Key takeaway: Fake job applicants are not a resume-padding problem. For remote roles they are an identity problem: the person who interviews may not be the person who applied, and the person who starts work may not be either. The fix is a staged verification process that re-confirms identity at application, interview, and onboarding, checks network and location signals against what the candidate claims, and forces live, unscripted work. The seven steps below are tool-independent and take about 25 extra minutes per finalist.

Remote hiring removed the one control every company used to have for free: meeting the candidate. The FBI's Internet Crime Complaint Center warned in June 2022 that complaints were rising about applicants using deepfake video and stolen personally identifiable information to apply for remote IT, programming, and database roles, often positions with access to customer PII and financial data (FBI IC3 PSA I-062822, June 28, 2022).

The scale has grown since. CrowdStrike attributed 304 incidents in 2024 to the North Korea-linked group it tracks as FAMOUS CHOLLIMA, about 40% of them insider-threat operations in which adversaries "operate under the guise of legitimate employment" (CrowdStrike 2025 Global Threat Report, February 27, 2025). Gartner projects that by 2028 one in four job candidates globally will be fake, a figure CNBC reported alongside the case of Pindrop catching a deepfaked applicant it nicknamed "Ivan X" in a senior engineering interview (CNBC, April 8, 2025).

Recruiting teams describe the same thing from the inside: inbound volume on remote postings is high, and a meaningful share of it is fraudulent or unqualified, which is where screening hours go. This guide is about the fraudulent share. It covers who the fake applicants are, the signals that separate them from legitimate candidates, and a verification workflow that works regardless of which ATS or screening tools you use. For the broader catalogue of resume and reference red flags, see our companion piece on how to tell if a candidate is fraudulent.

What counts as a fake job applicant?

"Fake applicant" covers four different actors, and they need different detection methods.

Type What they are doing Typical goal Primary detection layer
Identity impostor Applying under a stolen or synthetic identity, often with a deepfaked or proxy interview Salary, system access, data theft Identity re-verification at every stage
Proxy interviewee Real identity, but someone else answers technical questions live or via earpiece Get hired, then underperform or outsource Live, unscripted problem-solving
Credential fabricator Real person, invented degrees, employers, or dates Get past the screen Employment and education verification on primary sources
Laptop-farm worker Real hire whose company device is shipped to and operated by a third party Sustained revenue for an organized group Post-hire network and device monitoring

The first and last rows are the ones the FBI keeps issuing alerts about. In January 2025 the Bureau reported that North Korean IT workers, once discovered on company networks, had escalated to extortion, holding stolen code and proprietary data for ransom and in some cases publicly releasing it (FBI IC3 PSA, January 23, 2025). The same alert lists the operational tells: multiple logins to one account from different countries in a short window, and endpoint software that allows several audio and video calls to run concurrently.

The credential fabricator is the most common and least dangerous. Treat them with normal reference and verification hygiene. The rest of this article focuses on the impostor and proxy cases, because those are the ones that standard screening was never built to catch.

Why do remote roles attract fraudulent candidates?

Three properties of remote hiring make it the target of choice.

First, the process is asynchronous and distributed. Different people run the resume screen, the recruiter call, the technical interview, and onboarding, and nobody compares notes on whether the face and voice matched across stages. A candidate can clear most of the process before anyone notices the inconsistency.

Second, the payoff is access, not just salary. The 2022 FBI alert specifically flagged that targeted roles included access to customer PII, financial data, and corporate IT databases. A fake hire in a remote engineering seat gets credentials on day one.

Third, the tooling to fake it is now consumer grade. The New York State Bar Association's May 2026 analysis notes that Experian's 2026 Future of Fraud Forecast ranked "deepfakes will outsmart human resources" as the second-highest fraud threat of the year, predicting employers will onboard people who are not who they claim to be at a much larger scale (NYSBA, May 5, 2026).

None of this argues against remote hiring. It argues for treating identity as something you verify repeatedly, the way security teams treat authentication, rather than once at the top of the funnel.

What signals separate fake applicants from real ones?

