WaterPlum recruitment lures: preserving evidence when a job offer becomes a cyber incident

A recent Australian Cyber Security Centre advisory on WaterPlum, also known as Contagious Interview, is a reminder that a convincing job offer can become a cyber incident. For Australian organisations, the first response should protect both people and evidence.

A recruitment approach can be a security event

The Australian Cyber Security Centre has warned that threat actors use false employment opportunities to target technology professionals. A contact may appear credible because it uses a recognised employer name, a role that matches the recipient’s experience or a request to complete what looks like a routine technical task.

The risk changes when a recipient opens an unexpected file, installs a package, runs code supplied by an unfamiliar contact or enters credentials into a lookalike service. Recruitment contact should therefore be treated as a possible security event, not only as a human resources matter.

Preserve the evidence early

An early report gives an organisation the best chance to understand what happened. Preserve the original message, full headers where available, URLs, downloaded files, file hashes, screenshots, relevant device time, account activity and the cloud services involved. These records can support containment, incident response, insurer reporting and later law-enforcement enquiries.

Do not forward a suspicious attachment around the business or repeatedly open it to inspect it. Keep the original in a controlled way and record where it came from. If a file has already been opened, record the device, user account, time and any prompts or commands that followed. A contemporaneous record is usually more reliable than an account reconstructed days later.

Separate the people response from the technical response

Staff should be able to report a suspicious approach without being blamed. A prompt report can help the technical team determine whether the same sender, URL, domain or file reached other people. It can also establish whether credentials were entered, a device connected to an unfamiliar service or a corporate account was accessed from an unusual location.

The technical response should be proportionate. Preserve volatile evidence where possible, isolate a device if malicious activity is suspected, reset exposed credentials through the normal process and review identity, endpoint and network logs. Avoid changes that destroy the information needed to understand the incident unless immediate containment requires them.

Practical controls for Australian organisations

  • Use multi-factor authentication and ensure staff know how to report unexpected approval prompts.
  • Restrict software installation and code execution on managed devices where business needs allow it.
  • Use endpoint logging that can show process execution, downloaded files and network connections.
  • Maintain a documented process for preserving suspicious messages and files without distributing them.
  • Include recruitment scams and fake technical tests in awareness training for technical staff, contractors and recruiters.
  • Review external job advertisements and recruitment communications so staff can recognise the organisation’s legitimate process.

If someone has already engaged

Act quickly but methodically. Ask the person not to delete the message or clear browser history. Record the account used, the relevant time range, the service involved and any file or link opened. Escalate through the organisation’s incident process. For Australian cybercrime reporting, the ACSC directs victims to ReportCyber. Serious or immediate threats should also follow the appropriate police and emergency pathways.

Sources

This article is general information and is not incident-response, legal or law-enforcement advice.