The Flattering Job Offer Email That Was a Scam

A journalist was targeted by a tailored scam email offering paid work. Here's how spear-phishing works and how to spot it.

Updated 2026-10-02

A journalist at Which? recently received an email from someone claiming to be an HR manager at an overseas university, inviting her to deliver a paid guest lecture. The offer was flattering, specific, and entirely fake. It's a textbook example of spear-phishing: a scam built around one person, rather than a message fired at thousands of inboxes in the hope that someone bites.

What this actually means for you

Ordinary phishing is a numbers game. Criminals send millions of identical emails and wait for a small percentage of people to click. Spear-phishing works differently. Someone has looked you up, read about your work, found your job title, and written something that sounds like it was meant for you specifically, because it was.

This matters more now because AI tools can build a profile of a person from social media, professional profiles, news articles and leaked data in seconds. Work that used to take a scammer hours now takes moments. The result reads like a genuine, professional email: no spelling mistakes, no generic greeting, nothing that immediately looks wrong.

You don't need a high public profile to be a target. Personal information can come from a data breach as easily as from LinkedIn, even if your own accounts are locked down. And if you're a company director, charity trustee, or anyone with a visible professional role, you may be targeted specifically as a route into an organisation's systems, not just your own inbox. Government figures suggest this is a common problem rather than a rare one: the 2025/26 Cyber Security Breaches Survey found that a quarter of charities and more than a third of companies had experienced phishing attacks.

How the journalist spotted it

The giveaway wasn't obvious at first glance. It was in the detail: the email came from a '.edu' address, normally associated with US institutions, while the university it claimed to represent was in Singapore and used a '.sg' domain. The university had already published a warning about fake job offers sent from unofficial addresses. Checking the sender's domain against the organisation's genuine website is often the quickest way to catch this kind of scam.

What to do

  • Pause before replying to any unexpected offer of paid work, a lecture, a consultancy role, or similar, however flattering it is. Give yourself five minutes before answering.
  • Look up the organisation independently and compare the domain in the email to its real website. A mismatch, such as a '.edu' address for a university based elsewhere, is a strong warning sign.
  • Don't rely on your email provider's AI-suggested reply. These are built for speed, not scrutiny, and can make it easier to respond to a scam without reading it properly.
  • Don't click links in the email. Find the organisation's contact details yourself and get in touch that way instead.
  • If someone calls you unexpectedly, it's fine to hang up and call back using a number you've found independently.
  • Think about how much you share publicly on LinkedIn, company pages, or elsewhere. It won't stop a scammer working from breached data, but it reduces what a stranger can learn about you in thirty seconds.
  • Keep a reputable, independently tested antivirus product running.
  • Report phishing emails to report@phishing.gov.uk, and forward scam texts or calls to 7726.

What this does not fix

Deleting the email doesn't undo the fact that your details were findable in the first place. Antivirus software won't stop you believing a convincing story, it's a backstop, not a judgement call. And a VPN, while it hides your browsing from your network and masks your location, does nothing to stop a scammer emailing you directly. None of these tools replace the five minutes of thinking that catches most spear-phishing attempts.

If you've received a message that feels slightly too tailored to you, slightly too flattering, run it through our free scam checker at /tools/scam before you reply to anything. If it contains a link you're unsure about, check it at /tools/url rather than clicking it. Neither tool makes the decision for you, but both give you something solid to check your instincts against.

Check a suspicious message Free, and it needs no account.

All guides

Ready when you are.

£7.99 a month, or £69.99 a year. Cancel online whenever you want.

Get Veystrix