The career

Spotting fake jobs and scams

Job scams are not random. They come in a handful of shapes that repeat, and every one of them can be spotted before you lose money, time or your identity. This course teaches those shapes, the tells they share, the five-minute check that catches most of them, and exactly what to do in the hour after you realize you were caught.

8
lessons
~45
minutes
12
exam questions

Free · No paid tier · No certificate fee

After this course

Everything, and what is in it.

How job scams actually work

~5 min

A market built on need

Scams follow money and need. Remote work attracts both: thousands of capable people applying for positions they cannot verify, from a distance, often while a household depends on the result. That combination is what scammers hunt, and it is why the volume of fake postings is high in every remote market on earth. None of this means the market is rotten. Real clients and real jobs are the majority. It means you need a filter, and the filter has to be a habit rather than a mood, because the day you most need money is the day your judgement is worst. We are going to give you that filter: a small number of shapes to recognize, and a check you can run in five minutes before you hand over anything at all.

They want money or identity

Almost every job scam is after one of two things, and knowing which one tells you what happens next. The first is your money: a fee, a deposit, a payment you make and never see again. The second is your identity: your documents, your bank details, your logins, or the use of your name and your account to move someone else's money. A few want a third thing, which is free labor dressed as a test. Everything in this course is a variation on those three. When a new offer feels strange but you cannot say why, ask the question directly: if this is a scam, what exactly would they be taking? The answer usually appears in seconds, and it points straight at the step you should refuse.

Professional appearance proves nothing

A logo, a signature block, a careers page, a contract in a PDF, an interview over chat, a colleague who confirms the company is real: all of that costs a scammer almost nothing. Websites are cheap. Registration numbers are public and can be copied. Real brands are impersonated daily precisely because their reputation does the persuading. So drop appearance as evidence. What counts is what you can verify independently, and what counts is behavior: which direction money moves, whether the person will appear on video, whether the terms exist anywhere outside a chat window. A polished operation that asks you to pay a fee is a scam. A plain email from a small business that pays you first is a job.

Being scammed is not stupidity

People who get scammed are not careless or naive. They are usually busy, hopeful, and under time pressure, which is exactly the state the script is designed to produce. Professionals with twenty years of experience lose money to these schemes. Teachers, nurses, accountants, engineers. We say this now because shame is the scammer's best protection: victims who feel foolish stay quiet, do not report, and the same operation runs again next week on someone else. If it has already happened to you, the last lesson of this course is about what to do, and none of it involves blaming yourself. Treat this material as a professional skill, like checking a spreadsheet before delivery, not as a character test you might fail.

Remember

  • Every job scam wants one of three things: your money, your identity, or free labor.
  • Appearance is cheap. Judge behavior: money direction, video, and terms in writing.
  • Ask directly: if this were a scam, what would they be taking?
  • Victims are not naive. Shame keeps scams alive by keeping people quiet.

Money moving the wrong way

~6 min

The one rule that never bends

Here is the rule that catches more scams than any other: in real employment, money flows toward you. An employer pays you. You do not pay an employer for the chance to work for them, and you do not pay to be considered, trained, activated, verified, insured or placed. If money is being asked of you at any point before, during or after hiring, stop and treat everything else as unproven, no matter how convincing the rest looks. This holds across countries, industries and job levels. It holds when the fee is small. It holds when the fee is called refundable. Scammers know the rule too, which is why they spend their effort making the payment sound like something other than a payment. Learn the disguises and the rule does the rest.

Fees dressed as something else

The names change; the shape does not. An application or processing fee. A training or certification fee before you may start. A background check you must pay for. A placement fee taken from you rather than from the employer. A refundable deposit to activate your account. A small charge to receive your first payment. All of them move money from you to a stranger who has not yet paid you anything, and all of them are the scam. Two honest cases exist and look different. You may choose to buy a course or a certificate for yourself, from a provider you picked, with no job attached. And a real employer may reimburse a cost you already had. Neither involves paying a person who is dangling a job in front of you.

Equipment and software deposits

A common version: you are hired, the company will ship you a laptop and headset, and you need to pay a deposit or buy the equipment from their approved supplier. Sometimes they send a cheque to cover it, which you deposit and use to pay the supplier. The supplier is them. The cheque bounces a week later and the money is gone from your account. Real employers either ship equipment at their own cost, let you use what you already own, or state an allowance that arrives with your pay. Nobody legitimate needs you to route money through a supplier they chose. If a role requires software, it is either free, provided by the company, or something you already own and mentioned in your application.

