate HR department. That is the same weakness we mapped in PDF metadata.

The two asks

Strip away the specifics and every version of this fraud reaches one of two requests.

Give us your banking and identity details. Framed as onboarding. A direct-deposit form, a tax form, a copy of your passport and a utility bill "for right-to-work checks". Sometimes that is the whole objective — the package is worth more to an identity-fraud operation than any single theft — and sometimes it funds a loan application in your name a month later. It is the raw material for synthetic identity fraud.

Money moves toward you, then onward. This is the money-mule variant and it is the dangerous one, because the victim can end up criminally liable. A cheque or transfer arrives to buy equipment, pay a supplier, or cover a training fee. You forward most of it and keep a portion. Days later the original payment reverses, the money you sent on is gone, and your account is part of a laundering chain. National reporting bodies have run public campaigns on this for years, because the recruits are so often students and first-jobbers (ic3.gov).

A smaller third variant is the advance fee — pay for a background check, a visa application, a certification, or "equipment" that never ships. Lower value, higher volume.

The shape that gives it away first

Before any document analysis, there is a structural tell that costs nothing to check: an offer that arrived without a process.

Legitimate hiring is slow and bureaucratic. There is an application, there is a screening call, there are humans on video, there are references, and there is a gap of weeks. A scam compresses all of it, because every day of theatre is a day the impersonated employer might notice.

Diagram: a real hiring process compared with a recruitment scam
Every step a scam skips is a day it might get noticed

So the shapes worth reacting to are:

None of those is a document problem. All of them are cheaper to spot than a forged letterhead.

The checks, in order of how little they cost

Find the role on the employer's own site. Not through the link in the email. Type the company's domain yourself and go to their careers page. If the role does not exist there, you are done. This single step ends the overwhelming majority of these.

Check the domain in the email address. Character by character, against the domain on the company's real website. Then check when it was registered — a recruiter domain created last month is not a recruiter domain.

Call the company's switchboard. The number from their website, not from the signature block. Ask whether the named recruiter works there. Impersonators do not usually control the real company's phone system.

Read the contract for the entity, not the enthusiasm. Does it name a real registered legal entity, with a company number you can look up in the national register? Does the jurisdiction match where the company actually operates? A real contract is precise about this because it has to be enforceable.

Refuse to be the first mover on money. No legitimate employer asks a candidate to pay for their own background check, buy equipment through a specified supplier, or process a payment on the company's behalf. Not one. There is no exception to find.

Verify identity before you send identity documents. Banking details and passport scans belong in an onboarding system after an offer has been confirmed through a channel you established yourself — not in an email thread with someone whose employment you have not confirmed.

For employers: you are also the victim here

If your brand is being used, you find out late and from the outside — usually when a stranger calls to ask why their first paycheck has not arrived.

A few things reduce the damage:

Publish a canonical list of open roles and a note about your process. "We never ask candidates for payment, and all offers come from @ourdomain" on the careers page gives every suspicious recipient a two-minute check that resolves it.

Register the obvious lookalikes of your domain. It is not exhaustive, but the closest few variants are cheap friction.

Give people somewhere to report it. A monitored address on the careers page turns scattered incidents into a pattern you can act on, and often gets you the offer letter itself — which is evidence, and which tells you what the impersonator does and does not know about you.

Watch your own inbound paperwork with the same suspicion. The reverse direction is alive and well: candidates who fabricate the documents you asked for. We covered that side in seven documents job candidates fake, and the tells are the mirror image of these.

If a document has already arrived

Before you fill anything in, look at the file rather than the words. An offer letter or contract that came from an HR system leaves a very different trace from one assembled in a word processor by someone in a hurry: different producer software, different font handling, often a revision history that does not match a document supposedly generated once and sent.

Our free PDF X-Ray reads that structure without an account and without keeping the file. It is not a verdict on whether the job is real — the careers page answers that faster — but when a document has been assembled and re-saved several times before reaching you, that is worth knowing before you type your account number into it.

Frequently asked questions

How can I tell if a job offer is fake?

Start with the process, not the paperwork. If you did not apply, if there was no video interview, if the whole thing has moved in a day, or if the role does not appear on the employer's own careers page, treat it as fake regardless of how good the documents look.

Will a real employer ever ask me to pay for something?

No. Not for background checks, not for equipment, not for training, not for visa processing. Any request for money from a candidate is the fraud, not an unusual policy.

What if I already sent my bank details?

Contact your bank immediately and tell them the details may be compromised, then report it to your national fraud reporting body. If money has passed through your account, say so — being upfront about a mule situation you were tricked into is very different from being found later.

Why do the documents look so convincing?

Because logos are public and templates are easy. What is hard to copy is the internal convention — the exact legal entity name, the signatory who actually holds that title, the phrasing a company's lawyers settled on. That is where these documents come apart.

Put it to the test

Scan a document and get a plain-English verdict in seconds. Free to start.

Start scanning free

Keep reading