No single signal is conclusive, and several of them (VPN use, a recent LinkedIn profile, a quiet online footprint) describe plenty of honest candidates. The pattern is what matters: fraud tends to trip three or four of these at once.

Stage Signal Why it matters How to check
Application Disposable or newly created email domain Synthetic identities are assembled quickly Domain age lookup; flag, do not reject
Application Connection from a VPN or datacenter IP while claiming a US home address Location laundering Check the applicant's IP class in your ATS or form tool
Application Resume text that is near-identical to other applicants for the same role Fraud rings reuse templates Duplicate-text check across the applicant pool
Application Stated location, timezone of activity, and phone area code disagree Three independent location claims should agree Compare timestamps on emails and form submissions to the stated timezone
Screen Professional footprint that begins in the last 12 months with no earlier trace Real 10-year careers leave a trail: conference talks, old profiles, commits, patents Search the name plus former employers; look for anything older than a year
Screen Employers that cannot be independently confirmed or references on free email domains Fabricated history Verify with the company's main line or HR, not the number on the resume
Interview Lip movement and audio that drift out of sync, or coughs and gestures that do not match the sound The FBI's 2022 alert lists this as the tell for deepfaked video Ask the candidate to turn their head, wave a hand in front of their face, or stand up
Interview Long pauses before every technical answer, eyes tracking off-screen, or answers that sound read Proxy or AI assistance Interrupt with a follow-up mid-answer; ask them to reason aloud
Interview Refusal to turn on camera, or "camera broken" on every call Removes the identity check entirely Make camera-on a stated requirement for remote finalists
Offer Request to ship the laptop to a different address than the one on the application Laptop-farm setup Ship only to the verified address; require ID at delivery
Onboarding Multiple logins from different countries within hours, or remote desktop tools installed on day one The January 2025 FBI alert calls these out by name Alert on impossible travel and unapproved remote-access software

The right response to any one flag is a follow-up question, not a rejection. The right response to three is to move identity verification forward in the process and slow down until it clears.

How do you verify a remote candidate is who they say they are?

Here is the workflow. It is deliberately independent of any vendor, so a team can run it with an ATS, a video tool, and a spreadsheet.

  1. Publish the verification steps in the job posting. State that finalists will complete a live video interview with camera on, a government ID check before offer, and that equipment ships only to a verified address. Honest candidates do not mind; impostors frequently self-select out.

  2. Confirm the professional footprint predates the application. Before the recruiter screen, spend five minutes looking for evidence of the candidate's career that is more than a year old: a conference bio, an old company page, a commit history, a patent, a news mention. Most real senior candidates leave something. A footprint that appears fully formed in the last few months is the strongest early flag.

  3. Verify employment on primary sources. Call the former employer's main line or HR department, not the reference number the candidate supplied. Ask for dates and title only. This takes ten minutes per finalist and catches most fabricated histories. Our guide to structured screening calls covers how to fold this into the recruiter screen.

  4. Run every interview camera-on with at least one unscripted movement. Ask the candidate to turn their head fully to one side, pass a hand in front of their face, or hold up an object. Current real-time face-swap tools handle a static, front-facing head well and handle occlusion and profile views poorly. Note in the interview record that the check was done, so the next interviewer knows the face they see should match.

  5. Interview for reasoning, not answers. Replace "explain how you would design X" with a live problem the candidate has not seen, and interrupt partway through with a constraint change. Proxy interviewees and candidates relaying answers from a second screen fall apart when the question moves. Our piece on detecting AI cheating tools in interviews goes deeper on question design.

  6. Match identity across stages, then verify ID before the offer. Assign one person to compare the face and voice from the recruiter screen, the technical interview, and the final round. Before the offer, complete Form I-9 verification the way your counsel prescribes, and confirm the name, date of birth, and address on the ID match the application. If you outsource this step, our review of background check services covers which vendors include identity verification.

  7. Treat onboarding as the last checkpoint. Ship equipment only to the verified address, require the new hire to appear on camera at first login, and have IT alert on logins from multiple countries and on unapproved remote-desktop software in the first 30 days. These are the two monitoring tips the FBI's 2025 alert leads with, and they catch the laptop-farm case that every earlier step can miss.

