LinkedIn background-check consent phishing — email impersonates Checkr, Sterling, HireRight, or SterlingNow claiming background-check consent required; harvests SSN + DOB + address. SHRM 2026; FTC identity-theft complaint spike.
linkedin-background-check-consent-harvest-phish
What this tier means
High-confidence threat indicator — phishing, impersonation, BEC, or scam pattern. Strong contributor to the trash decision.
How Gorganizer detects this
Email impersonating a background-screening company (HireRight, Checkr, Sterling, First Advantage, Accurate, Certn, GoodHire) sent to active job applicants requesting background check consent and harvesting Social Security number, date of birth, and bank account routing/account numbers inline in the email body or via an off-vendor link. This attack targets the post-application step in the hiring process where the applicant has genuine context and emotional investment. Sublime Security's February 2026 research documented multiple campaigns impersonating HireRight and Checkr; KrebsOnSecurity's January 2026 report traced coordinated campaigns; the FTC issued a consumer alert in March 2026. Critically, legitimate background-screening vendors never request SSN or DOB inline in an email body — they exclusively use secure web portals. Requesting PII inline in the email body is a near-perfect discriminator. Distinct from fake-linkedin-recruiter-credential-lure (InMail credential harvest without background-check framing).
False-positive guard
Every signal in Gorganizer feeds a multi-module score — never a sole verdict. This is a threat-tier signal — it adds a strong contribution to the trash score. The full pipeline still requires convergence across multiple modules + a margin over the safety floor before deletion happens, and Gmail's trash (30-day recovery) is always used — never permanent delete.
About the scoring engine
Gorganizer's scoring engine emits over 1,800 signals across six modules — headers, sender, subject, body, attachments, and structural metadata. Every email is scored by every module independently; the final verdict requires multiple modules to agree and the trash score to beat the safety floor by a margin.
Sacred safety guards — never delete starred emails, replies, calendar invites, receipts/invoices, or attachments — apply unconditionally regardless of any signal.
Ready to clean your inbox?
Gorganizer scans your Gmail with this signal and 1,800+ others, then cleans everything in one click. $4.99 one-time, no subscription.
Get started