OSINT Employee Screening and Pre-Employment Checks

OSINT employee screening tests what a candidate has told you against the public record: that the employers existed, the roles fit the dates, the person on the video call is the person on the CV, and nothing they left out will surprise you after the offer. We run it for senior, remote and high-trust hires, with consent and proportionality built in.

  • CV and career verification
  • Fake and proxy candidates
  • Overemployment and conflicts
  • FCRA and UK GDPR aware
Short answer

OSINT employee screening checks a candidate's identity, career, education and business interests against registries, company records, court files, media and public online sources. It finds inconsistencies that reference calls and database checks miss, such as invented employers, borrowed identities or undisclosed directorships. It does not replace official criminal record checks, right-to-work checks or the FCRA process for US hiring.

What OSINT Employee Screening Checks

Five questions that decide most screening outcomes. Each is answered from records the candidate cannot edit.

Identity

Is the candidate a real, consistent person?

Name, photos, contact details and history line up across independent sources, and are not borrowed from someone else.

Career

Did the jobs happen as described?

Employers exist, titles and dates are consistent with registries, press, conference talks and archived team pages.

Education

Are the degrees real?

Institutions are accredited and not degree mills; graduation claims fit what the institution publishes.

Conflicts

What else does the person run or own?

Directorships, shareholdings and side businesses that could compete with you or supply you.

Conduct

Is there public history that matters for the role?

Litigation, regulatory actions and relevant media, reviewed only where the role justifies it.

Fake Candidates and Remote-Hire Identity Fraud

Remote hiring has made it easier to apply under a borrowed or invented identity, and employers are now advised to verify identity throughout the process, not only at the offer.

  • In a 2025 Gartner survey of 3,000 job candidates, 6% admitted to interview fraud, either posing as someone else or having someone pose as them; Gartner predicts that by 2028, one in four candidate profiles worldwide will be fake (Gartner).
  • In 2025 the FBI reported that North Korean IT workers hired remotely had used AI and face-swapping in video interviews and reused phone numbers and email addresses across résumés. It advised employers to verify identity during interviewing, onboarding and throughout remote employment (FBI IC3).

OSINT looks for what fabricated identities lack: a history. We check whether the profile photo appears elsewhere under another name, whether the employment history leaves independent traces, and whether the phone number, email or portfolio link has been used by other applicants. If a case points to fraud against you, it can move into a fraud investigation or a cyber investigation.

Overemployment Checks on Remote Staff

Overemployed OSINT checks look for public signs that a full-time employee holds another full-time job. They are only appropriate when a contract or conflict policy is at stake and there is a specific, documented concern.

Holding two jobs is not unlawful in itself. It matters when it breaches an exclusivity clause, creates a conflict of interest or puts confidential work in a competitor's hands. A check focuses on public, work-related signals: professional profiles, company team pages, public code contributions, conference talks and press releases that place the same person in two roles at once.

This is a check on a current employee, so it is a form of monitoring under data-protection law and needs a documented reason and a proportionate scope; the ICO publishes separate guidance on monitoring workers. We do not monitor private accounts, devices or personal life, and we report findings so that your HR and legal teams can follow a fair process with the employee. Screening sits alongside the other OSINT services for HR and security teams we run, from background checks to fraud work.

OSINT Techniques for Employment Verification

Six steps, from a lawful purpose and candidate notice to a report your hiring manager can act on.

  1. Confirm the purpose and the noticeWe agree which roles justify screening, what will be checked and how candidates are told. In the US we confirm the FCRA steps before any work starts.
  2. Fix the identityFull name, former names, photo, contact details and stated history become the identifiers every finding is matched against.
  3. Verify the careerRegistries, archived web pages, press, publications and public code show whether each role left independent traces; degrees and licenses are checked against the institutions and registers.
  4. Review business interests and historyDirectorships, shareholdings, litigation and relevant media, in proportion to the role.
  5. Report job-relevant findings onlyA senior analyst reviews the report. Information that is not relevant to the role, including protected characteristics, is left out.

Which Check for Which Hiring Risk?

OSINT covers the gaps between the official checks. It does not replace them.

RiskPrimary toolWhat OSINT adds
Criminal recordUK: DBS, AccessNI or Disclosure Scotland. US: a criminal search ordered through the FCRA processReported cases and regulatory actions abroad, where the role justifies it
Right to workThe statutory right-to-work checkNothing; this is a legal process of its own
Borrowed or fake identityDocument and liveness verificationWhether the identity has a consistent public history
Invented career or degreeReferences and employer confirmationsIndependent traces of each role; degree-mill checks
Conflicts and side businessesCandidate declarationDirectorships and shareholdings in public registries

FCRA Consent and Adverse Action in the US

If a third party prepares a background report on a candidate or employee for a US employment decision, the FCRA applies: disclosure and written permission first, and notice before and after any adverse decision.

  • Before the check. Tell the person in writing, in a stand-alone document and not in the application, that a report may be used, and get their written permission (FTC).
  • Before an adverse decision. Send a pre-adverse action notice with a copy of the report and A Summary of Your Rights Under the Fair Credit Reporting Act.
  • After the decision. Send an adverse action notice naming the company that supplied the report and the person's right to dispute it.
  • Reference interviews. If the work includes interviews about character or reputation, it becomes an investigative consumer report, and the disclosure must go out no later than three days after the report is requested (15 U.S.C. §1681d).

State and city laws can add further limits on what may be asked and when. Your employment counsel should confirm the process for each location.

