I passed a 48-hour technical challenge, received an offer letter, and then lost the job because I had to enter and upload my ID number and make a payment on a page to complete a background check. I already knew what this was, but I needed to verify my suspicions.
The offer that wasn’t.
The email message felt authentic: it was addressed to me by my name, included details from my resume, and congratulated me on being selected from “a massive pool of applicants” for a job with a company named WeatherAI. The challenge was to build anything using their API, then submit a repo and live deployment link. I created it, submitted it, and received ‘passed’ with a signed offer letter from embed hr@weather-ai.co at the near 48-hour mark. Next came a Background Check.
I had already come across yet another developer who had written about this very same procedure–the same company, the same challenge, the same offer letter, the same redirect. When I visited a website called beta.verika.org, I got a page to enter my ID number, proof of address, KRA PIN, phone number, email, and certificates, and to top it off, I was supposed to pay a fee to them; I wasn't discovering a scam. I was verifying one. I had no item submitted when I closed the tab.
Why it lasted for more than 48 hours
The vast majority of the scam warning posts tell you about some blatantly false item. This one wasn’t. The API was real: full docs, working endpoints, real JSON weather data, tiered rates (up to 1000 requests per month), even SMS farmer notifications, and Paystack billing integrated into the docs for Kenya. It was like a real weather API for East Africa. The invite email mentioned “the scaling challenges we face on a day-to-day basis,” so I built a caching, quota-aware gateway around that constraint instead of just a weather display, and shipped it inside the window. A good challenge remains a challenge. What follows is the key to knowing what you are dealing with.
The tell, and what I walked away with
A background-check page that asks the candidate to pay for his/her background check is enough. Real employers do not bill the candidate for any kind of background check, whether it is called an “expense,” a “background check fee,” or something else, but pay for the background check themselves through a named background check vendor. The developer whose account led me here described the identical site, challenge, and fee. Two engineers, months apart, running through an identical script isn't a coincidence. It's a template.
The company isn't really there, but the 48 hours weren't wasted. I designed the project around the same restriction outlined by the fake job, and shipped a working FastAPI gateway with the following features: response caching (no repeat requests should make it to the upstream API twice), persistent quota tracking (the API itself does not track quotas, and storing them locally in SQLite is easier), retry + backoff logic specific to the errors I wanted to retry, and a React UI deployed live at weatheraigateway.onrender.com (source). The frontend, known as Kenya Weather Log, allows anyone to browse the real-time weather conditions in Nairobi, Kisumu, Bomet, and Mombasa: a little product that survived the phony job that gave it birth. But the fact that the offer was fake did not deter anyone from believing it was real.
What to look out for and what to do.
A frictionless hiring process means no humans are holding it back. Don’t take it as a compliment if the challenge seems to be a craptacular mirrored version of your CV. Any kind of payment request, no matter how it’s worded, is disqualifying. Compliance language that doesn't match your country is copied, not diligent. Someone else already publishing your exact story is confirmation, not coincidence. If you have seen it: don’t pay or upload anything; report the domains through WHOIS and report wherever the domains were seen. If you have already submitted documents or payment, inform the DCI cybercrime department and notify your bank of your ID number and KRA PIN. Do not delete anything you have created. First, keep in mind that a job search is one of the moments we are most likely to be vulnerable to this type of attack – we are on the lookout for any job opening and ready to say yes with minimal hesitation. It is this enthusiasm which is under attack. Slow down anyway.
Top comments (0)