Fake Job Applicant Identity Verification: Remote Candidate OSINT Checks

Fake job applicant identity verification answers a question remote hiring has made urgent: is the person on the video call the person on the CV, and does that person exist? We test whether a remote candidate's identity has a real, consistent history, before you send a laptop and grant access to your systems.

  • Proxy and stand-in interviews
  • Stolen and borrowed identities
  • AI-generated profiles and deepfakes
  • Same checks for every candidate
Short answer

Fake job applicant identity verification checks whether a remote candidate's name, photo, contact details, employers and online profiles belong to one real person with a consistent history. It looks for reused photos, shared phone numbers and résumé text across applicants, invented employers and profiles that appeared recently. It complements document and liveness checks; it does not replace them.

Four Kinds of Remote-Hire Identity Fraud

Each one fails a different test, so the check is built to cover all four.

Proxy

Proxy interviews

A more skilled person interviews in the candidate's place, or feeds answers in real time, and someone else turns up for the job.

Stolen

Stolen identities

A real person's name, date of birth and history are used to apply. The victim often learns of it only when a background check comes back.

Synthetic

AI-generated profiles

Generated headshots, invented employers and a professional profile a few months old, built to pass a recruiter's first look.

Deepfake

Deepfake interviews

Face-swapping or voice spoofing on a live video call, sometimes by organized groups placing workers in many companies at once.

What the FBI Has Warned Employers About

The FBI's Internet Crime Complaint Center has published several public service announcements on fake remote applicants since 2022, each with warning signs employers can check.

  • Deepfakes and stolen PII (June 2022). In PSA I-062822-PSA, Deepfakes and Stolen PII Utilized to Apply for Remote Work Positions, the FBI reported more complaints of deepfakes and stolen personal information used to apply for remote IT, programming, database and software roles, some with access to customer data or financial systems. Signs included lip movements out of step with the audio, and coughs or sneezes that did not match the video (FBI IC3).
  • North Korean IT workers (October 2023). PSA I-101823-PSA, Additional Guidance on the Democratic People's Republic of Korea Information Technology Workers, lists red flags such as unwillingness to appear on camera, online profiles that do not match the résumé, several profiles with one identity and different photos, and laptops shipped to freight-forwarding addresses. It advises employers to run their own background checks when a staffing firm cannot show its process (FBI IC3).
  • Data extortion (January 2025). PSA I-012325-PSA, North Korean IT Workers Conducting Data Extortion, advises identity verification during interviewing and onboarding, cross-checking HR systems for other applicants with the same résumé content, and looking for phone numbers and emails reused across résumés (FBI IC3).

OSINT covers the parts of that advice that depend on outside records: whether an identity, a photo or a contact detail has a history elsewhere.

Fake Applicant Warning Signs and the OSINT Check for Each

A warning sign is a reason to check, not a finding. Each one maps to a test against independent records.

Warning signOSINT check
Professional profile only months old, few real connectionsWeb archives and other platforms for earlier traces of the same person
Headshot looks too polished or genericReverse image search for the photo under other names; signs of a generated face
Same phone, email or portfolio as another applicantCross-check against your applicant records and public postings
Employers that leave no traceRegistries, archived team pages and press for each employer and role
Identity details match a real person living elsewherePublic records and profiles of the real person, to test for a stolen identity
Equipment shipping address differs from the stated homeWhether the address is residential, commercial or a freight forwarder

Our analysts work only with public and lawfully available sources: no fake profiles, no pretexting calls and no purchased leaked data. When a case points to deliberate fraud or a network placing workers, it can move into a fraud investigation or an insider threat investigation.

How OSINT Checks Fit Your Remote Hiring Funnel

Light checks early, a full identity review before the offer, and a consistency check at onboarding, each applied the same way to every candidate at that stage.

  1. Set a written policyWhich roles, at which stage, with which checks, applied to every candidate for that role. In the US, FCRA disclosure and written authorization come first if we prepare the report.
  2. ShortlistConsistency of name, photo, contact details and profiles across sources.
  3. Before the offerEmployers and roles traced, the identity tested for a history, and duplicates checked against other applicants.
  4. OnboardingThe person, address and accounts at onboarding match the identity that was verified.
  5. ReportA senior analyst reviews the findings, with the sources behind each one.

Lawful, Non-Discriminatory OSINT Identity Checks

Fraud checks must not become a filter on nationality, accent or foreign education. The defense is a consistent process, job-related criteria and documented findings.

  • National origin and citizenship. The Justice Department's Immigrant and Employee Rights Section enforces the ban on citizenship-status and national-origin discrimination in hiring and on unfair documentary practices in employment eligibility verification (DOJ). Do not ask some candidates for more documents than others.
  • Protected characteristics online. The EEOC has warned that race, gender, age and other protected traits are often visible on social media and that improper use may be discriminatory (EEOC). We report only identity and job-related findings.
  • Consent and notice. A third-party report for a US hiring decision is a consumer report under the FCRA (FTC). In the UK and the EU, candidates must be told about the checks.

The full screening process, including FCRA adverse action and UK rules, is set out on the parent employee screening page. For the career claims themselves, see employment verification; for the rest of our OSINT services for security teams, see the home page.

Check the Candidate Before You Ship the Laptop

Tell us the role, the stage you are at and what worried you. We reply with a scope, a delivery date and a fixed quote. Narrow identity questions can sometimes be answered in one business day.

Remote Candidate Verification FAQ

We think a remote developer applicant may be using a fake identity — what does fake job applicant identity verification actually check, and can you do it before our final interview on Thursday?

Fake job applicant identity verification checks whether the name, photo, phone, email, employers and profiles belong to one real person with a history. We search the photo under other names, test contact details against other applicants and public records, and trace each employer. Narrow questions can sometimes be answered in one business day; a full review takes from 10 business days.

During our video interview the candidate's lips didn't quite match his voice and he refused to turn his camera back on after a "connection problem" — is that a deepfake, and what should we do next?

It may be. The FBI has listed lip movements out of sync with audio and unwillingness to appear on camera as warning signs. Do not decide on that alone: record your observations, ask for a further live interview with identification shown on camera, and have the identity checked against independent records before any offer.

Our staffing agency supplied three contractors who all have similar résumés and only new professional profiles — can you check whether they are real people and whether the agency vetted them?

Yes. We test each identity for a history, compare résumé text, phone numbers, emails and photos across the three, and check the agency's own registration and track record. The FBI advises employers to run their own checks if a staffing firm cannot show its background check process, and to vet the individuals it supplies.

I'm worried that checking remote candidates for fraud could look like we're discriminating against applicants from other countries — how do we keep these checks lawful and fair?

Apply the same checks to every candidate for the role at the same stage, write the criteria down, and act only on identity and job-related findings. Do not ask some applicants for extra documents in the eligibility process, and keep nationality, accent and foreign education out of the decision. Separating the researcher from the decision-maker helps.

We already hired someone who now seems to be a different person from the one we interviewed, and he has access to our code — can your check help, or is this a security incident?

Both. Treat it as a security incident first: limit access and preserve logs with your IT team and counsel. We can then compare the hired person's identity, accounts and public traces with the interviewed one, and the work can move into an insider threat or fraud investigation. Report it to the FBI's IC3 if you are in the US.

We suspect a remote candidate is lying about where he lives — can your analysts create a fake recruiter profile to chat with him and find out where he really is?

No. We do not use fake profiles, pretexting or purchased leaked data. We work from public and lawfully available sources, and tell you which lawful steps can settle what open sources cannot, such as an in-person identity check, a notarized document or a live interview with identification shown on camera.