Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

HR Bewar(y): Job applications and resumes could have ransomware attached

By Sonni Nolan on January 26, 2017
Email this postTweet this postLike this postShare this post on LinkedIn

You recently engaged a contract HR recruiter to work onsite helping with increased hiring. The contractor is reviewing hundreds of job applications for several new job postings. Not surprisingly, many of the job applications have a PDF resume attached. The contract recruiter clicks on one of the attached resumes and enables the associated macro to run. Suddenly, the recruiter gets a screen notifying him that unless a ransom is paid, the victim will not be able to access their files. Not the best way to start off the week for HR, IT, or security employees.

Clicking on what appeared to be a routine innocuous attachment, the contract recruiter unsuspectingly downloads ransomware. At which point, the recruiter is directed to make a payment of approximately $1,000 (or 1.3 Bitcoins) using an untraceable payment method in a Dark Web portal. The brazen malware operators even offer tech support in case the victim has issues making the payment. Without the payment, the victim is precluded from accessing their files. This recent scam started with German companies, but may soon be coming to a company near you.

What can you do to avoid a similar tale of woe?

  • First, don’t run scripts from emails outside your company. Don’t enable any macros.
  • Second, open outside documents using a cloud service, such as GoogleDocs.

More and more companies are turning to “phishing simulation training” that puts employees in positions to help them recognize fraudulent communications such as these. However, more employers are using temps and contract employees to augment their regular workforce when lots of hiring needs to occur quickly. Unfortunately, contract employees may not receive cybersecurity training before being assigned to a company.

With tax season upon us, HR should be extra vigilant and should expect new phishing scams to be unveiled. Last year, hackers had great success in getting unsuspecting payroll employees to provide access to employees’ personal data by posing as a high-level executive requesting the information. Who knows what hackers have in store for this tax season?

 

 

 

 

 

Photo of Sonni Nolan Sonni Nolan

As a former corporate attorney for a Fortune 100 company with extensive litigation experience, Sonni is uniquely qualified to provide clients with practical, creative and sound legal advice compatible with today’s business environment.

Read more about Sonni NolanEmailSonni's Linkedin Profile
  • Posted in:
    Employment & Labor
  • Blog:
    Byte Back
  • Organization:
    Husch Blackwell LLP
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo