Skip to content
← Back to blog
Security·September 29, 2026·6 min read

Fake client inquiries are the new fake recruiters. Nine checks before the first call.

Attackers now pose as clients to reach agencies through Clutch and contact forms. Nine checks, most under a minute, to run before anyone opens a file.

For years the warning to developers was about fake recruiters: a too-good job offer, a take-home test, a repository that stole your keys. On September 18, 2026 the FBI's IC3 and partner agencies in Japan, Australia and Germany published an alert saying the North Korea-linked group behind those campaigns also poses as clients on freelance and gig platforms. Eleven days later one of those "clients" found us through our Clutch profile. Here's what he sent. This post is about the part before the malware: the inquiry itself, and the nine checks that would have flagged it before anyone opened a file.

Why agencies make a better target than job seekers

A fake recruiter compromises one engineer. A fake client compromises the laptop of someone who holds credentials for every client that agency serves: repository access, cloud consoles, staging databases, the .env file for a project that went live last month. From an attacker's side that's a much better return on one convincing email.

It also plays to how agencies are built. Everything in a good sales process pushes toward saying yes quickly. Reply within the hour, get the brief, show you understand it, book the call. Our reply went out the same morning, and it should have, because most inquiries are real. The fix isn't to slow sales down. It's to put a short gate between "sales is talking to a lead" and "an engineer opens something the lead sent".

The nine checks

None of these proves anything alone. Two or three together should stop the process until someone has made a phone call.

#CheckHow longWhat we saw
1How old is the sender's domain?30 secondsRegistered the day before the email
2Does the domain match the company's real website?30 secondsNo. The real company uses a different domain
3Does the phone number fit the company's location?10 secondsA Rhode Island area code for an Austin company
4Can you reach the person through the company's official number or site?5 minutesWe didn't need to; checks 1 to 3 were enough
5Are they sending files before a first call?InstantYes, a full project archive
6What format are the files?InstantA .tar.gz of a git repository, not a PDF or a link
7How is the NDA delivered?Instant"In the NDA branch of the repository"
8Is the order of steps odd?InstantNDA before any discussion, but only via the repo
9Is the project suspiciously perfect for you?JudgementA textbook fit for a custom software shop

Check 9 deserves a word. Our inquiry was a well-written brief for exactly the kind of platform we build, with vision, MVP scope and stakeholders, because that's what makes a busy agency owner reply. A pitch that fits you perfectly isn't suspicious by itself. It just shouldn't lower your guard for the other eight.

How to check a domain's age in 30 seconds

This is the single most useful check, and the one attackers can't fake after the fact.

  • In a browser: search the domain on an RDAP or WHOIS lookup service (ICANN runs one at lookup.icann.org). Look for the registration or creation date.
  • In a terminal: whois example.com | grep -i creation

A real consultancy's domain is usually years old. A domain created this week, sending you a partnership proposal, is worth a question. Ours was registered on September 28 and emailed us on September 29.

Then compare it with the company's actual website. Lookalikes tend to add a word (inc, group, global), swap a letter, or change the ending. If the real company is easy to find and its site lists a different domain, you have your answer.

What to say to a lead you're not sure about

You don't need to accuse anyone. A real client won't be bothered by any of these, and a fake one usually goes quiet:

  • "We don't open repositories sent as archives. Could you share a hosted link, or a PDF of the spec?"
  • "Could you send the NDA as a PDF or an e-signature link? We'll turn it round today."
  • "Happy to jump on a call first. I'll ring the main number on your website."

That last one is the strongest, because it moves the conversation onto a channel the attacker doesn't control. If the person on the company's switchboard has never heard of your contact, you're done.

Keep speed-to-lead without the risk

The gate we now use is simple enough that nobody on the sales side has to think about it:

  1. 1.Anyone can reply to a lead. Speed still matters and nothing here slows the first response.
  2. 2.Nobody opens a lead's files on a work laptop until checks 1 to 3 pass. Documents are read in a browser preview or a throwaway machine, never downloaded into a project folder.
  3. 3.Repositories get the technical triage we wrote up in how to check a client's git repo for malicious hooks, which takes about ten minutes.
  4. 4.Anything that has to run (a demo, an install, a test suite) runs in a disposable VM with no credentials on it.
  5. 5.Suspicious leads get reported, not just ignored. A lookalike domain goes to its registrar, a hosted file to its host, and the lead source (Clutch, in our case) gets told so they can warn other providers.

For an agency that also subcontracts or takes white-label work, the same gate applies to partners as well as clients: anyone who sends you code is someone whose code will run on your machines.

If you'd like a second opinion on an inquiry that feels off, or help putting a gate like this in place, our cybersecurity team is happy to look, and you can reach us through the contact page.

Sources

Frequently asked questions.

Check how old the sender's domain is, whether it matches the company's real website, and whether the phone number fits the company's location. Be wary of files sent before a first call, repositories sent as archives, and NDAs delivered in any form other than a PDF or e-signature link. Two or three of these together are enough to pause.

Search the domain on an RDAP or WHOIS lookup such as lookup.icann.org, or run whois with the domain name in a terminal and look for the creation date. A real company's domain is usually years old. The one that targeted us was registered the day before it sent its first email.

Yes. On September 18, 2026 the FBI's IC3 and partner agencies warned that the North Korea-linked Contagious Interview group poses as clients on freelance and gig platforms as well as employers. We received one such inquiry through our Clutch profile eleven days later.

Let anyone reply to a lead immediately, but keep a gate before an engineer opens anything the lead sends: domain age, domain match and phone checks first, a repo triage for any code, and a disposable virtual machine for anything that has to run. The first response stays fast and the risk stays off work laptops.