HR & Recruitment Risks

    Not Every Candidate Is a Candidate

    Suspicious CV attachments, candidate portfolio links and software-install requests target HR teams.

    Business & Leadership SecurityHR & recruitmentLeadership

    Illustrative scenario

    How It Looks in Real Life

    An applicant sends a CV as a password-protected archive and asks the recruiter to install a specific video app for the interview.

    Understand it

    How the Attack Works

    HR teams are expected to open attachments from strangers. Attackers use this to deliver malware through CVs, portfolio links or meeting software requests.

    Red flags

    Warning Signs

    • CVs in archives, password-protected files or unusual formats.
    • Portfolio links to file-sharing sites requiring sign-in.
    • Candidates insisting on unfamiliar meeting software.

    Safer habits

    What to Do Instead

    • 1Accept CVs through your applicant tracking system or in standard document formats.
    • 2Use your organisation’s approved meeting platform only.
    • 3Report suspicious applications to IT before opening attachments.

    Response playbook

    Already Interacted?

    For work accounts and devices, report promptly through your organisation’s IT or security process first. Never share passwords, codes or tokens in a report.

    If you: opened a message or clicked a link
    1. 1Close the page without entering anything further.
    2. 2Report the message through your usual IT or security reporting channel.
    3. 3Keep the original message; do not forward it to colleagues as a warning.
    If you: installed software or ran a command
    1. 1Disconnect the device from the network (Wi-Fi off or cable out) but leave it powered on.
    2. 2Report to IT or security and describe exactly what you ran or installed.
    3. 3Do not delete files, wipe the device or run cleanup tools yourself; evidence helps the investigation.
    4. 4From a different, trusted device, change passwords for accounts used on the affected machine.
    If you: entered credentials or shared a code
    1. 1Report it to IT or security immediately for a work account; speed matters more than embarrassment.
    2. 2Change the password from a trusted device by typing the real address yourself.
    3. 3Sign out of all sessions from the account security settings. A password change alone may not end active sessions.
    4. 4Review recovery email, phone number and forwarding rules for unexpected changes.

    Knowledge Check

    What Would You Do?

    A candidate sends “CV.zip” with a password in the email body. What do you do?

    Fictional example for learning. Not a test score or certification.

    Sources

    Content reviewed by WazuGuardix on 5 October 2026. Summaries are in our own words.

    All Awareness Guides

    Make Safe Habits Part of Your Culture

    Plain-language awareness sessions for everyday staff, developers and business teams.

    Email Us