How to compromise your system with a job interview
The current situation on the IT job market is hard. So you are lucky when a recruiter on LinkedIn reaches out to you having a suitable match for a new position based on your prior experience. It might not be what it seems at a first glance.
“A relevant opportunity” with part-time remote work and a great hourly compensation is what surely pulls a lot of current Software Engineers into the conversation when a new job offer on LinkedIn comes in - so it happened to a friend of mine. The job offer was matching very well with the former experience and paired with speeding up the interview process with a quickly sent coding challenge after a couple of messages on LinkedIn.
Info The initial contact was made in the name of a company that did not know about this. So it is pure phishing just to steal your secrets and credentials. The company is well aware of that and already published a post on LinkedIn explaining the situation.
Before you start with the test, you might be suspicious about the following:
The person contacting you is not part of the company on LinkedIn
There is no first “Get to know you”-call before you receive the coding test
The test might be in a different programming language than you’re skilled in
The code is available on Bitbucket, which IMHO is uncommon
The sender email address is a @gmail.com instead of an official one from the company
... continue reading