Osato Umweni · Blog

Your business name is the easiest part of a scam to fake

A businesswoman sits at her desk on the phone, looking concerned while checking her laptop in a bright office

Someone calls your office to ask why the marketing assistant role you posted needs a forty pound "training kit" fee paid up front before the first day. You have never posted a marketing assistant role. Whoever wrote that listing used your company's real name, pulled your logo straight off your own website, and linked to something close enough to your real site that nobody scanning it on a phone during a lunch break would think twice. By the time the call reaches you, the deposit is gone, the listing has been taken down, and the person on the other end of the phone thinks your business stole from them.

Nobody broke into anything. Nobody guessed a password or found a hole in your website. The only thing the fraud needed was your name, which was sitting in public view the entire time.

What you actually want here

Not much, when you put it plainly. You want your business's name, on a job posting, an invoice, or a website, to mean your business and nothing else. You want the one person who calls asking about that fake listing to be the exception, not the start of a pattern. That is a smaller ask than it sounds, and most of what stands between you and it is a handful of settings that already exist and just were never turned on.

Why this is suddenly a line item in federal crime statistics

Here is the part that made this worth writing about now rather than at some point in the abstract. In its 2025 Internet Crime Report, the FBI's Internet Crime Complaint Center broke out AI-related fraud as its own category for the first time in the unit's 25-year history. It recorded 22,364 complaints referencing AI and $893 million in reported losses, out of just over a million complaints and $20.9 billion in total losses across all categories that year, up from $16.6 billion the year before (source: FBI, "Cryptocurrency and AI Scams Bilk Americans of Billions"; PYMNTS, 7 April 2026).

What actually earned the new category was not a single new type of crime. It was that the same old fraud categories, business email compromise, romance scams, investment scams, and employment scams, started showing a common ingredient underneath them: AI-generated content convincing enough that a person reading it on their phone, at speed, had no real chance of catching the tell. The FBI's own language on this is worth quoting directly, because it is unusually blunt for a federal report: "AI-enabled synthetic content is becoming increasingly difficult to detect and easier to make, which allows criminal actors to potentially conduct successful fraud schemes."

Employment scams sit in that list for a reason that matters here. They are the one category on the FBI's list that does not target your bank account at all. It targets your name.

A woman sits at a desk in a modern office, talking on the phone and taking notes

What an employment scam borrowing your name actually looks like

Take the scene at the top of this piece apart and there is nothing technically clever in it. A scammer needs three things: your logo, which is on your website for anyone to save; your company description, which is on your website or your LinkedIn page, ready to be rewritten in a different voice in seconds by any general-purpose AI tool; and a plausible-looking link, which can be a domain one character off your real one, registered for a few pounds an hour before the listing goes up.

Everything after that is just volume. The same listing goes up on three or four job boards at once, sometimes translated, sometimes lightly reworded so it does not trip duplicate-content filters. A fake "HR" inbox, often a free webmail address dressed up with your company name in the display field, handles replies. Applicants get an offer within a day or two, faster than any real hiring process, because speed is what makes people skip the questions they would otherwise ask. Somewhere in that exchange comes the ask: a training kit fee, a background check fee, sometimes just a request for a passport photo and a bank sort code for "payroll setup."

None of this needed your systems. It needed your name being easy to find and easy to copy convincingly, which describes almost every small business website ever built, including yours and mine.

Why this used to be harder and now is not

Five years ago this same scam existed, but it took longer to set up and it read badly enough that a careful applicant caught it. Spelling gave it away. Tone gave it away. A generic "Dear Applicant" instead of a name gave it away. AI writing tools removed all three tells in one step. A convincing job description, a matching offer letter, and a set of follow-up replies that sound like a real person handling a real inbox now take minutes to generate, not hours, and they no longer read like anything other than a normal exchange with a normal small company.

That is the actual shift behind the FBI's new numbers, and it is also the answer to a question worth asking directly: why would a scammer bother building a convincing fake around a small, mostly unknown business rather than a household name. The honest answer is that it is safer for them. A big brand has a legal team, a fraud team, and a public warning page the moment a scam using its name gets reported. A business with one website, one inbox, and no monitoring in place is a far quieter target, and there are millions of businesses that fit that description for every one that fits the first.

The part of this your domain actually controls

Here is where the job-posting scam and the domain settings this site usually writes about meet, and it is a more direct connection than it looks at first.

A scammer running an employment scam under your name almost always needs to send at least one email that looks like it came from you, whether that is the initial listing contact, the fake offer letter, or the payroll-details request that closes the scam out. The easiest way to make that email look real is not a lookalike domain at all. It is putting your exact real address in the From field, because email was never built to check whether the server sending a message was actually authorised to send on your behalf. Unless your domain has told the internet which servers can send as you, and told receiving mail systems what to do when a message fails that check, a fraudster can type your real address into the From field and a large share of inboxes will deliver it without complaint. That mechanism is exactly what we covered in how a fraudster sends an invoice that looks like it came from you, and it applies here in the opposite direction: instead of your invoice being forged, your job offer is.

