The Forced Labor Behind Social Engineering Attacks

By Svetlana Leonova, CEO, Donate Foundation [ Join Cybersecurity Insiders ]
online chat

July 30 marks the World Day Against Trafficking in Persons. The 2026 campaign, “Trapped Behind the Scam,” draws attention to a form of trafficking that can no longer be separated from cybercrime. People are lured by false job offers, transported across borders, confined in guarded compounds and forced to carry out online fraud against strangers.

For security teams, this creates an unsettling dual reality. The message arriving in an employee’s inbox may represent a genuine threat to the organization. Yet the person behind the account may also be operating under threats, violence or coercion.

This is where the familiar line between criminal and victim begins to blur. The same operation can exploit people on both sides of the screen: one is deceived by the scam, while another is forced to carry it out.

In other words, modern scams don’t necessarily want your wallet. Your email, social media password, and work accounts will often suffice.

From a False Job Offer to Forced Online Fraud

INTERPOL describes a global criminal model in which people are recruited through false job advertisements, transported to controlled compounds and forced to conduct social-engineering scams. As of March 2025, victims from 66 countries had been trafficked into online scam centers. By the end of that year, the number had grown to nearly 80 nationalities.

The operations run from these compounds range from investment and cryptocurrency fraud to romance scams, impersonation, illegal online gambling and other forms of manipulation built around trust. Those who resist, fail to meet their targets or attempt to escape may face debt bondage, violence, sexual exploitation, torture or resale to another operation.

None of this means that every person involved in online fraud is a trafficking victim. INTERPOL explicitly warns that not everyone working inside a scam center is acting under coercion. A single message cannot tell us who is behind it, let alone whether that person is a victim.

But cybersecurity teams do not need to resolve that question before responding. They only need to recognize that malicious activity and individual culpability are not the same thing.

This is where cybercrime and human trafficking cease to be separate worlds. They become two ends of the same criminal operation: one victim is deceived out of money, while another may be forced to carry out the deception. 

The darkest threats do not have to come from the darkest of Webs – they reside in the digital spaces you already know.  Nor do you need to be wealthy, influential or unusually careless to attract their attention. In many cases, simply having an email address, a public professional 

The Threat Becomes Personal Quickly

When we launched Donate Foundation, a nonprofit technology platform based in California, we learned how little time it takes for even a small organization to attract unwanted attention.

Soon after launch, our website was affected by malicious redirects. Then came fraudulent inquiries and partnership proposals sent to our organizational inboxes. Some carried suspicious attachments. Others appeared to draw on information visible through employees’ public LinkedIn profiles, disguising themselves as plausible job offers, community polls, newsletters or promotions connected to interests they had shared online.

As we examined those attachments through safe throwaway accounts, we saw that they were designed to steal credentials and whole “workplace identities.” Some were simply files carrying malware, whereas others were designed to look like contracts and invoices from our partners. One of our employees ended up having her Google Workspace credentials stolen through exactly the same mechanism.

This particular employee’s vulnerability was enabled by her front-facing position in the company. As a Partner Relations Manager, it was a normal part of any work day to receive communications, invoices, and other documents for various active negotiations. As our investigation revealed, that specific message was referring to an actual partnership we casually mentioned on one of our social media pages a week earlier.

Generative AI has made this kind of personalization cheaper to produce, easier to automate and harder to detect. Cybersecurity Insiders has already documented how AI can make scams more convincing at scale. Awkward grammar and obviously fabricated details are no longer dependable warning signs. A message can imitate a familiar tone, incorporate real information and adjust its approach as the conversation develops.

For the recipient, the immediate task is to recognize the threat and protect the organization. Yet the false offer used to compromise one employee may closely resemble the offer used to recruit another person into a guarded compound.

In both cases, the weapon is the same: a carefully constructed promise designed to exploit trust.

Where the Standard Playbook Ends Too Early

The usual advice for dealing with a suspicious message is sensible: do not engage, report it, delete it and block the sender.

But that sequence can end the investigation before it begins.

If the message disappears before its relevant indicators are preserved, the organization may lose information capable of connecting an apparently isolated attempt to a broader campaign. What looks like one fraudulent inquiry may share domains, attachments, language patterns or infrastructure with attacks targeting dozens of other organizations.

Security teams should therefore separate immediate containment from evidence preservation. The threat must be stopped, but the traces it leaves behind should not disappear with it.

A practical response can be built around four actions: protect, preserve, escalate and educate.

Protect the Immediate Target

First, contain the threat. End the interaction, block malicious links or domains, determine whether credentials or personal information were exposed, and stop any pending payment.

The possibility that the sender may be acting under coercion does not make the message less dangerous. It should never delay protective action.

Preserve Relevant Indicators

Before deleting the message or blocking the activity, retain the information needed for internal review or external reporting.

Depending on the incident, this may include screenshots, message headers, sender addresses, phone numbers, usernames, account identifiers, URLs, domain names, copies of job postings, payment instructions, cryptocurrency wallet addresses, timestamps, and recurring phrases or templates.

The FBI advises those reporting cyber-enabled fraud to provide as much identifying, communication, domain, transaction, and timeline information as possible. Organizations should preserve only what is relevant and do so in accordance with their privacy, retention, and incident-response policies.

The principle is simple: stop the threat, but do not erase its traces.

Escalate Through a Defined Path

Employees should know exactly where to send a suspicious message.

Security or IT may lead the initial review. HR should become involved when attackers impersonate recruiters or misuse the organization’s brand. Finance, legal, privacy, or fraud teams may also need to participate when money, credentials, or sensitive data are at risk.

Repeated templates, shared domains, cryptocurrency addresses, or cross-platform patterns may justify escalation beyond the normal phishing workflow. In the United States, cyber-enabled fraud can be reported through the FBI’s Internet Crime Complaint Center.

Employees and analysts should not contact the sender, attempt a rescue, or investigate whether an individual is being trafficked. Their role is to protect, document, and report—not to determine victim status.

Educate Without Oversimplifying

Awareness training should explain both sides of the threat.

Not every person involved in online fraud is a trafficking victim, and the possibility of coercion does not remove the need to block malicious activity. At the same time, organizations should avoid teaching employees that every person behind a fraudulent account occupies the same place in the criminal network.

The goal is not to turn security teams into trafficking investigators. It is to make sure that protecting the immediate target does not erase evidence that may point to a wider criminal system.

The answer is not to surrender trust, but to make it harder to exploit.

The threat may appear inside a guarded compound or in an ordinary inbox. Increasingly, it exists in both places at once.

_____

About the Author

Svetlana Leonova is CEO of Donate Foundation, a nonprofit technology platform focused on trusted charitable giving. Her work centers on nonprofit trust, digital risk, and the responsible use of technology in philanthropy.

donate-foundation.org

Join our LinkedIn group Information Security Community!

No posts to display