1. What happened
A website using the name and look of Nike's careers pages asked visitors to log in with Facebook before continuing a job application.
The page was hosted at nikerecruits[.]com, not at Nike's official website. It copied Nike's logo, navigation, images, and recruitment language to make the page feel familiar and trustworthy. A video was also playing in the background, adding movement and polish that made the page look more like a real corporate careers site.

![Figure 2. The Nike-branded page at nikerecruits[.]com copied the real site's navigation, imagery, and careers presentation. A background video was playing during the review.](/investigations/nikerecruits-phishing-report-2026/figure-2-nike-page.png)
The page then displayed a Facebook login form while the address bar still showed nikerecruits[.]com. The domain did not change to Facebook.
![Figure 3. The fake login page displayed Facebook branding, but the browser remained on nikerecruits[.]com.](/investigations/nikerecruits-phishing-report-2026/figure-3-facebook-login.png)
2. The warning signs we found
Several details pointed in the same direction:
- The address was wrong. The page used nikerecruits[.]com rather than an official Nike careers address.
- The page copied Nike's appearance. It used Nike branding, career-navigation links, and language about joining the company.
- Facebook was the only way forward. The page did not offer a normal job application. It asked the visitor to continue with Facebook instead.
- The privacy and terms text was decorative. The words appeared on the page but did not lead to working policy pages.
- The page asked for more than a job application should require. In one branch of the flow, a password step was followed by a request for an SMS verification code.
A genuine employer may use a third-party sign-in option in some situations, but the sign-in must take place on the real service's trusted domain. A familiar logo does not make a page safe.
3. What happened after the login prompt
During a controlled test using deliberately bogus text, the first test produced an incorrect-password message. With a second test email, different from the first, the flow did not repeat that message. Instead, it proceeded to a “Check your text messages” screen requesting an SMS verification code. The differing behavior between the two attempts indicates that the flow varied conditionally rather than simply displaying a static message.

In a separate follow-up test, the browser was sent to facebook2fa[.]official-recruitment[.]com/system-check. That page displayed Vercel's “This deployment is unavailable” message.
On August 14, 2026, the Cybersecurity Reach Foundation reported nikerecruits[.]com to Cloudflare as suspected phishing and brand impersonation. The report included the observed login and SMS-code flow.
We did not use a real password or enter a verification code.
4. How this scam could harm someone
This type of page is designed to catch people at a moment when they are motivated to act quickly: while looking for a job.
If someone enters a Facebook password into a fake login form, the person behind the page may try to use that password on the real Facebook service or on other accounts. If the page then asks for a one-time code, the attacker may be trying to use that code during a live login attempt.
The risks include:
- Account takeover: A stolen password may allow access to Facebook or another account where the same password was reused.
- Loss of account control: An attacker may change the password, email address, or recovery settings.
- Identity theft: A fake recruitment process may later request a résumé, identity document, phone number, or other personal information.
- Further fraud: The person may be contacted again and asked for fees, banking information, equipment payments, or additional security codes.
5. Why the page looked believable
The page used techniques that are common in modern phishing:
Familiar branding
The page borrowed Nike's logo, colors, imagery, and career language. Familiar design can make people less likely to check the address bar.
A believable story
The page presented the login as part of a career application. A visitor may assume that a sign-in request is a normal step rather than a separate attempt to collect account information.
A trusted service name
Facebook is widely recognized. Showing a Facebook login screen can make a fake page seem more legitimate, even when the address bar still belongs to an unrelated domain.
A second verification step
A request for an SMS code can make a scam feel more secure. In reality, a one-time code should never be entered into a page reached through an unexpected or unverified link.
6. What the technical records show
The domain was registered on July 27, 2026, with privacy protection enabled. It used Cloudflare to sit between visitors and the underlying server. Certificates for the domain and wildcard name were issued on the same day.
These records do not prove fraud by themselves. They show a newly created site that was quickly configured and placed behind a service that hides the underlying server. Combined with the copied Nike page and the unusual login flow, they add to the warning signs.
For comparison, Nike's real careers site uses its own official domain and presents job listings and application details directly.

7. How to protect yourself
Before applying for a job or signing in:
- Check the address bar. A Nike job should be reached through Nike's known official website, not a lookalike domain.
- Do not trust a logo or page design by itself. Scammers can copy both.
- Never enter a password into a page reached from an unexpected message. Open the real service yourself instead.
- Never share a one-time code. An employer or recruiter should not need your Facebook, email, or banking verification code.
- Be careful with job-related requests for money or identity documents. Verify the employer through a known official contact route.
- If you already entered a reused password, change it immediately through the real service and review recent sign-ins.
8. Bottom line
The page at nikerecruits[.]com was not a Nike job application. It copied Nike's careers branding and directed visitors to a Facebook login, then showed behavior consistent with a second step requesting an SMS verification code. A follow-up destination at facebook2fa[.]official-recruitment[.]com was unavailable on Vercel when checked, but that does not change the risk posed by the original page.
Treat recruitment pages that ask for social-media passwords or one-time codes as phishing. Go directly to the employer's official website, find the job there, and apply through that trusted route.
Reader safety
If you encountered a similar recruitment page
Do not enter passwords, personal information, or verification codes. Reach the employer through a known official address, not a link in an unexpected message.