Three DNS records close that gap. SPF lists which servers are allowed to send mail as your domain. DKIM signs outgoing mail so a receiving server can confirm it was not altered and genuinely came from a server you control. DMARC is the instruction that ties the two together and tells receiving mail systems what to actually do when a message fails both checks, which is the setting almost every small business skips even after adding the other two. Without DMARC set to quarantine or reject, a domain can pass every other check and still be fully spoofable, because a failed check with no DMARC policy behind it is only ever a suggestion, never an instruction. We went through why the most common in-between setting, p=none, does not actually protect you in what p=none really means and why it protects nobody, and it is worth a second look if you have never checked which policy your own domain is running.

None of that stops the lookalike-domain version of this scam, because a domain like yourcompany-careers.com is a separate registration with its own DNS, entirely outside anything you control. But it closes the version where the fraud arrives from your exact real address, which is the version that survives even after a job board takes the fake listing down, because it does not depend on the listing at all.

A person works across multiple monitors at a desk, reviewing security information

How common is the underlying gap

Wider than most business owners assume. Monitoring 1,276,088 domains worldwide in July 2026, the deliverability tracker DmarcDkim found that 68.7% had no effective DMARC protection in place (source: DmarcDkim, July 2026). That figure is not describing a niche of poorly run businesses. It describes more than two out of every three domains online, including plenty that already send invoices, job offers, and customer replies every day without ever checking whether anyone else could send those same messages just as convincingly.

If you want the fuller explanation of what SPF, DKIM and DMARC each actually do and how they fit together, we laid that out in plain terms in SPF, DKIM and DMARC explained without the jargon.

What actually helps, beyond the DNS fix

Fixing the DNS side removes the version of this scam that abuses your real domain directly, but it is worth pairing with a few habits that cost nothing and take an afternoon, not a project plan.

Put a line about your hiring process somewhere obvious on your own site, ideally on the same page any applicant would land on to verify a listing. Something as short as "we never ask candidates to pay any fee at any stage of hiring" gives a suspicious applicant something concrete to check against, and it costs you one sentence.

Search your own company name alongside words like "hiring," "careers" or "job offer" every so often, the same way you might vanity-search your own name. Fake listings using a real company usually surface within the first page of results once enough people have applied and started asking questions publicly.

Report anything you find directly to the platform hosting it. LinkedIn, Indeed and most major job boards have a specific fraud-reporting flow for exactly this, and listings using a real, identifiable company tend to come down faster than anonymous ones, because the platform has a real business it can verify against.

Keep your own site accurate and current. A scam listing works partly because it borrows credibility from a real website that looks maintained. A site with a working careers page, current contact details and no obvious neglect gives a suspicious applicant somewhere real to double-check against, in a way a stale or broken site cannot. We covered what tends to fail first on a site nobody maintains in what actually breaks on a website nobody maintains, which is worth a look if it has been a while since anyone touched yours.

Why did I not hear about this sooner

Because this version of fraud does not send you a bill. It sends someone else a bill, with your name attached, and you usually only find out when they call, angry, assuming you took their money. That is the uncomfortable difference between this and a straightforward invoice scam: with invoice fraud, you or your client notice the money is missing almost immediately. With an identity-borrowing scam, the first sign is reputational, arriving as a confused or furious message from a stranger, sometimes weeks after the listing has already been taken down and the money already gone.

Frequently asked questions

Can someone really use my exact business name and logo without hacking anything? Yes. A logo and a company description are public by design, sitting on your own website and social profiles so customers can find and trust you. Nothing about copying them requires access to your systems, only access to the internet.

Does setting up DMARC stop a fake job listing on LinkedIn or Indeed? No, not directly. DMARC governs email that claims to come from your domain, not content posted on a third-party platform. What it does stop is the version of the scam that moves into email using your exact real address, which is where most of these scams eventually need to go to look credible enough to close.

How would I even find out my business name is being used this way? Usually from the person it happened to, contacting you directly, or occasionally from a search of your own company name turning up a listing or a complaint you never posted. There is no dashboard that alerts you automatically, which is exactly why an occasional manual search is worth the ten minutes it takes.

Is this only a risk for big, well-known brands? No, and the opposite is closer to true. A large brand has legal and fraud teams watching for exactly this and a public channel to warn people quickly. A small business with one website and no monitoring is a quieter, safer target for the same scam, which is part of why the FBI's new AI fraud category spans businesses of every size, not just recognisable names.

What is the fastest first step? Check what your domain is actually publishing right now. A free domain health check shows your SPF, DKIM and DMARC status in a couple of minutes, and tells you plainly whether your domain could be used to send a message that looks like it came from you today.

Most of what makes this kind of fraud possible is not a gap you have to build something new to close. It is a setting that has been sitting unset since the day your domain was registered. Run the free check on your own domain, see exactly what it says about you right now, and fix the part that is actually within your control before someone else uses it on your behalf.

Check your own

Is your domain one of them?

The check is free, takes about thirty seconds, and shows the full result without asking for your email.

Run the free check

Back to all posts

Check domain WhatsApp Call