Threat Brief: Recruiting Scheme Impersonating Palo Alto Networks Talent Acquisition Team
ID: 3e58b97a-eb16-55bd-924a-1bfdf20bb3cb
STIX ID: report--3e58b97a-eb16-55bd-924a-1bfdf20bb3cb
Feed Name: Palo Alto Networks Unit 42
Since August 2025 Unit 42 has tracked a targeted phishing campaign in which actors impersonate Palo Alto Networks recruiters, leveraging LinkedIn-scraped details and manufactured ATS/HR bureaucratic crises to pressure senior candidates into paying for résumé/ATS “alignment” services. The brief includes example phishing emails, listed email addresses, handles and phone numbers used by the actors, recommended mitigations (verify domains, refuse payment requests, report on LinkedIn), and contact information for Unit 42 Incident Response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