What this means for AfterDesk

We will never ask you for money. Not to join, not to be vetted, not to take an Academy course, not to sit an exam, not to receive a certificate, and not to claim a task. There is no equipment to buy from us and no deposit of any kind. Every task in the pool shows a fixed payout before you claim it, and that money moves in one direction only, from us to you after quality control approves your delivery. If anyone ever contacts you claiming to represent us and asks for a payment, a deposit or a fee, it is not us. Say no and tell us. The same test we are teaching you applies to us, and we intend to pass it every time.

Remember

  • In real employment money flows toward you. Any fee before pay is the scam.
  • Training fees, deposits, activation charges and placement fees are one shape renamed.
  • Nobody legitimate needs you to buy equipment from a supplier they chose.
  • AfterDesk never asks you for money, at any stage, for any reason.

Cheques, refunds and money muling

~6 min

The overpayment and refund script

You are hired, and your first payment arrives larger than agreed. The employer apologizes for the error and asks you to return the difference, quickly, to a named account or wallet. Or you are asked to receive money meant for a supplier and pass it on, keeping a share. In both versions the original payment is fake, stolen or reversible, and the money you send back is real and yours. When it unwinds, your bank takes the fake payment back out of your account and the money you forwarded is gone. The rule is simple and absolute: you never send money back to an employer, and you never move money on their behalf. If a payment arrives that you did not expect, do not touch it. Report it to your bank and wait.

Available is not the same as cleared

Bank apps and e-wallets often show funds as available before the payment has truly settled. With cheques this gap can be days, sometimes weeks. Scammers build their timing around it: they want you to see the balance, believe it is yours, and send the refund before the underlying payment fails. When it fails, the reversal falls on you, because you are the account holder who spent it. Treat any incoming payment from a new party as provisional. If you must act on one, ask your bank directly whether the funds have cleared and finally settled, and take the answer from the bank rather than from the person asking you to hurry. This is not financial advice. It is a description of how settlement works and why the delay is the weapon.

Processing payments is a crime

Some offers are open about the work: receive payments into your personal account, withdraw or forward them, keep a percentage. It may be called payment processing, financial agent, local representative or transfer coordinator. This is money muling, and it is the laundering of money stolen from other people. Say this part plainly to yourself, because it is the part victims learn too late. When it is investigated, the account holder is the person the evidence points to. You are the one whose name is on the transfers. People are prosecuted for this, have accounts frozen, are refused by banks for years, and can face charges even when they believed they had a job. There is no version of this arrangement that is legal for you. Refuse it, keep the messages, report it.

Parcels, gift cards and top-ups

The same laundering logic appears without a bank account. Reshipping schemes ask you to receive parcels at home, repack them and forward them abroad; the goods were bought with stolen cards and you are the link in the chain that can be found. Gift card errands ask you to buy cards for a client or a boss and send the codes; the codes are cash and cannot be recovered. Mobile top-up and crypto transfer requests work the same way, chosen because the transfer cannot be reversed once it is made. A legitimate job may ask you to spend company money through company systems with real receipts. It does not ask you, in week one, to buy value with your own funds and send the codes to a stranger.

Remember

  • You never refund an employer and never move money on their behalf.
  • Funds shown as available are not settled. The reversal lands on you.
  • Processing payments through your account is laundering, and the account holder gets charged.
  • Gift cards, top-ups and crypto are chosen because they cannot be reversed.

Test tasks and free work

~5 min

When a test is production

Unpaid test tasks are the quietest scam because you lose only time, and only once, so few people report it. The shape is recognizable. The test is large: several hours, hundreds of rows, a full article, a whole deck. It uses real live client material rather than a sample. It has a deadline tied to someone's actual business, not to your convenience. Different candidates receive different sections, which together happen to make a finished job. And the feedback never comes, or comes as a polite decline after your work is used. Add it up: twelve candidates doing three hours each is thirty-six hours of production work for nothing, and the position may not exist. The tell is not the word unpaid. The tell is whether the output is usable by them tomorrow.

