Hiring has gone remote-first, and so has hiring fraud. A fake job applicant is no longer just someone who padded a resume. It is often a fabricated or stolen identity, an interview answered by a stand-in, or, in the most organized cases, a state-sponsored operator working from another country while appearing to sit in your city. If you want to know how to prevent fake job applicants, the honest answer is that no single check does it. You layer identity verification, device intelligence, and disciplined process so a fake applicant has to beat all three at once.
This guide walks through how companies detect fake job applicants today, the concrete steps to prevent them, the red flags worth escalating, and where device intelligence fits into the application itself.
Why fake job applicants are a growing problem
Three forces made this worse at the same time. Remote work removed the in-person moment that used to expose an impostor. Generative AI made fabricated resumes, cover letters, headshots, and even live video convincing. And organized groups turned it into a business.
The most documented example is the North Korean IT worker scheme. Operators apply for remote engineering roles at Western companies using stolen or fabricated identities, then work from outside the country while appearing to be local. The playbook has recognizable moving parts:
- A laptop farm. A facilitator, often based in the target country, receives the company-issued laptop and keeps it running at their home, so the shipping address and the on-network location look domestic. Our explainer on what a laptop farm is covers the mechanics.
- A VPN or proxy to mask origin. The real operator connects through a VPN, proxy, or residential proxy so their network location matches the fake identity's stated location instead of their own.
- Remote-control software. Tools like remote desktop or screen-sharing utilities let the operator abroad drive the domestic laptop, so the traffic looks local even though the person is not.
- Interview proxies and deepfakes. A different, more fluent person may sit the interview, or a real-time face swap stands in for the applicant on camera.
US authorities, including the FBI and the Department of Justice, have issued repeated advisories about this scheme, and it is not limited to nation-state actors: ordinary fraud rings use the same tools to place unqualified people into paid roles or to get a foot inside a company. For more on the specific state-sponsored angle, see our post on North Korean actors attempting to infiltrate technology companies.
How do companies detect fake job applicants?
Detection works when you stop relying on any one signal. The teams that catch fakes reliably combine three layers:
- Identity verification. Confirm the person is real, and that they match their documents and their claimed history.
- Device and network intelligence. Read how the applicant actually connects, virtual machine, VPN or proxy, anti-detect browser, remote-control software, one device behind many identities, during the application and the interview.
- Process controls. Live video, unannounced re-checks, and cross-referencing of addresses and contact details, run by a human who knows what a mismatch looks like.
A fabricated applicant can usually defeat one layer. Defeating all three, consistently, across a full hiring cycle, is much harder. The rest of this guide is how to build those layers.
How to prevent fake job applicants, step by step
Step 1: Verify identity properly, not just on paper
Ask for government-issued identification and verify it with a document-verification provider rather than eyeballing a scan. Match the name and photo against a live video check, not a static selfie that could be reused. Cross-reference the details the applicant gives you, email, phone, address, and professional profiles, and be suspicious when a professional history cannot be corroborated anywhere independent of the resume itself.
Step 2: Read device and network signals during the application
This is the layer most hiring processes skip, and it is the one that catches the organized cases. When an applicant fills in your form or logs into your applicant portal, the session carries signals about the environment it runs in. Watching those signals flags the classic tells early:
- A session running inside a virtual machine, a common way to spoof a clean, disposable environment.
- A connection routed through a VPN or proxy, including residential proxies, so the network origin no longer matches the stated location.
- An anti-detect browser or incognito mode built to defeat tracking and blend many identities together.
- Remote-control software operating the machine, the signature of a laptop-farm setup driven from abroad.
- One device behind many applications, where several "different" candidates trace back to a single machine.
None of these is a conviction on its own, a real candidate might use a corporate VPN, but each one is a reason to look harder before investing recruiter time. The goal is to surface suspicious sessions automatically so a human reviews the right ones.
Step 3: Watch for red flags in the process
Train recruiters and hiring managers to notice the patterns fakes produce:
- Reluctance to turn the camera on, or a video feed that looks manipulated or out of sync with the audio.
- Answers that lag, as if a proxy is relaying the question to someone off-camera.
- A stated location that contradicts the network origin, the timezone of their responses, or their working hours.
- A request to ship the laptop to an address different from the home address on file.
- Payment details, such as a bank or payroll routing, that do not match the claimed location.
Step 4: Control the interview environment
Use live, interactive video rather than pre-recorded responses. Ask unpredictable, context-specific questions a coached stand-in cannot rehearse, and ask the candidate to do small real-world actions on camera. If a live interview session shows remote-control software or a VPN connection, treat it as a prompt to re-verify identity on the spot rather than pressing on.
Step 5: Harden onboarding and equipment
The scheme does not end at the offer. Ship equipment only to a verified home address and confirm receipt with a live video call from that location. Watch for remote-access tools installed on a new hire's company laptop in the first days. Keep the same device and network monitoring running past day one, because the point where a fake applicant becomes a fake employee is exactly where many controls stop.
A quick red-flag checklist
Escalate to a closer human review when you see any of these during application or interview:
| Signal | What it can indicate |
|---|---|
| VPN, proxy, or residential proxy connection | Origin being masked to match a fake location |
| Virtual machine detected | Disposable, spoofed environment |
| Remote-control / screen-share software active | Machine driven by someone elsewhere (laptop farm) |
| Network origin contradicts stated location | Applicant is not where they claim to be |
| One device across multiple identities | A single operator running many personas |
| Camera avoidance or lip-sync mismatch | Interview proxy or real-time deepfake |
| Laptop shipping address differs from home address | Laptop-farm facilitator receiving the device |
Any single row can have an innocent explanation. Two or more together rarely do.
Where cside's device intelligence fits
cside is a single first-party JavaScript snippet that gives you the device-and-network layer of this process. Add it to your careers site, application form, or hiring portal, and it reads the session while the applicant is in it, no separate collector for an ad blocker to strip, and no change to your DNS or traffic path.
For applicant screening, cside collects 250+ browser, device, and network signals per session and returns a verdict alongside a stable device ID. In practice that means it can flag, during the application:
- Sessions running through VPNs and proxies, including the residential proxies that slip past IP-reputation lists, so a masked origin does not go unnoticed.
- Virtual machines, anti-detect browsers, and incognito environments built to look clean and disposable.
- Indicators of remote-control software, the hallmark of a laptop-farm setup operated from another country.
- A single device submitting many separate identities, so a fraud ring running dozens of personas surfaces as one machine.
Because the verdict arrives with the device ID, a slow manual investigation becomes an early filter: the clearly suspicious sessions are flagged for a recruiter to review, and the rest move through. cside is built for exactly this use case on the applicant check page, and it complements, rather than replaces, your identity-verification and interview controls. For a deeper look at the software category, see applicant fraud detection software.
Device intelligence is one layer of three. Paired with real identity verification and an attentive interview process, it makes preventing fake job applicants a repeatable process instead of a lucky catch.









