A polished LinkedIn message offers remote work, a signing bonus, or “equipment reimbursement.” Then the “recruiter” asks you to pay a background-check fee, buy Apple/Google Play/Steam gift cards, wire money for software licenses, or install AnyDesk, TeamViewer, or similar remote-access tools so “IT can set up your laptop.” Real employers at Google, Amazon, JPMorgan Chase, or a local hospital system do not hire that way.
This is the LinkedIn-flavored cousin of fake job offer deposit scams and fake job background-check fee scams. Broader money and identity traps: Credit and debt scams.
How the LinkedIn job script usually runs
| Step | What they say | What actually happens |
|---|---|---|
| 1 | InMail or connection: “We saw your profile—urgent remote role” | Spoofed company name, freemail HR address, or a look-alike domain |
| 2 | “You’re hired—complete onboarding today” | No real career-page posting, no switchboard call, no video with known staff |
| 3 | Pay for “badge / drug screen / software” via gift card, crypto, Zelle, or wire | Irreversible payment to the scammer (Gift cards and prepaid risks) |
| 4 | Or: “Install remote support so we can configure payroll” | They control your PC, drain bank/brokerage sessions, or plant malware |
| 5 | Follow-on: deposit-then-wire-back “stipend” check | Same bounce trap as job and check-cashing scams |
Legitimate LinkedIn recruiting still ends on a company career site, a real calendar invite, and payroll through ADP, Workday, or the employer’s own systems—not your Venmo.
Hard red flags
- Any request for gift-card PINs, crypto, wires, or P2P to “unlock” hiring, taxes, or equipment.
- Pressure to install remote-access software before day one with a company-owned device.
- Freemail “HR” (
company.hr247@gmail.com) while claiming to represent a Fortune 500 brand. - Job offers that skip every public posting and jump straight to payment or software install.
- “Recruiter” profiles created last week with stock photos and no mutual connections inside the real firm.
Phishing that steals LinkedIn or email logins can sit beside these pitches: Phishing and account takeover.
Worked example: the $890 “equipment kit” InMail
Sam gets a LinkedIn InMail from “Taylor Chen, Talent Partner – Microsoft.” The role is remote customer success at $95,000. Taylor says Sam is pre-approved and must buy an $890 Best Buy gift card for a “secure laptop image kit,” then read the PINs on a Zoom call so IT can “provision” overnight.
Sam almost buys the cards at CVS. Instead Sam opens Microsoft’s real careers site (typed, not from the InMail), finds no matching req, and calls the general Microsoft recruiting number published on that site. The real desk confirms no such InMail. Sam reports the profile and message through LinkedIn’s official Help flow and files at ReportFraud.ftc.gov. No cards purchased, no remote tool installed, no loss.
If Sam had paid, the PINs would be gone in minutes. A second ask for “tax clearance via Bitcoin” would have followed—the same irreversible extract pattern as other advance-fee job cons.
How to verify a LinkedIn offer
- Open the company’s official careers page yourself; search the req ID or title.
- Call the main switchboard or recruiting number from the company’s site—not a number in the InMail.
- Confirm the recruiter’s email domain matches the company (and that it is not a look-alike like
microsft-careers.com). - Refuse any payment or remote-access install as a hiring condition.
- If a check or “stipend deposit” appears, treat it as a deposit-then-wire scam until the bank confirms finality in writing.
If you already paid or installed remote software
- Stop all further payments and disconnect the remote session; uninstall the tool; consider a clean OS reinstall if the device held banking passwords.
- Change passwords from a different clean device; enable stronger MFA on email, LinkedIn, bank, and brokerage.
- Call your bank/credit union and card issuers (Chase, Bank of America, Capital One, Ally, local credit union) using numbers on the card or statement.
- Freeze credit if you shared SSN or ID images (Credit freezes and fraud alerts).
- Document chats, LinkedIn profile URLs, and receipts; report to FTC, LinkedIn, and local police if the loss is material.
Checklist
- No real employer needs gift cards, crypto, or your remote-desktop password to hire you.
- Verify roles on the company’s own careers site and switchboard.
- Treat brand-new recruiter profiles and freemail HR as hostile until proven otherwise.
- Never install AnyDesk/TeamViewer/etc. because a LinkedIn stranger demanded it.
- Report attempts even when you catch them early; patterns help others.
- Pair LinkedIn caution with the same skepticism you use for deposit and background-fee job scripts.
Educational only. Not legal, employment, or fraud-recovery advice. Scam tactics change; verify employers through official company channels and report fraud to FTC and the platform.