Someone appears to be using my name, location, and GitHub profile to create false trust with clients who specifically want to hire developers based in the United States. They invited me to participate in this arrangement, but I have no interest in lending my identity or profile to mislead anyone. It seems like clients could be scammed, and I'm concerned this may violate platform rules or the law. What is the proper way to report this, and what evidence should I preserve?
2 Answers
Make sure your own account is secured first: enable 2FA, use a unique strong password, review active sessions and authorized applications, and check recovery settings. If your profile was copied rather than hacked, report the duplicate account and explain that it is using your identity without permission.
Don’t accept the offer or provide access to your accounts. Save the invitation, sender details, profile links, screenshots, and any messages, then report the impersonation through GitHub’s support or abuse channels. If someone is actually defrauding clients, you can also contact the appropriate cybercrime or consumer-protection authority in your jurisdiction.

Exactly. A long password helps, but 2FA and reviewing connected apps are important too, especially if the account contains public work or personal details.