What a real test looks like

Genuine skills tests exist and are reasonable. They are small, usually well under an hour. They are the same for every candidate, which is what lets the client compare answers. They use a sample, dummy data or an old anonymized file rather than live client records. The scope and the time expected are stated up front. You get an answer either way, often with a comment on what was strong or weak. Some employers pay for tests as a matter of policy, and that is a good sign rather than a requirement. If a test meets those conditions, doing it is a fair trade: you spend forty minutes, they get evidence you can do the work, and you get evidence the process is real. Refusing every test on principle will cost you good jobs.

How to ask without losing the job

You are allowed to ask questions, and asking them is itself a filter, because real employers answer and scammers get annoyed. Useful wording: how long should this take, and is there a scope limit. Is this sample data or live client work. Will all candidates do the same test. When will I hear back. If it runs longer than an hour, is there a fee for the test. Send it as one short, friendly message rather than a list of demands. A real hiring manager reads that as a professional protecting their time. If the reply is pressure, vagueness or a suggestion that you are not serious, you have your answer, and it arrived before you spent the afternoon.

How AfterDesk does this

We do not use unpaid test tasks. Entry runs through vetting and this Academy, and the exams you sit here are ours, not a client's work in disguise. Once you are approved, every task in the pool carries a fixed payout printed before you claim, including the first one you ever do. There is no trial period at a lower rate and no sample task you complete for free to prove yourself. If you ever see something on our platform that looks like unpaid production work, that is a bug or an impersonation, and we want to hear about it. We built it this way on purpose, because free trial work is one of the mechanisms that made remote work feel cheap, and we are not interested in reproducing it.

Remember

  • The tell is not the word unpaid. It is whether they can use your output.
  • A real test is short, identical for all candidates, and uses sample data.
  • Asking about scope and timing filters employers. Real ones answer, scammers push back.
  • AfterDesk has no unpaid tests. Every task shows a fixed payout first.

Your documents and your logins

~6 min

What your identity is worth

A clear photograph of your government ID, plus a selfie holding it, plus your date of birth and address, is enough for someone to open accounts, take loans, register wallets and register companies in your name. That package sells, and it keeps working for years. Which is why so much fake hiring never asks for a peso: the documents are the payday. Damage from stolen identity is slow and hard to reverse. You may only discover it when a lender contacts you about a debt you never took, or when an account you need is refused. So treat your documents like cash and your logins like keys. The question is not whether the request seems normal, but whether the person asking has been verified and needs it yet.

Fake onboarding is the favorite

The most efficient version of this scam is a hiring process that looks complete. You get an offer letter, a welcome message, and a link to an onboarding portal where you upload your ID, your bank details and a signed contract, and create a password. The portal is theirs. The password you chose is very likely one you use elsewhere. The bank details go straight into fraud. Everything felt legitimate because there was paperwork, and paperwork is the cheapest thing to fake. The counter is boring and it works: never reach a company's systems through a link someone sent you. Find the company yourself, from a search or an address you already knew, and log in there. If the portal exists only at the end of their link, it exists only for you.

When sharing documents is normal

Legitimate employers do need identity documents eventually, so the answer is not to refuse forever. It is sequence and channel. Sequence: documents come after a genuine offer from an employer you have verified independently, not during a first chat. Channel: through the company's own system, or an official address at their own domain, never a personal mail account and never a messaging app. Practical habits help. Send the minimum asked for, not your whole folder. Where the receiving system allows it, use a copy marked with the purpose and the date across the image, so it cannot be reused elsewhere. Never send a full ID, a selfie holding it, and your bank details together to a party you have not verified. That bundle is the complete kit.

Passwords and one-time codes

One rule has no exceptions: you never give anyone a one-time code. Not to an HR representative, not to verify your account, not to a support agent, not to someone who says they sent it by mistake. Those codes exist to prove it is you, so anyone asking for one is trying to be you. Alongside that, use a different password for every important account, starting with the email address your other accounts recover through, and turn on two-step verification there first. A free password manager will handle the rest, and your browser's built-in one is far better than reusing a password. If you do nothing else after this lesson, protect the email account, because whoever controls it can reset everything else you own.