Social Media Screening Without Discrimination Risk

The risk is not looking at public profiles; it is letting protected characteristics you see there affect the decision. Separating the researcher from the decision-maker is the standard safeguard.

The EEOC has warned that a person's race, gender, general age and possibly ethnicity can usually be seen on social media, and that improper use of that information may be discriminatory. It also advised using only publicly available information and never asking for passwords (EEOC).

Our analysts review public profiles against a written list of job-related criteria, such as threats, harassment, disclosure of confidential information or conduct that contradicts the application, and pass on only those findings. Deeper work on accounts belongs to social media investigations.

UK Screening: DBS, Right to Work and UK GDPR

Criminal records in the UK come through official checks, not open-source research. OSINT screening has to be necessary, proportionate and disclosed to candidates.

DBS checks are the official route in England and Wales: a basic check shows unspent convictions and conditional cautions, a standard check shows spent and unspent convictions and cautions, and an enhanced check adds relevant local police information (GOV.UK). Standard and enhanced checks are limited to roles that meet DBS eligibility rules. From 5 October 2026 a basic or standard check costs £20 and an enhanced check £41 (DBS).

The ICO's draft guidance on pre-employment vetting says employers should vet only where there is a legal obligation or a significant and particular risk, should not routinely vet all candidates, must tell candidates about vetting and social media checks, and should keep the people researching social media apart from those making the decision (ICO). We scope UK screening to match.

OSINT Employee Screening: Specialized Services

Focused versions of employee screening for specific subjects, deals and situations.

Employee screening

Employment verification

Work history and credentials checked at the source: employers, roles and dates, degrees, professional licenses and references.

Read more →
Employee screening

Remote candidate verification

Checks for proxy interviews, stolen identities, AI-generated profiles and deepfake interviews in remote hiring, run lawfully and consistently.

Read more →
Employee screening

Overemployment checks

Lawful, proportionate checks of public work-related signals when a specific concern suggests an employee holds an undisclosed second job.

Read more →

Screen Your Next Senior or Remote Hire

Tell us the role, the location and your offer date. We confirm the lawful steps, the scope and a fixed quote. Focused checks take from 10 business days.

OSINT Employee Screening FAQ

We're hiring a remote senior engineer based in another country — can OSINT employee screening confirm she really worked at the three companies on her CV, and do we need her consent first?

Yes to both, in most cases. OSINT employee screening looks for independent traces of each role: company registries, archived team pages, conference talks, publications and public code. Consent depends on where you hire: the FCRA requires written disclosure and permission in the US, and UK and EU candidates must be told about vetting. We confirm the steps before we start.

During last week's video interview our candidate's face seemed to lag behind his voice and his professional profile is only four months old — how can we check whether he is a fake candidate before sending an offer?

We check whether the identity has a history. That means searching for the profile photo under other names, testing the phone number, email and portfolio links against other applications and public records, and looking for independent traces of the employers he lists. If the identity does not hold up, you will know before the offer.

I suspect one of our full-time remote developers is overemployed and secretly working a second full-time job for a competitor — can you check that from public sources without breaking employment or privacy laws?

Often, if there is a contractual reason and a specific concern. We look only at public, work-related signals, such as professional profiles, company pages, public code contributions and press, that place the same person in two roles. We do not monitor private accounts or devices. Because this is a check on a current employee, document the reason and involve HR and legal so any next step follows a fair process.

Our US company ordered a screening report and it flagged something on a candidate we liked — what exactly do we have to send them before we withdraw the offer under the FCRA?

Before deciding, send a pre-adverse action notice with a copy of the report and the FTC's Summary of Your Rights Under the Fair Credit Reporting Act, so the candidate has a chance to review it and explain any negative information. If you then withdraw the offer, send an adverse action notice that names the company that supplied the report and explains the right to dispute it. Check state and city rules too.

Our recruiters like to scroll through candidates' Instagram and X accounts before interviews — is that a discrimination risk with the EEOC, and is there a safer way to handle social media screening?

Yes, it is a risk. The EEOC has noted that race, gender, age and other protected traits are often visible on social media, and improper use may be discriminatory. The safer way is to have someone outside the hiring decision review public profiles against written, job-related criteria and pass on only relevant findings. That is how we run social media screening.

We're a UK charity hiring someone to work with children — can an OSINT check replace the DBS check, or do we still need an enhanced DBS check as well?

You still need the official check. An enhanced DBS check, with a barred list check where the role qualifies, is the legal route for criminal records and safeguarding information in England and Wales; an OSINT check cannot replace it. OSINT can add context the DBS does not cover, such as roles abroad, where that is necessary and the candidate has been told.

Our offer deadline for a new finance director is next Friday — how long does pre-employment OSINT screening normally take for a senior hire, and can you do it faster?

A focused check takes from 10 business days, and a multi-country senior hire can take up to about a month. If the deadline is shorter, urgent delivery is possible for a 50% surcharge, and some narrow questions, such as confirming one employer or one directorship, can sometimes be answered in a business day. The quote fixes the date, and the fee goes down if we miss it.

Can we just run OSINT checks on every applicant who applies to us to be safe, or does UK GDPR require us to limit who gets checked and at what stage?

UK GDPR expects you to limit it. The ICO's draft guidance says employers should not routinely vet all candidates unless legally required, should vet only where there is a significant and particular risk, and should obtain criminal records only for the person they intend to appoint. In practice, screen preferred candidates for roles that justify it, and tell them in advance.