For years the warning to developers was about fake recruiters: a too-good job offer, a take-home test, a repository that stole your keys. On September 18, 2026 the FBI's IC3 and partner agencies in Japan, Australia and Germany published an alert saying the North Korea-linked group behind those campaigns also poses as clients on freelance and gig platforms. Eleven days later one of those "clients" found us through our Clutch profile. Here's what he sent. This post is about the part before the malware: the inquiry itself, and the nine checks that would have flagged it before anyone opened a file.
Why agencies make a better target than job seekers
A fake recruiter compromises one engineer. A fake client compromises the laptop of someone who holds credentials for every client that agency serves: repository access, cloud consoles, staging databases, the .env file for a project that went live last month. From an attacker's side that's a much better return on one convincing email.
It also plays to how agencies are built. Everything in a good sales process pushes toward saying yes quickly. Reply within the hour, get the brief, show you understand it, book the call. Our reply went out the same morning, and it should have, because most inquiries are real. The fix isn't to slow sales down. It's to put a short gate between "sales is talking to a lead" and "an engineer opens something the lead sent".
The nine checks
None of these proves anything alone. Two or three together should stop the process until someone has made a phone call.
| # | Check | How long | What we saw |
|---|---|---|---|
| 1 | How old is the sender's domain? | 30 seconds | Registered the day before the email |
| 2 | Does the domain match the company's real website? | 30 seconds | No. The real company uses a different domain |
| 3 | Does the phone number fit the company's location? | 10 seconds | A Rhode Island area code for an Austin company |
| 4 | Can you reach the person through the company's official number or site? | 5 minutes | We didn't need to; checks 1 to 3 were enough |
| 5 | Are they sending files before a first call? | Instant | Yes, a full project archive |
| 6 | What format are the files? | Instant | A .tar.gz of a git repository, not a PDF or a link |
| 7 | How is the NDA delivered? | Instant | "In the NDA branch of the repository" |
| 8 | Is the order of steps odd? | Instant | NDA before any discussion, but only via the repo |
| 9 | Is the project suspiciously perfect for you? | Judgement | A textbook fit for a custom software shop |
Check 9 deserves a word. Our inquiry was a well-written brief for exactly the kind of platform we build, with vision, MVP scope and stakeholders, because that's what makes a busy agency owner reply. A pitch that fits you perfectly isn't suspicious by itself. It just shouldn't lower your guard for the other eight.
How to check a domain's age in 30 seconds
This is the single most useful check, and the one attackers can't fake after the fact.
- In a browser: search the domain on an RDAP or WHOIS lookup service (ICANN runs one at lookup.icann.org). Look for the registration or creation date.
- In a terminal:
whois example.com | grep -i creation
A real consultancy's domain is usually years old. A domain created this week, sending you a partnership proposal, is worth a question. Ours was registered on September 28 and emailed us on September 29.
Then compare it with the company's actual website. Lookalikes tend to add a word (inc, group, global), swap a letter, or change the ending. If the real company is easy to find and its site lists a different domain, you have your answer.
What to say to a lead you're not sure about
You don't need to accuse anyone. A real client won't be bothered by any of these, and a fake one usually goes quiet:
- "We don't open repositories sent as archives. Could you share a hosted link, or a PDF of the spec?"
- "Could you send the NDA as a PDF or an e-signature link? We'll turn it round today."
- "Happy to jump on a call first. I'll ring the main number on your website."
That last one is the strongest, because it moves the conversation onto a channel the attacker doesn't control. If the person on the company's switchboard has never heard of your contact, you're done.
Keep speed-to-lead without the risk
The gate we now use is simple enough that nobody on the sales side has to think about it:
- 1.Anyone can reply to a lead. Speed still matters and nothing here slows the first response.
- 2.Nobody opens a lead's files on a work laptop until checks 1 to 3 pass. Documents are read in a browser preview or a throwaway machine, never downloaded into a project folder.
- 3.Repositories get the technical triage we wrote up in how to check a client's git repo for malicious hooks, which takes about ten minutes.
- 4.Anything that has to run (a demo, an install, a test suite) runs in a disposable VM with no credentials on it.
- 5.Suspicious leads get reported, not just ignored. A lookalike domain goes to its registrar, a hosted file to its host, and the lead source (Clutch, in our case) gets told so they can warn other providers.
For an agency that also subcontracts or takes white-label work, the same gate applies to partners as well as clients: anyone who sends you code is someone whose code will run on your machines.
If you'd like a second opinion on an inquiry that feels off, or help putting a gate like this in place, our cybersecurity team is happy to look, and you can reach us through the contact page.