Remember

  • A full ID, a selfie holding it, and bank details are a complete identity kit.
  • Never reach a company's systems through a link that was sent to you.
  • Documents come after a verified offer, through company systems, never a personal account.
  • Never share a one-time code with anyone, for any stated reason.
  • Protect your main email first. It resets everything else you own.

Unsolicited offers and fake brands

~5 min

The message that arrives unasked

A large share of scams begins with a message you did not invite: a chat request, an SMS, a direct message, an email saying your CV was found and a role is reserved for you. The pay is above the market, the requirements are vague, and the next step is always to move the conversation to a private chat app. Some of these end in a fee, some in identity theft, and some in the task-and-commission apps where you complete small paid jobs, watch a small balance grow, and are then asked to deposit your own money to unlock the next level. That deposit is the whole business. Unsolicited does not automatically mean fake, but it does mean unproven, and the burden of proof sits with them.

Read the address, not the name

The display name on an email or a chat account is decorative; anyone can type anything there. What matters is the actual address and domain. A corporate recruiting role that writes from a free mail account is a strong signal, because real companies use their own domain. Then read the domain itself, character by character, looking for the near miss: an extra letter, a hyphen that does not belong, a different ending where the real company uses a plain one, or a familiar name sitting in front of an unrelated domain. Do the same with any link before clicking, because the visible text can say anything while the destination says something else. This takes fifteen seconds and defeats a large share of impersonation.

Verify from the other direction

Never verify a company using the materials the company sent you. Their site, their number, their reference letter and their staff list are all part of the package. Go the other way instead. Search for the company yourself and open its site from the results. Find the careers page and see whether the role is posted there. Look up the recruiter's name on the professional network and check whether the profile is old, connected and consistent, or created last month with a stock photograph. Where a business register is public, look for the company in it. If the role exists on the company's own site, apply through that page rather than through the message you received. If it exists nowhere except in your inbox, you have your answer.

Real recruiters exist

None of this means an unexpected approach is always a fraud. Recruiters really do search professional networks and message people who never applied. The difference is what happens when you slow the conversation down. A real recruiter will name the client or explain why they cannot yet, will appear on a video call, will send the details in an email from a company domain, and will not mind that you took two days to verify them. A scammer needs the pace they set. They will push, hint that the role is going to someone else, or refuse video with a reason that changes each time. Slowing down costs you nothing with a genuine employer. It costs a scammer everything, which is why they resist it.

Remember

  • Unsolicited is not proof of fraud, but the burden of proof is theirs.
  • Display names are decorative. Read the real address, domain and link destination.
  • Verify a company using sources it did not give you.
  • Real recruiters tolerate you slowing down. Scammers cannot afford it.

The tells and the five-minute check

~6 min

Six tells that travel together

Individually a tell can have an innocent explanation. Together they are a diagnosis. One: money is being asked of you, in any form and under any name. Two: urgency, a deadline to accept, a slot that expires today. Three: refusal to appear on video, or a voice-only call with an excuse that changes. Four: a personal or free mail domain for a corporate role, or a lookalike domain. Five: the terms live only in chat, and nothing is confirmed in a document or an email you can keep. Six: the pay is well above the market for work described so vaguely that you could not start it tomorrow. Two of these on the same offer is enough to stop and verify before you send anything at all.

Urgency is the engine

Every scam script runs on time pressure, because thinking is the only defence that reliably works and thinking takes time. So the offer expires today. The deposit must arrive before the shipment leaves. Twelve other candidates are waiting. The client is angry. Notice what this does: it moves you from judging the offer to protecting the offer. Once you are afraid of losing it, you stop asking questions and start doing whatever keeps it alive. The counter is a rule you set in advance, before any of it applies to you. Nothing goes out on the same day it is asked for. No money, no documents, no codes, no signature. Twenty-four hours costs you nothing real, and almost every genuine opportunity survives it. Almost no scam does.

Nothing exists until it is written

Ask for the arrangement in writing: the work, the rate, when payment happens, and who you report to. Ask for it in an email rather than a chat message, because chat can be deleted from both sides and often is. Two things then happen. A real employer sends something, and now you have terms you can hold them to. A fake one delays, sends a document that contradicts what you were told, or gets irritated that you asked. Keep everything either way: screenshots, the full email, account names, numbers, dates, and any transaction reference. If this later becomes a report to your bank or the police, the quality of your evidence decides how far it goes.

