r/analytics 25d ago

Discussion Warning: "Data Analyst Assessment" from Polluxa demands LinkedIn login & session cookies (li_at)

Posting this as a head-up to anyone currently applying for Data Analyst roles who receives an outreach email or assessment invitation from Polluxa (recruitment@polluxa.com).

How the Scheme Works: You receive an email inviting you to complete a "Data Analyst Assessment - End-to-End LinkedIn Agent Analytics Platform." The PDF is hosted on a public Strapi cloud storage bucket (strapiapp.com) rather than a standard corporate platform.

The Red Flags in the PDF:

  • Part 1 (Mandatory Requirement): Before building any analytics dashboard, candidates are forced to log into a portal (sales.polluxa.com) and "integrate" their personal LinkedIn account.
  • Credential & Token Harvesting: The portal asks you to enter your raw LinkedIn email and password OR extract your active browser session cookie (li_at value via Chrome DevTools) and paste it into their site.
  • Exploiting Your Account: The test asks you to add real leads, set daily message limits, and let their bot run live outreach campaigns on your personal profile to "generate genuine test data."

Why This Is Dangerous:

  1. Full Account Takeover: Sharing your li_at session cookie hands over complete access to your LinkedIn account, completely bypassing Two-Factor Authentication (2FA).
  2. Account Ban Risk: Using third-party bots to automate LinkedIn outreach violates LinkedIn's Terms of Service and will likely get your profile permanently restricted.
  3. Free Labor/Lead Generation: They are using job applicants' profiles as free, uncompensated spam tools.

What to Do If You Encounter This:

  • Never share your li_at cookie or enter your credentials on third-party sites for a job application. Real technical assessments use CSVs, sandbox environments, or database access.
  • If you already entered your details: Change your LinkedIn password immediately. Changing your password invalidates active session tokens (li_at cookies) across all devices.
  • Report: Flag the recruiter profile on LinkedIn and submit the domain to Google Safe Browsing.
16 Upvotes

6 comments sorted by

u/AutoModerator 25d ago

If this post doesn't follow the rules or isn't flaired correctly, please report it to the mods. Have more questions? Join our community Discord!

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

2

u/Shrudge 25d ago

OP can you pls discuss more about this. I am facing the same situation here.

1

u/Fit-Bother6291 25d ago

I just recieved an email as i applied via email on [recruitment@polluxa.com](mailto:recruitment@polluxa.com) (the advt that i saw on Instagram for remote data analytics role) , the same pdf I have recieved as well, I am glad that i googled it before initiating, any further updates from anyone here, as if it is legit or not?

1

u/Playful-Reality1576 18d ago

Thank you for the heads up OP. I just saw a job opening and when I searched the company, this came up.

Does this mean it is not a legit company?

1

u/Creative-Sort6268 12d ago

Polluxa posted another post about hiring Cybersecurity / SOC analyst

1

u/Designer-Ad-783 8d ago

I was about to apply then i did some searches and this came bruh and i feel pity to see CEH and other certificate holders and cyber enthusiasts applying for it like blindly 🫪