A recruiter wants your ID before the interview. This is a good moment to pause
A company logo and HR form are not enough reason to send identity documents or bank details. Verify the vacancy, recruiter and stage of the process.
- AUTHOR
- Karol Rapacz / CEO of Breachroad · OSCP · PNPT
- PUBLISHED
- 8 September 2026
- READING TIME
- 8 min read
- TOPIC
- Human Security
The message sounds like excellent news: your experience fits the role, the company wants to move quickly and the recruiter attaches a form “to prepare your contract”. There is one problem. No interview has taken place, but the form wants identity documents, a home address and bank details.
A genuine employer will need some personal information after hiring. A scammer borrows that fact and moves the paperwork to a stage where the candidate has not even confirmed who is speaking. Pressure and the promise of a good role are meant to make reasonable questions feel impolite.
The stage of recruitment matters
A CV should contain what an employer needs to assess experience and make contact. Bank details are for salary payments, not an invitation to the first interview. A copy of an identity document should not be a routine ticket to learning what the job involves either.
Ask exactly why an item is needed, the basis for collecting it, who will receive it and how long it will be kept. An honest recruiter can explain the process without taking offence or giving you five minutes before the “offer disappears”. Identity or background checks can be legitimate for regulated roles, but they should have a defined purpose, an appropriate point in the process and a trusted channel.
Do not add an identity number, document copy, marital status or bank information to a CV “just in case”. The less unnecessary information travelling through inboxes and recruitment databases, the lower the cost of a mistake or breach.
Verify the employer independently
Reach the employer’s website by typing its address yourself. Check that the vacancy appears in the official careers section and that the sender’s domain matches the business. A misspelling, free email account or communication only through chat are warning signs, although a corporate-looking address is not absolute proof.
Call the main number from the company’s website and ask it to confirm the recruiter and vacancy. Do not use the number in the questionable message. If an agency is involved, verify it separately and ask the employer whether the relationship is genuine.
Never pay for equipment, training, document checks or a “reserved position”. An employer may explain its equipment requirements, but asking a candidate to send money or buy through a named shop before hiring is not ordinary onboarding.
A secure-looking form can still ask for too much
A padlock beside a web address means the connection is encrypted, not that the form is honest. A document resembling an HR system may belong to a scammer or simply be a shared cloud file. Professional appearance does not answer why the information is needed.
Once the company confirms a legitimate request, use its approved channel rather than a random attachment. Supply only the required fields. If the purpose is simply to inspect an identity document, ask whether a retained full copy is actually necessary.
If you have already sent the information
Keep the messages, form address and a list of what you disclosed. Contact the real employer to establish whether the process belonged to it and report the impersonating account to the platform. Change a disclosed password through the genuine service and end active sessions. Contact your bank after sharing financial details, even if no transaction is visible yet.
An identity-document copy and full personal record call for watching for impersonation, new accounts or contracts. Readers in Poland should consider reporting the incident to the relevant authorities and protecting their PESEL number according to the information exposed; people elsewhere should use their national identity-protection process.
What the sources say and what Breachroad recommends
Poland’s data protection authority explains in its recruitment guidance that employers should not demand unnecessary candidate data or collect it in advance without a defined need. The US FTC’s current warning about scam recruiters describes offers seeking identity or banking information before an interview and advises verifying the company independently.
Breachroad recommends checking three things: have you confirmed the employer, does this stage justify the data, and did the genuine organisation provide the channel? A good salary should not shorten those checks.
The same pressure appears in fake remote work that makes the candidate pay. We help organisations protect candidates and staff through cybersecurity training.

