Стас Юрасовздолай шахрая
19 August 2026, 11:48
2026-08-19
AI vacancies and the "pay for software" trap: How scammers disguise themselves as IT companies and extort money from Ukrainian specialists
The Ukrainian IT market has encountered a new wave of sophisticated online fraud. Criminals are actively parasitizing on the artificial intelligence trend, creating the image of progressive international startups. They lure job seekers with attractive conditions, conduct quite convincing interviews, and at the onboarding stage, they drain money from bank cards under the pretext of purchasing corporate software or access to the internal knowledge base.
The Ukrainian IT market has encountered a new wave of sophisticated online fraud. Criminals are actively parasitizing on the artificial intelligence trend, creating the image of progressive international startups. They lure job seekers with attractive conditions, conduct quite convincing interviews, and at the onboarding stage, they drain money from bank cards under the pretext of purchasing corporate software or access to the internal knowledge base.
UX/UI designer Anastasia Krystopchuk, as well as other specialists who almost fell victim to this scheme, spoke about the alleged scam surrounding the fake company CarrotDevs on social media.
The perfect offer that turned out to be a trap
The scheme starts off standardly: vacancies for remote collaboration appear on popular job search platforms, in particular Work.ua. The conditions look very attractive, and the recruitment process unfolds unusually quickly.
Anastasia Krystopchuk shares that the vacancy from the «Canadian IT company» CarrotDevs immediately caught her attention. After the response, the HR manager promptly contacted her and offered to take a test task. According to the designer, the test turned out to be very easy and short, so she agreed to take it without hesitation.
The real grounds for trust appeared during the technical interview. The designer notes that the «team leader» who conducted the interview asked really deep and professional questions, creating the impression of communicating with a real experienced IT professional. Soon the candidate was sent an offer. However, later an alarming detail was revealed: the company representatives did not even open the file with the completed test task.
Red flags to look out for
Doubts about the legitimacy of the employer began to grow when Anastasia was asked to provide personal documents before a contract or employment agreement was even provided for review. Gradually, other suspicious details began to emerge, forming a complete picture.
«First, to sign an employment contract, I had to provide them with all my documents without even seeing the contract in person…», shares Anastasia.
Anonymity and communication. Recruiters used regular free email addresses instead of corporate addresses on their own domain. During the interview, company representatives categorically refused to turn on video cameras.
Traces on the network. No employee listed in the offer or associated with the company could be found on the professional network LinkedIn.
Strange inconsistencies. Positioning itself as a Canadian business, the company conducted all recruitment exclusively in Ukrainian. The official website was quickly created using the Webflow designer, and the HR manager’s Telegram avatar was clearly an image generated by artificial intelligence.
How the money laundering mechanism works
The most interesting part begins after the candidate accepts the offer. They are transferred to the so-called «onboarding» stage and asked to register on a special internal platform — in the case of one of the victims, it was called TheFamoso.
On this platform, fake mentors and team leaders create the appearance of a work process and inform that in order to start working, it is necessary to take out a paid subscription to a corporate WIKI system or special software. Company representatives assure that these costs will be compensated with the first salary, but they urge «not to waste time» and pay a small amount — about $7 — yourself right now.
«They also said that they would compensate for gyms and tuition up to $2,000 per year,» Anastasia added under the post.
The outcome of this story was told by another girl (Threads user sunflower_0.02), who found herself in a similar situation. She followed the link and made the payment. In fact, the small subscription amount is just a cover. The phishing page intercepts the full details of the bank card, including the number, expiration date, and CVV code.
The company’s «manager» asked her to review internal documents on the «Wiki.»
»…you just get acquainted and that’s it, then it says you need to be verified and pay for the wiki on their platform, it’s like their local library and access is only after payment, on the screen the scammer says that he will tell the CEO to send me the money so that I don’t pay out of my own pocket…», the girl told Threads.
Immediately after this, attempts begin to debit all available funds and credit limits from the victim’s account.
«You subscribed, paid, and that’s it, well done, you have access to the wiki, read it, today I noticed that there was an unsuccessful payment, because of course the scammers got the card data,» says sunflower_0.02.
But as soon as access to the account is blocked, pseudo-employers instantly stop communication or report that «cooperation will not work out» and block the user.
What is known about CarrotDevs now?
At the time of publication of the material, dev.ua did not find any confirmation of the existence of CarrotDevs as an officially registered business or a real IT company. The brand’s social networks are either completely empty or do not contain any signs of real activity. How many specialists could have suffered from the actions of these scammers remains unknown at this time. But we see that under the post sunflower_0.02 in Threads, comments from other victims who fell into the same trap began to appear.
The dev.ua editorial team is ready to publish CarrotDevs' position and has requested an official comment at the email address listed on their website.
Remember the main principle of employment. No legitimate company ever asks candidates for money. The employer pays you for the work you do, not the other way around.
A free address for HR of an international IT company is a serious reason for additional verification.
A website today is weak proof of the existence of a business. It can be created quickly, and texts, photos of employees, and case studies can be generated by AI.
You should also check the legal registration of the company in the relevant country, the history of the domain, the profiles of real employees, the length of their activity, mentions of the company in independent sources, the history of vacancies and the correspondence of contacts to the official domain. A «professional interview» is no longer a reliable check.
Ignore requests to purchase software or verify yourself. Requests to pay for access to an internal WIKI, training materials, «corporate software,» or to pass a verification with the promise of further compensation are 100% signs of a scam.
Never enter your bank card details on unknown resources. Any requests to deposit your own funds or enter your card details (including the expiration date and CVV code) on third-party «onboarding platforms» are guaranteed to lead to the theft of your savings. (By the way, in advanced banks the user is provided with a dynamic CVV that changes every hour. So you don’t have to be afraid that they will write off the money).
Provide documents only after establishing who exactly you are transferring them to and why. Passport, ID card, tax number, selfie with a document, bank details are valuable data. Before transferring documents, the candidate must at least understand: which legal entity receives them, for what purpose, what data is needed and on what basis. Particularly dangerous requests for: a photo of a bank card; CVV2/CVC2, PIN; bank confirmation codes; banking password; Action. Signature on the instructions of a third party; demonstration of the screen when entering the bank; installation of remote access programs.
If payment is still necessary, do not proceed to payment via the link from the chat. Find the official website of the software provider yourself and check the domain. For example, if the «employer» claims that you need to buy a well-known commercial product, do not use its Pay/Subscribe/Activate button. Find the manufacturer yourself and check whether the named product, tariff, and payment method even exist. Many banking applications have the ability to issue a virtual card for a one-time payment or for a payment not exceeding a specified amount — this is convenient to use in questionable cases of payment, if you still dare to do it.