Fake Journalists Are Targeting Companies Using TechCrunch
A sophisticated wave of impersonation attempts is currently targeting companies, with bad actors posing as TechCrunch reporters, editors, and event leads to solicit sensitive information. This trend of fraudulent outreach has reached a point where the publication is publicly warning businesses to exercise extreme caution when receiving media inquiries.

The Evolving Tactics of Impersonators
Fraudsters are leveraging the reputation of established media brands to gain access to proprietary corporate data. In the most common schemes, attackers adopt the identities of actual staff members, drafting professional-looking media inquiries that request introductory calls or interviews to discuss product updates and startup trends.
While recipients previously relied on spotting mismatched email domains to identify fakes, tactics have become increasingly deceptive. Scammers are now utilizing email conventions that mirror legitimate staff addresses. In some instances, they attempt to lure victims into phone interviews, using those sessions to extract deeper, non-public details about a company’s infrastructure or internal operations.
Industry observers, including former staff at Yahoo, suggest these campaigns are part of a persistent effort by threat actors to facilitate account takeovers (ATO) and large-scale data theft. These campaigns frequently target sectors such as cryptocurrency, cloud services, and general technology firms.
How to Verify Media Inquiries
To protect against these phishing attempts, companies are advised to move beyond blind trust when receiving outreach. TechCrunch recommends the following verification steps:
- Consult the Official Roster: Always cross-reference the sender’s name against the official TechCrunch staff page. If the individual is not listed, the inquiry is fraudulent.
- Analyze the Request Context: Even if a name appears on the staff page, assess the relevance of the request. For example, a copy editor likely would not be conducting primary reporting on new business product launches.
- Use Verified Communication Channels: If you harbor any doubt, reach out to the journalist via the contact methods explicitly listed on their official staff bio page rather than replying directly to the email in question.
Known Fraudulent Domains
TechCrunch has compiled a list of domains identified in recent months that have no affiliation with the publication. Organizations should configure their email security systems to flag or block communications originating from these sources:
email-techcrunch[.]com, hr-techcrunch[.]com, interview-techcrunch[.]com, mail-techcrunch[.]com, media-techcrunch[.]com, noreply-tc-techcrunch[.]com, noreply-techcrunch[.]com, pr-techcrunch[.]com, techcrunch-outreach[.]com, techcrunch-startups[.]info, techcrunch-team[.]com, techcrunch[.]ai, techcrunch[.]biz[.]id, techcrunch[.]bz, techcrunch[.]cc, techcrunch[.]ch, techcrunch[.]com[.]pl, techcrunch[.]gl, techcrunch[.]gs, techcrunch[.]id, techcrunch[.]it, techcrunch[.]la, techcrunch[.]lt, techcrunch[.]net[.]cn, techcrunch1[.]com
By maintaining vigilance and following these verification protocols, businesses not only protect their own proprietary information but also help maintain the integrity of the professional relationship between the media and the industries they cover.