Cybersecurity Reach Foundation
Investigations

Threat investigation

The Fake Nike Careers Site That Tried to Steal Facebook Logins

A convincing Nike job-site clone used a fake Facebook sign-in to target people looking for work.

Investigator
Higor Silva · CTI Researcher, Cybersecurity Reach Foundation
Published
August 14, 2026
Scope
Passive · Non-intrusive · Evidence-led
On this page

Research note — This report documents a controlled review of nikerecruits[.]com. No real credentials, personal information, or verification codes were submitted. Suspicious domains are defanged in public text where a clickable link is not necessary.

What readers need to know

A fake Nike careers site tried to steal Facebook logins.

The page at nikerecruits[.]com copied Nike's careers branding and made a Facebook login the only visible way to continue a job application.

One branch then requested an SMS verification code. A follow-up destination was unavailable on Vercel when checked. Treat similar pages as phishing and use the employer's official website instead.

If you encountered it:

  • Do not enter a password or one-time code.
  • Open the employer's official website yourself and find its careers page.
  • Change any reused password through the real service.
  • Review account sign-in activity and report the suspicious page.

1. What happened

A website using the name and look of Nike's careers pages asked visitors to log in with Facebook before continuing a job application.

The page was hosted at nikerecruits[.]com, not at Nike's official website. It copied Nike's logo, navigation, images, and recruitment language to make the page feel familiar and trustworthy. A video was also playing in the background, adding movement and polish that made the page look more like a real corporate careers site.

Figure 1. The page asked visitors to continue with Facebook as the only visible way to proceed.
Figure 1. The page asked visitors to continue with Facebook as the only visible way to proceed.
Figure 2. The Nike-branded page at nikerecruits[.]com copied the real site's navigation, imagery, and careers presentation. A background video was playing during the review.
Figure 2. The Nike-branded page at nikerecruits[.]com copied the real site's navigation, imagery, and careers presentation. A background video was playing during the review.

The page then displayed a Facebook login form while the address bar still showed nikerecruits[.]com. The domain did not change to Facebook.

Figure 3. The fake login page displayed Facebook branding, but the browser remained on nikerecruits[.]com.
Figure 3. The fake login page displayed Facebook branding, but the browser remained on nikerecruits[.]com.

2. The warning signs we found

Several details pointed in the same direction:

  • The address was wrong. The page used nikerecruits[.]com rather than an official Nike careers address.
  • The page copied Nike's appearance. It used Nike branding, career-navigation links, and language about joining the company.
  • Facebook was the only way forward. The page did not offer a normal job application. It asked the visitor to continue with Facebook instead.
  • The privacy and terms text was decorative. The words appeared on the page but did not lead to working policy pages.
  • The page asked for more than a job application should require. In one branch of the flow, a password step was followed by a request for an SMS verification code.

A genuine employer may use a third-party sign-in option in some situations, but the sign-in must take place on the real service's trusted domain. A familiar logo does not make a page safe.

3. What happened after the login prompt

During a controlled test using deliberately bogus text, the first test produced an incorrect-password message. With a second test email, different from the first, the flow did not repeat that message. Instead, it proceeded to a “Check your text messages” screen requesting an SMS verification code. The differing behavior between the two attempts indicates that the flow varied conditionally rather than simply displaying a static message.

Figure 4. After the second test, the flow displayed a “Check your text messages” screen requesting an SMS verification code.
Figure 4. After the second test, the flow displayed a “Check your text messages” screen requesting an SMS verification code.

In a separate follow-up test, the browser was sent to facebook2fa[.]official-recruitment[.]com/system-check. That page displayed Vercel's “This deployment is unavailable” message.

On August 14, 2026, the Cybersecurity Reach Foundation reported nikerecruits[.]com to Cloudflare as suspected phishing and brand impersonation. The report included the observed login and SMS-code flow.

We did not use a real password or enter a verification code.

4. How this scam could harm someone

This type of page is designed to catch people at a moment when they are motivated to act quickly: while looking for a job.

If someone enters a Facebook password into a fake login form, the person behind the page may try to use that password on the real Facebook service or on other accounts. If the page then asks for a one-time code, the attacker may be trying to use that code during a live login attempt.

The risks include:

  • Account takeover: A stolen password may allow access to Facebook or another account where the same password was reused.
  • Loss of account control: An attacker may change the password, email address, or recovery settings.
  • Identity theft: A fake recruitment process may later request a résumé, identity document, phone number, or other personal information.
  • Further fraud: The person may be contacted again and asked for fees, banking information, equipment payments, or additional security codes.

5. Why the page looked believable

The page used techniques that are common in modern phishing:

Familiar branding

The page borrowed Nike's logo, colors, imagery, and career language. Familiar design can make people less likely to check the address bar.

A believable story

The page presented the login as part of a career application. A visitor may assume that a sign-in request is a normal step rather than a separate attempt to collect account information.

A trusted service name

Facebook is widely recognized. Showing a Facebook login screen can make a fake page seem more legitimate, even when the address bar still belongs to an unrelated domain.

A second verification step

A request for an SMS code can make a scam feel more secure. In reality, a one-time code should never be entered into a page reached through an unexpected or unverified link.

6. What the technical records show

The domain was registered on July 27, 2026, with privacy protection enabled. It used Cloudflare to sit between visitors and the underlying server. Certificates for the domain and wildcard name were issued on the same day.

These records do not prove fraud by themselves. They show a newly created site that was quickly configured and placed behind a service that hides the underlying server. Combined with the copied Nike page and the unusual login flow, they add to the warning signs.

For comparison, Nike's real careers site uses its own official domain and presents job listings and application details directly.

Figure 5. Nike's official careers experience, shown for comparison. The address bar shows careers.nike.com.
Figure 5. Nike's official careers experience, shown for comparison. The address bar shows careers.nike.com.

7. How to protect yourself

Before applying for a job or signing in:

  1. Check the address bar. A Nike job should be reached through Nike's known official website, not a lookalike domain.
  2. Do not trust a logo or page design by itself. Scammers can copy both.
  3. Never enter a password into a page reached from an unexpected message. Open the real service yourself instead.
  4. Never share a one-time code. An employer or recruiter should not need your Facebook, email, or banking verification code.
  5. Be careful with job-related requests for money or identity documents. Verify the employer through a known official contact route.
  6. If you already entered a reused password, change it immediately through the real service and review recent sign-ins.

8. Bottom line

The page at nikerecruits[.]com was not a Nike job application. It copied Nike's careers branding and directed visitors to a Facebook login, then showed behavior consistent with a second step requesting an SMS verification code. A follow-up destination at facebook2fa[.]official-recruitment[.]com was unavailable on Vercel when checked, but that does not change the risk posed by the original page.

Treat recruitment pages that ask for social-media passwords or one-time codes as phishing. Go directly to the employer's official website, find the job there, and apply through that trusted route.

Reader safety

If you encountered a similar recruitment page

Do not enter passwords, personal information, or verification codes. Reach the employer through a known official address, not a link in an unexpected message.