Steps 1 through 6 add roughly 25 minutes per finalist. Step 7 is IT policy that should exist anyway.

What does this process cost, and where does it break?

The most common failure is applying the process unevenly. Teams add identity checks to engineering roles, where the FBI alerts are focused, and skip them for finance, customer support, and data roles that also carry access. Apply the same finalist checks to every remote role with system or data access.

The second failure is treating flags as rejections. VPN use, a thin online presence, and a new email address describe many legitimate candidates, especially international ones and career changers. Regulators are clear that employment screening must be applied consistently and lawfully; use the flags to decide where to verify harder, and document the decision.

The third is stopping at the offer. Almost every publicized North Korean IT worker case was discovered after hire, through network behavior. If your process ends when the contract is signed, you have verified the applicant and not the employee.

How does Noon help teams filter fraudulent applicants?

Everything above works without Noon. What Noon changes is how much of it happens automatically, and on how many applicants.

For inbound roles, Noon's Inbound Screening pulls applications from connected ATSes several times a day and ranks every applicant against the role's criteria and non-negotiables, so the fraudulent and unqualified share stops consuming recruiter hours before a human opens the queue. Noon's Fraud Detection runs as a layered system across every applicant: network signals (VPN and datacenter connections), identity-location signals (stated location versus observed timezone), email signals (disposable or throwaway domains), and professional-footprint signals are correlated rather than checked in isolation. Flagged applicants are marked, never hidden, with the specific signals that triggered the flag, and a recruiter can override the call. Flags persist across roles, so an applicant caught on one posting does not get a clean slate on the next.

For outbound roles the exposure is different. Candidates Noon's AI Sourcer finds are identified from their public professional footprint rather than a self-submitted resume, their full career history is evaluated before contact, and every email address is verified before outreach goes out, so the "footprint that appeared last month" case rarely enters the pipeline at all. Shifting a remote role's pipeline toward sourced candidates is itself a fraud control; our comparison of outbound versus inbound recruiting explains why.

Noon is not an identity verification or background check service. Steps 4, 6, and 7 above still belong to your interviewers, your I-9 process, and your IT team. If you want to see how the flagging and ranking work on a live requisition, book a demo.

Frequently asked questions

How do you identify fake candidates? Look for clusters of signals rather than any single one: a professional footprint that begins in the last year, a VPN or datacenter connection paired with a claimed US address, disposable email domains, resume text duplicated across applicants, and references that cannot be verified through the employer's main line. Then confirm identity live: camera on, an unscripted head turn or hand pass during the interview, and an ID check before the offer.

Does the platform offer fraud detection for inbound applicants? Noon does. Every inbound applicant is checked for VPN or datacenter connections, location and timezone mismatches, and throwaway email domains, with signals correlated into an explainable flag that shows the reviewer what triggered it. Flagged applicants stay visible and can be overridden. Details are on the Fraud Detection page.

How do you spot a deepfake in a video interview? The FBI's 2022 alert describes the reliable tell: lip movement and audio that do not fully coordinate, and sounds like coughing or sneezing that do not match what is on screen. Add active checks. Ask the candidate to turn their head to profile, pass a hand across their face, or hold up a nearby object. Real-time face-swap tools still struggle with occlusion and profile views.

Are fake applicants only a problem for engineering roles? No. Engineering roles draw the most public attention because the FBI's alerts focus on IT workers, but any remote role with access to customer data, payment systems, or internal databases is a target. Finance operations, customer support with account access, and data analyst roles should run the same finalist checks.

Can we reject a candidate because they use a VPN or have a small online presence? Not on that basis alone. Both describe many legitimate candidates. Use those signals to decide where to verify more carefully, apply the same checks to every finalist for the role, and document the outcome. Consistency protects both the candidate and the company.

What should IT monitor after a remote hire starts? The FBI's January 2025 guidance leads with two items: multiple logins to one account from different countries within a short period, and the installation of remote desktop software or tools that allow several concurrent audio and video calls. Alert on both for at least the first 30 days, apply least-privilege access, and ship equipment only to the verified address on file.