Free Security Audit · A Random Act of Kindness

You Open Attachments From Strangers for a Living.

My first job is to protect you.
My second job is to make you money.

No form. No email. No catch.

Want more like this?

How search firms get robbed

Recruiting is the only profession where opening unsolicited files from unknown people is the core job function. Hackers noticed and they have your number.

The poisoned resume

Attack groups apply to real jobs with fake resumes that install backdoors. Their own playbooks name recruiters as the target, because opening attachments is the job.

Venom Spider / More_eggs campaigns

The fake candidate

Stolen identities, deepfaked interviews, laptop farms. You place them and collect the fee, and your client just hired a foreign operative.

DOJ: 300+ firms infiltrated

The rerouted fee

Someone reads your inbox for weeks, waits for an invoice to go out, then sends “updated banking details” from your own address.

$3.04B lost in 2025

The database you’re sitting on

Comp data, addresses, sometimes SSNs, every fee agreement you’ve signed. A hacker sees a payday behind weak locks.

The shared password

Shared logins, high turnover, ex-employees with working credentials. Infostealers harvest the rest and sell it for pennies.

The AI leak

Candidate PII pasted into free chatbots with training turned on is out of your custody forever. And hidden instructions inside resumes now target the AI tools screening them.

What’s inside the audit

Ten categories, sixty plain-language questions, sequenced by where search firms actually lose money. Eight questions are marked RED FLAG. A no on any of those gets fixed the same week.

01

Email

Where firms actually get robbed

02

Money movement

Wires, invoices, verification rules

03

Identity and access

Passwords, MFA, who holds keys

04

The human layer

Phishing, fake candidates, cloned voices

05

Candidate and client data

The database and its legal weight

06

AI tools

What gets pasted where, and by whom

07

Vendors and contractors

Every outsider with a key

08

Devices and networks

Laptops, routers, hotel wifi

09

Backups and continuity

Ransomware and the LinkedIn lockout

10

Incident response

The plan you write before the bad day

The audit has one rule

“I don’t know”
counts as no.

Attackers don’t care whether your exposure is deliberate or
accidental. If a question confuses you, the confusion is a finding.

Take the Audit.

Sixty questions and an afternoon of honesty. When you’re done,
you’ll know exactly where your firm is exposed and what to fix first.
If you found this valuable, a comment on the LinkedIn article would be much appreciated. Thank you!

We won’t even make you give an email address.

Want more like this? Free, high-value content for recruiters only.

Written by Tricia Tamkin

33 years in recruiting. Co-founder of Moore eSSentials. The audit was built with Claude.

Published August 2026 · Updated August 2026

Questions people ask

Yes. No email, no gate, no upsell on the download. Consider it a Random Act of Kindness for our industry.
Owners and recruiters at agency search firms, from a solo desk to a mid-size shop. Nothing in it requires an IT department. Most fixes are settings, habits, and short conversations.
An afternoon. Sixty yes-or-no questions across ten categories, and “I don’t know” counts as no. Eight red-flag items come first, then work the categories top to bottom.
Because our first job is to protect you. The industry’s been good to us, and this fits the RAK Friday tradition. If you want more free content afterward, there’s a signup above. That’s it.