Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Background check for a new employer resulted in me getting an email to my personal account:

"Hi, I'm XYZ from XYZ background checks, I'm conducting your pre-employment check, and I just want to confirm that your full name is V, your DOB is W, your place of birth is X, your address is Y and your full SSN is Z...

... and that this is the correct email address for you. Please confirm."

Holy hell. Thankfully I reached out to the employer about this (and the background check company's attempt to reach out to my partner on Facebook for ... something? This wasn't a security check, just a regular employment background) and they were as horrified as me, apologized, and fired their background check provider.



Hah, my employer in Sweden recently started using one of these security training companies. They send you emails with some online courses you're supposed to do and then send occasionally phishing attempts etc. and when you fall for one they send you an email what you did wrong.

Out of interest I clicked on the link in one of their "phishing" emails and I was redirected to a link where they essentially told me "never click on links in emails, you never know where they lead to". One week later I get an email "please click on this link to complete the second part of your course". Obviously I never completed their course, they told me never to click on links.

What's even worse is that they don't even use their own domain for the courses, but some random looking domain.


I'm a software dev. When I get phising mails I often click the links to check out what the scam is. I open in a separate browser I don't usually use, so there isn't anything in it for the phising site to gobble up. And yeah I trust that the browser sandbox I good enough, that no one is going to waste a zero day exploit on me in order to break it - hackers also have economic constraints. If I was working on something super sensitive, then I should use a vm, but I'm not so I don't.

I also did this at work, and yeah it was a fake phising mail sent by a security company, and I had to do a quick 20 min online course on email security best practices. Yay. Me and like 3 other dudes, who clearly all also understood it was phising and were just curious about the scam.


When they introduced the weird fake phishing mails at my last work place I checked the email headers and just filed it into a separate folder. My coworkers were happy to get rid of the spam as well.

Just shows how bad they are at faking it.


Sounds like the sort of thing Hireright would do.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: