Criminals in Brazil are using fake job advertisements from well-known global brands to steal personal data and email credentials [1].
This surge in fraudulent recruitment exploits high employment demand and the visibility of major events, such as the 2026 FIFA World Cup, to trick job seekers [1].
The scam involves attackers posing as recruiters from brands including FIFA, L'Oréal, Coca-Cola, Red Bull, and Ogilvy [1], [2]. According to reports from June 10, 2026, some of these fake offers specifically targeted users to gain unauthorized access to email accounts [3].
Methods vary depending on the target. Some criminals focus on stealing credentials, while others demand payment for a bogus "certificate" before the victim disappears [4], [5]. These fraudulent schemes often use the prestige of the spoofed companies to lower the victim's suspicion during the initial contact.
Security experts provided guidance on June 30, 2026, to help the public identify these scams [4]. They said that legitimate companies typically do not request payment for certifications or sensitive login credentials during the early stages of a recruitment process.
At least four major brands have been identified as primary targets for spoofing in these campaigns [3]. The fraud has been reported nationwide across Brazil, with Portuguese-language media warning citizens to verify the authenticity of job offers through official corporate channels [1], [2].
Victims are encouraged to be wary of unsolicited job offers that promise high rewards or require immediate payment for administrative fees. Security analysts said that verifying the sender's email address and contacting the company directly are the most effective ways to avoid these traps [2], [4].
“Criminals in Brazil are using fake job advertisements from well-known global brands to steal personal data.”
This trend highlights a growing intersection between social engineering and event-driven fraud. By leveraging the 2026 World Cup and the perceived stability of multinational corporations, scammers are increasing their success rates. The shift toward stealing email credentials suggests these attacks may be precursors to larger corporate espionage or financial theft, as email access provides a gateway to other sensitive accounts.


