Skip to main content
Blog
Blog

Applicant fraud detection software: identifying fake job applicants before they are hired

Applicant fraud detection software flags fake job applicants by analyzing device, network, and location signals during the application session.

Jul 24, 2026 5 min read
Applicant fraud detection software: identifying fake job applicants before they are hired

TL;DR: sanctioned-jurisdiction remote hire session screening

  • Identity verification confirms the passport is real, not that the person holding it is in a jurisdiction you can legally hire from. Veriff and Persona will hand you a green tick for an application session routing through three VPN hops.
  • cside pairs device fingerprinting with TLS handshake fingerprint TLS for VPN and proxy detection and cross-application device linkage, so a dozen resumes under different names arriving from one device fingerprint stop being a coincidence.
  • If your recruiting funnel loses hours to interviews with North Korean IT-worker fronts, screen at application submission. If your roles are all in-office with witness signature, do not bother.

Applicant fraud detection software analyzes the device, network, and location signals present in a job application session to identify fraudulent applicants, including state-sponsored remote workers using fabricated identities. Background checks and identity verification validate the identity an applicant presents, but they cannot tell you whether the device submitting the application sits in a sanctioned jurisdiction, or whether it is the same device behind a dozen other applications filed under different names.

Applicant fraud is the submission of fraudulent job applications using fabricated, stolen, or manipulated identities. It spans a range of threat actors: individuals using false credentials to obtain employment they would not otherwise qualify for, organized fraud rings submitting applications at scale to extract data from hiring systems, and, at the most serious end, state-sponsored programs in which workers from sanctioned jurisdictions apply for legitimate remote positions under false identities to generate revenue for their governments.

Standard hiring controls (resume review, reference checks, and identity verification) validate the information presented. They do not analyze the device and network signals present during the application session, which reveal patterns that fabricated identities cannot hide.

ToolAnalyzes session device signalsDetects sanctioned-jurisdiction connectionsIdentifies coordinated campaignsIdentity document checkFree tier
csideYes, browser-layer hardware + network signalsYes, TLS handshake fingerprint TLS + device fingerprintYes, linked device across applicationsNo (complements IDV tools)Yes, 1,000 API calls/mo
Identity verification (Veriff, Persona)NoNoNoYesNo
Background check platformsNoNoNoYesNo

The state-sponsored applicant fraud problem

The most serious form of applicant fraud targeting tech companies in 2026 involves workers from sanctioned nations, specifically North Korea, applying for remote software development, design, and support roles under fabricated identities. These applicants submit genuine-quality resumes with plausible work histories, pass initial screening, and obtain employment at organizations that cannot legally employ nationals from sanctioned jurisdictions.

The device signals that reveal these applications are consistent across the threat: applications submitted from specific geographic clusters, VPN and proxy connections routing application sessions through third countries, device fingerprints and network characteristics that cluster around specific infrastructure, and often a single physical location behind dozens of distinct identity applications.

Identity verification tools confirm that a provided identity document matches the person presenting it. They do not determine whether the person presenting it is physically in a sanctioned jurisdiction, whether the device is shared across multiple identity applications, or whether the network connection is routing through an anonymizing layer to conceal a true location.

cside: device and network signal analysis for applicant screening

cside applicant fraud detection analyzes the browser session during a job application the same way it analyzes any other high-value interaction: device fingerprint, TLS handshake fingerprint TLS fingerprinting for VPN and proxy detection, network characteristics, and behavioral signals.

The signals most relevant to applicant fraud are:

  • Geographic consistency: whether the device and network signals match the location the applicant claims.
  • Connection type: whether the application session routes through a VPN or proxy that may be concealing a true origin.
  • Cross-application device linkage: whether the same device fingerprint appears behind multiple applications with different identity credentials.

A cluster of applications from different identities arriving via the same device fingerprint, with network signals consistent with a specific geographic region, is not a coincidence. cside returns these signals via API for each application session, so your hiring team can flag applications for additional review before investing screening resources.

Identity verification platforms

Identity verification platforms like Veriff and Persona confirm that an applicant's submitted identity document is genuine and matches the person presenting it in a live selfie or video check. They are an important baseline control for roles that require identity confirmation.

Identity verification addresses whether the identity being presented is real. It does not address whether the person presenting that identity is in a permitted jurisdiction, whether the device submitting the application is the same device behind other applications with different identities, or whether the network signals during the session are consistent with the declared location. Device and network signal analysis by cside answers these questions and is complementary to, not a substitute for, identity verification.

Background check platforms

Background check platforms verify employment history, criminal records, credential validation, and in some cases sanctions screening. They operate on the identity the applicant presents and the historical records associated with it.

They do not analyze the device from which the application was submitted or the network signals present during the application session. A fabricated identity that passes a background check, because the underlying records are either clean or falsified, remains undetectable by background screening alone. Device signal analysis is the complementary control that operates at the session layer rather than the identity layer.

Further reading

Mike Kutlu
Client-Side Security Consultant

Client-side security consultant at cside. 10+ years of experience implementing technology solutions for enterprises (previously at Oracle, Cloudflare, and Splunk). Now helping teams use client-side intelligence to catch & reduce fraud.

FAQ

Frequently Asked Questions

Applicant fraud detection software analyzes the device, network, and session signals present when a job application is submitted. It identifies patterns that fabricated or fraudulent identities cannot hide: applications from devices linked to other fraud attempts, sessions routing through VPNs that conceal a sanctioned-jurisdiction origin, and clusters of applications from the same physical device using different identity credentials. It complements, rather than replaces, identity verification and background screening.

cside analyzes the device fingerprint, TLS handshake fingerprint TLS fingerprint, and network characteristics of the application session. Applications originating from specific geographic clusters, routing through VPNs or proxies that conceal a true origin, or submitted from devices that appear across multiple applications with different identities are flagged for additional review. These signals are consistent across coordinated state-sponsored application campaigns even when the identity documents presented are of high quality.

No. Identity verification confirms that a presented document is genuine and matches the person presenting it. cside's applicant fraud detection analyzes the session device and network signals that reveal whether the person presenting that identity is in a permitted jurisdiction and whether their device is linked to other fraudulent applications. Both controls are needed: identity verification at the identity layer, device and network analysis at the session layer.

The most operationally efficient point is during the initial application submission, before any recruiter or hiring manager time is invested. cside returns device and network signals via API during the application session, allowing automated flagging of high-risk applications for additional review before the hiring process begins. This concentrates screening resources on the applications most likely to be genuine.

Monitor and Secure Your Third-Party Scripts

Gain full visibility and control over every script delivered to your users to enhance site security and performance.

Start free, or try Business with a 14-day trial.

cside dashboard interface showing script monitoring and security analytics
Related Articles
Book a demo