To follow up on the earlier thread, the impersonation of AECOM HR part 2 continues with the malicious actors respond to my reply.
I had responded to the threat actor, providing availability for a conversation. The threat actor responded with the questions below at 0331 AM PT 2026-02-04. This should have been a big tell for me as the spoofed HR persona is located in Portland, OR and not likely working in the middle of the night.
Then when I had not responded, they replied to the same email thread with the same content at 1737 PM PT 2026-02-04. This is what triggered my further analysis and recognized the miscreant at work.
I posted the IOCs and details on my Github:
https://github.com/obrientg/Analysis/blob/main/2026%2002%2004%20Impersonation%20of%20AECOM%20HR%20part%202
#jobsearch #fraud #impersonation #informationsecurity #abuse #risk #riskmanagement #gethired #hiring #threatintel #IOC #IOCs #gethired #hiring #threatlandscape #getFediHired #threatInteligence #cybersecurity #phishing