Your five-minute check

Run this before you send money, documents, codes or hours of work. One, which direction does money move; if any of it moves toward them, stop here. Two, read the sender's real address and the destination of any link. Three, find the company yourself and check whether the role exists on its own site. Four, check the person: profile age, connections, whether a video call is possible. Five, ask for the terms in writing and watch how they react. Five minutes, five steps, and it stops the overwhelming majority of what is out there. Write the steps somewhere you will see them, because the point is to have the check ready on the night you are tired, broke and hopeful, which is exactly when the message arrives.

Remember

  • Money toward them, urgency, no video, wrong domain, chat-only terms, unreal pay.
  • Set the rule in advance: nothing goes out the same day it is requested.
  • Ask for terms by email. Keep every screenshot, name, number and reference.
  • Five steps, five minutes, run before you send anything of value.

After a scam: what to do

~6 min

The first hour

If you realize mid-scam, stop where you are. Send nothing further, however much has already gone, because the next request is always framed as the one that fixes the last. Do not warn them that you know; simply stop replying. Then, in this order: contact your bank or e-wallet provider and tell them exactly what happened, because some transfers can be halted or recalled in the first hours and almost none can later. If you shared login details, change those passwords now, starting with your email. If you gave card details, ask the provider to block the card. Screenshot everything before you delete anything, or before the other side deletes it. Speed matters more than completeness here. You can write the full account of it afterwards.

Secure what they touched

Work through what they actually reached. Passwords: change them anywhere you reused the one you gave, starting with the email account your other accounts recover through, then turn on two-step verification there. Devices: if you installed anything they asked you to install, especially remote access or screen sharing software, remove it and change your passwords from a different device. Accounts: watch your bank and wallet statements closely for small unfamiliar charges, which are often a test before a larger one. Documents: if you sent identity documents, assume they are in circulation and check periodically whether accounts or loans have been opened in your name. Where your country offers a way to flag your identity as compromised, using it is worth the paperwork.

Report it properly

Report even when the amount is small and even when you expect nothing back, because reports are how patterns get seen and how the same operation stops working next month. Report to your bank or wallet provider, to the platform where the contact happened, and to the police. In the Philippines, cybercrime complaints are handled by units within the national police and the investigation bureau, and other countries have their equivalent; look up the current official channel on the agency's own website rather than trusting a number someone sends you. Bring your evidence organized: dates, names, accounts, amounts, screenshots. We are not lawyers and this is not legal advice. If the sums are significant or your identity was taken, ask a qualified professional in your country what your options are.

The second scam: recovery services

Within days of being scammed, many people are contacted by someone offering to recover the lost funds: an agent, a lawyer, a hacker, a fraud specialist, sometimes a person claiming to be from the authorities. They will show testimonials and ask for a fee, or for your documents, to start. This is a second scam, run on lists of known victims, often by the same people. Nobody legitimate charges you an advance fee to get your money back. Recovery, when it happens at all, happens through your bank, the payment provider, or a police case. Treat every unsolicited offer of help after a scam as part of the scam, and route everything through the official channels you contacted yourself.

Say it out loud

Tell someone. A partner, a friend, a peer in this work. Not because talking undoes the loss, but because silence is the condition scams need in order to keep running, and because the second opinion you skipped before the transfer is still useful afterwards. Post the details in a workers' community if you have one, with the account names, the domains and the script they used, so the next person recognizes it in time. If it happened while working with us, tell us, and tell us even when it happened somewhere else, because knowing which scripts are circulating helps us warn everyone. What happened is information now. It stops being a private failure the moment you hand it to someone who can use it.

Remember

  • Stop sending immediately. The next payment is always framed as the fix.
  • Call your bank first. Some transfers can be recalled within hours, not days.
  • Change the email password first, then anything sharing that password.
  • Anyone offering to recover your money for a fee is the second scam.
  • Report it and tell people. Silence is what keeps the operation running.

Sit the exam

The courses are free. The work is real.

Twelve scenario questions. Pass at ten. Three attempts a day. The bar is the point.

No paid tier. No certificate fee. No upsell. Not now, not later.

Create a free account

You can start the first course tonight.

The curriculum

Everything, and what is in it.