Two Emails, Two Scams: The Dark Side of Cold Outreach

Two cold emails arrived this week pitching 'opportunity' and 'accountability.' Both simply tried to extract value without fair exchange.



My inbox landed two interesting emails this week. Both were polished, professionally worded, and looked absolutely legit. And both were, beneath the surface, attempts to extract value from someone without fair compensation. I thought they were worth sharing, because they represent two patterns that are more common than most people realize.


The "Build Contest" Trap

The first email came from a company called It's Today Media. They'd found me on GitHub and wanted to invite me to a "Marketing Development Engineer Build Contest." The pitch: build an AI-powered marketing tool, and if yours is the best submission, you win $5,000 cash and a full-time job offer.

Sounds exciting, right? Let's do the math.

A serious, competitive submission to something like this would take a skilled engineer somewhere between 40 and 80 hours of real work. At $5,000, that's between $62 and $125 per hour. That’s not bad, if you win. But only one person wins, and everyone else works for free. The company, meanwhile, gets to evaluate potentially dozens of real, functional, production-quality tools built to solve their actual business problems, at no cost to them whatsoever.

This is called spec work, and the development and design communities have been pushing back against it for decades. The job offer attached to the prize is what makes it feel like an audition rather than exploitation —a clever reframe that makes you feel like you're competing for an opportunity rather than donating your labour. And honestly, I'd be shocked if either the job offer or the $5,000 reward even actually exist. They might, but I'd be surprised.

Legitimate companies evaluate engineering talent using structured technical interviews, or they pay candidates for take-home work. Full stop.


The "We Found Vulnerabilities" Shakedown

The second email was addressed to "Hi Team" (already a tell) and informed me that the sender had previously reported security vulnerabilities and hadn't heard back. They were following up to ask what compensation I offer for reported issues. Oh, and by the way, they have "even more critical vulnerabilities ready to share" once we've resolved the current ones.

This is a pattern sometimes called bug bounty fishing, and at its more aggressive end, it shades into soft extortion.

Notice what's missing: any actual details about the vulnerabilities. A legitimate security researcher leads with a responsible disclosure writeup, something that is specific, reproducible, and documented. This email leads with is a payment inquiry and a veiled threat: respond and compensate us, or we may have to "escalate or disclose."

Real researchers disclose first and discuss compensation after. Withholding details while demanding payment isn't responsible disclosure; it's leverage. The invocation of "standard industry practice" and "responsible disclosure policies" is designed to make the whole thing sound professional and principled, but the structure of the email undermines both of those claims entirely.


The Common Thread

What links these two emails is the same underlying move: using the language and framing of legitimate professional practice to extract something of value (labour, money, anxiety) without offering fair exchange. One dresses exploitation up as opportunity. The other dresses a shakedown up as a public service.

The tell, in both cases, is the imbalance. Who bears the risk? Who does the work? Who pays if things don't work out? In a legitimate transaction, those questions have reasonable answers. In these emails, the answers all point in the same direction.


When your inbox starts asking you to audition for free or pay for problems you can't verify, it's usually safe to hit delete.



Categories: : DevLife, Navigating Tech Opportunities, TechScams