Recruiting is the only profession where opening unsolicited files from unknown people is the core job function. Hackers noticed and they have your number.
The poisoned resume
Attack groups apply to real jobs with fake resumes that install backdoors. Their own playbooks name recruiters as the target, because opening attachments is the job.
Venom Spider / More_eggs campaigns
The fake candidate
Stolen identities, deepfaked interviews, laptop farms. You place them and collect the fee, and your client just hired a foreign operative.
DOJ: 300+ firms infiltrated
The rerouted fee
Someone reads your inbox for weeks, waits for an invoice to go out, then sends “updated banking details” from your own address.
$3.04B lost in 2025
The database you’re sitting on
Comp data, addresses, sometimes SSNs, every fee agreement you’ve signed. A hacker sees a payday behind weak locks.
The shared password
Shared logins, high turnover, ex-employees with working credentials. Infostealers harvest the rest and sell it for pennies.
The AI leak
Candidate PII pasted into free chatbots with training turned on is out of your custody forever. And hidden instructions inside resumes now target the AI tools screening them.
What’s inside the audit
Ten categories, sixty plain-language questions, sequenced by where search firms actually lose money. Eight questions are marked RED FLAG. A no on any of those gets fixed the same week.
01
Email
Where firms actually get robbed
02
Money movement
Wires, invoices, verification rules
03
Identity and access
Passwords, MFA, who holds keys
04
The human layer
Phishing, fake candidates, cloned voices
05
Candidate and client data
The database and its legal weight
06
AI tools
What gets pasted where, and by whom
07
Vendors and contractors
Every outsider with a key
08
Devices and networks
Laptops, routers, hotel wifi
09
Backups and continuity
Ransomware and the LinkedIn lockout
10
Incident response
The plan you write before the bad day
The audit has one rule
“I don’t know”
counts as no.
Attackers don’t care whether your exposure is deliberate or accidental. If a question confuses you, the confusion is a finding.
Take the Audit.
Sixty questions and an afternoon of honesty. When you’re done, you’ll know exactly where your firm is exposed and what to fix first.
If you found this valuable, a comment on the LinkedIn articlewould be much appreciated. Thank you!
We won’t even make you give an email address.
Want more like this? Free, high-value content for recruiters only.
Written by Tricia Tamkin
33 years in recruiting. Co-founder of Moore eSSentials. The audit was built with Claude.
Published August 2026 · Updated August 2026
Questions people ask
Is the audit really free?
Yes. No email, no gate, no upsell on the download. Consider it a Random Act of Kindness for our industry.
Who is the audit for?
Owners and recruiters at agency search firms, from a solo desk to a mid-size shop. Nothing in it requires an IT department. Most fixes are settings, habits, and short conversations.
How long does it take?
An afternoon. Sixty yes-or-no questions across ten categories, and “I don’t know” counts as no. Eight red-flag items come first, then work the categories top to bottom.
Why is Moore eSSentials giving this away?
Because our first job is to protect you. The industry’s been good to us, and this fits the RAK Friday tradition. If you want more free content afterward, there’s a signup above. That’s it.