TL;DR: sanctioned-jurisdiction remote hire session screening
- Identity verification confirms the passport is real, not that the person holding it is in a jurisdiction you can legally hire from. Veriff and Persona will hand you a green tick for an application session routing through three VPN hops.
- cside pairs device fingerprinting with TLS handshake fingerprint TLS for VPN and proxy detection and cross-application device linkage, so a dozen resumes under different names arriving from one device fingerprint stop being a coincidence.
- If your recruiting funnel loses hours to interviews with North Korean IT-worker fronts, screen at application submission. If your roles are all in-office with witness signature, do not bother.
Applicant fraud detection software analyzes the device, network, and location signals present in a job application session to identify fraudulent applicants, including state-sponsored remote workers using fabricated identities. Background checks and identity verification validate the identity an applicant presents, but they cannot tell you whether the device submitting the application sits in a sanctioned jurisdiction, or whether it is the same device behind a dozen other applications filed under different names.
Applicant fraud is the submission of fraudulent job applications using fabricated, stolen, or manipulated identities. It spans a range of threat actors: individuals using false credentials to obtain employment they would not otherwise qualify for, organized fraud rings submitting applications at scale to extract data from hiring systems, and, at the most serious end, state-sponsored programs in which workers from sanctioned jurisdictions apply for legitimate remote positions under false identities to generate revenue for their governments.
Standard hiring controls (resume review, reference checks, and identity verification) validate the information presented. They do not analyze the device and network signals present during the application session, which reveal patterns that fabricated identities cannot hide.
| Tool | Analyzes session device signals | Detects sanctioned-jurisdiction connections | Identifies coordinated campaigns | Identity document check | Free tier |
|---|---|---|---|---|---|
| cside | Yes, browser-layer hardware + network signals | Yes, TLS handshake fingerprint TLS + device fingerprint | Yes, linked device across applications | No (complements IDV tools) | Yes, 1,000 API calls/mo |
| Identity verification (Veriff, Persona) | No | No | No | Yes | No |
| Background check platforms | No | No | No | Yes | No |
The state-sponsored applicant fraud problem
The most serious form of applicant fraud targeting tech companies in 2026 involves workers from sanctioned nations, specifically North Korea, applying for remote software development, design, and support roles under fabricated identities. These applicants submit genuine-quality resumes with plausible work histories, pass initial screening, and obtain employment at organizations that cannot legally employ nationals from sanctioned jurisdictions.
The device signals that reveal these applications are consistent across the threat: applications submitted from specific geographic clusters, VPN and proxy connections routing application sessions through third countries, device fingerprints and network characteristics that cluster around specific infrastructure, and often a single physical location behind dozens of distinct identity applications.
Identity verification tools confirm that a provided identity document matches the person presenting it. They do not determine whether the person presenting it is physically in a sanctioned jurisdiction, whether the device is shared across multiple identity applications, or whether the network connection is routing through an anonymizing layer to conceal a true location.
cside: device and network signal analysis for applicant screening
cside applicant fraud detection analyzes the browser session during a job application the same way it analyzes any other high-value interaction: device fingerprint, TLS handshake fingerprint TLS fingerprinting for VPN and proxy detection, network characteristics, and behavioral signals.
The signals most relevant to applicant fraud are:
- Geographic consistency: whether the device and network signals match the location the applicant claims.
- Connection type: whether the application session routes through a VPN or proxy that may be concealing a true origin.
- Cross-application device linkage: whether the same device fingerprint appears behind multiple applications with different identity credentials.
A cluster of applications from different identities arriving via the same device fingerprint, with network signals consistent with a specific geographic region, is not a coincidence. cside returns these signals via API for each application session, so your hiring team can flag applications for additional review before investing screening resources.
Identity verification platforms
Identity verification platforms like Veriff and Persona confirm that an applicant's submitted identity document is genuine and matches the person presenting it in a live selfie or video check. They are an important baseline control for roles that require identity confirmation.
Identity verification addresses whether the identity being presented is real. It does not address whether the person presenting that identity is in a permitted jurisdiction, whether the device submitting the application is the same device behind other applications with different identities, or whether the network signals during the session are consistent with the declared location. Device and network signal analysis by cside answers these questions and is complementary to, not a substitute for, identity verification.
Background check platforms
Background check platforms verify employment history, criminal records, credential validation, and in some cases sanctions screening. They operate on the identity the applicant presents and the historical records associated with it.
They do not analyze the device from which the application was submitted or the network signals present during the application session. A fabricated identity that passes a background check, because the underlying records are either clean or falsified, remains undetectable by background screening alone. Device signal analysis is the complementary control that operates at the session layer rather than the identity layer.








