Skip to main content
Blog
Blog

How to prevent fake job applicants: a step-by-step guide for 2026

How to prevent fake job applicants: verify identity, read device and network signals during the application, and spot the red flags before you hire.

Aug 21, 2026 Updated Aug 22, 2026 8 min read
How to prevent fake job applicants: a step-by-step guide for 2026
Table of Contents

Hiring has gone remote-first, and so has hiring fraud. A fake job applicant is no longer just someone who padded a resume. It is often a fabricated or stolen identity, an interview answered by a stand-in, or, in the most organized cases, a state-sponsored operator working from another country while appearing to sit in your city. If you want to know how to prevent fake job applicants, the honest answer is that no single check does it. You layer identity verification, device intelligence, and disciplined process so a fake applicant has to beat all three at once.

This guide walks through how companies detect fake job applicants today, the concrete steps to prevent them, the red flags worth escalating, and where device intelligence fits into the application itself.

Why fake job applicants are a growing problem

Three forces made this worse at the same time. Remote work removed the in-person moment that used to expose an impostor. Generative AI made fabricated resumes, cover letters, headshots, and even live video convincing. And organized groups turned it into a business.

The most documented example is the North Korean IT worker scheme. Operators apply for remote engineering roles at Western companies using stolen or fabricated identities, then work from outside the country while appearing to be local. The playbook has recognizable moving parts:

  • A laptop farm. A facilitator, often based in the target country, receives the company-issued laptop and keeps it running at their home, so the shipping address and the on-network location look domestic. Our explainer on what a laptop farm is covers the mechanics.
  • A VPN or proxy to mask origin. The real operator connects through a VPN, proxy, or residential proxy so their network location matches the fake identity's stated location instead of their own.
  • Remote-control software. Tools like remote desktop or screen-sharing utilities let the operator abroad drive the domestic laptop, so the traffic looks local even though the person is not.
  • Interview proxies and deepfakes. A different, more fluent person may sit the interview, or a real-time face swap stands in for the applicant on camera.

US authorities, including the FBI and the Department of Justice, have issued repeated advisories about this scheme, and it is not limited to nation-state actors: ordinary fraud rings use the same tools to place unqualified people into paid roles or to get a foot inside a company. For more on the specific state-sponsored angle, see our post on North Korean actors attempting to infiltrate technology companies.

How do companies detect fake job applicants?

Detection works when you stop relying on any one signal. The teams that catch fakes reliably combine three layers:

  1. Identity verification. Confirm the person is real, and that they match their documents and their claimed history.
  2. Device and network intelligence. Read how the applicant actually connects, virtual machine, VPN or proxy, anti-detect browser, remote-control software, one device behind many identities, during the application and the interview.
  3. Process controls. Live video, unannounced re-checks, and cross-referencing of addresses and contact details, run by a human who knows what a mismatch looks like.

A fabricated applicant can usually defeat one layer. Defeating all three, consistently, across a full hiring cycle, is much harder. The rest of this guide is how to build those layers.

How to prevent fake job applicants, step by step

Step 1: Verify identity properly, not just on paper

Ask for government-issued identification and verify it with a document-verification provider rather than eyeballing a scan. Match the name and photo against a live video check, not a static selfie that could be reused. Cross-reference the details the applicant gives you, email, phone, address, and professional profiles, and be suspicious when a professional history cannot be corroborated anywhere independent of the resume itself.

Step 2: Read device and network signals during the application

This is the layer most hiring processes skip, and it is the one that catches the organized cases. When an applicant fills in your form or logs into your applicant portal, the session carries signals about the environment it runs in. Watching those signals flags the classic tells early:

  • A session running inside a virtual machine, a common way to spoof a clean, disposable environment.
  • A connection routed through a VPN or proxy, including residential proxies, so the network origin no longer matches the stated location.
  • An anti-detect browser or incognito mode built to defeat tracking and blend many identities together.
  • Remote-control software operating the machine, the signature of a laptop-farm setup driven from abroad.
  • One device behind many applications, where several "different" candidates trace back to a single machine.

None of these is a conviction on its own, a real candidate might use a corporate VPN, but each one is a reason to look harder before investing recruiter time. The goal is to surface suspicious sessions automatically so a human reviews the right ones.

Step 3: Watch for red flags in the process

Train recruiters and hiring managers to notice the patterns fakes produce:

  • Reluctance to turn the camera on, or a video feed that looks manipulated or out of sync with the audio.
  • Answers that lag, as if a proxy is relaying the question to someone off-camera.
  • A stated location that contradicts the network origin, the timezone of their responses, or their working hours.
  • A request to ship the laptop to an address different from the home address on file.
  • Payment details, such as a bank or payroll routing, that do not match the claimed location.

Step 4: Control the interview environment

Use live, interactive video rather than pre-recorded responses. Ask unpredictable, context-specific questions a coached stand-in cannot rehearse, and ask the candidate to do small real-world actions on camera. If a live interview session shows remote-control software or a VPN connection, treat it as a prompt to re-verify identity on the spot rather than pressing on.

Step 5: Harden onboarding and equipment

The scheme does not end at the offer. Ship equipment only to a verified home address and confirm receipt with a live video call from that location. Watch for remote-access tools installed on a new hire's company laptop in the first days. Keep the same device and network monitoring running past day one, because the point where a fake applicant becomes a fake employee is exactly where many controls stop.

A quick red-flag checklist

Escalate to a closer human review when you see any of these during application or interview:

SignalWhat it can indicate
VPN, proxy, or residential proxy connectionOrigin being masked to match a fake location
Virtual machine detectedDisposable, spoofed environment
Remote-control / screen-share software activeMachine driven by someone elsewhere (laptop farm)
Network origin contradicts stated locationApplicant is not where they claim to be
One device across multiple identitiesA single operator running many personas
Camera avoidance or lip-sync mismatchInterview proxy or real-time deepfake
Laptop shipping address differs from home addressLaptop-farm facilitator receiving the device

Any single row can have an innocent explanation. Two or more together rarely do.

Where cside's device intelligence fits

cside is a single first-party JavaScript snippet that gives you the device-and-network layer of this process. Add it to your careers site, application form, or hiring portal, and it reads the session while the applicant is in it, no separate collector for an ad blocker to strip, and no change to your DNS or traffic path.

For applicant screening, cside collects 250+ browser, device, and network signals per session and returns a verdict alongside a stable device ID. In practice that means it can flag, during the application:

  • Sessions running through VPNs and proxies, including the residential proxies that slip past IP-reputation lists, so a masked origin does not go unnoticed.
  • Virtual machines, anti-detect browsers, and incognito environments built to look clean and disposable.
  • Indicators of remote-control software, the hallmark of a laptop-farm setup operated from another country.
  • A single device submitting many separate identities, so a fraud ring running dozens of personas surfaces as one machine.

Because the verdict arrives with the device ID, a slow manual investigation becomes an early filter: the clearly suspicious sessions are flagged for a recruiter to review, and the rest move through. cside is built for exactly this use case on the applicant check page, and it complements, rather than replaces, your identity-verification and interview controls. For a deeper look at the software category, see applicant fraud detection software.

Device intelligence is one layer of three. Paired with real identity verification and an attentive interview process, it makes preventing fake job applicants a repeatable process instead of a lucky catch.

Further reading

Mike Kutlu
Client-Side Security Consultant

Client-side security consultant at cside. 10+ years of experience implementing technology solutions for enterprises (previously at Oracle, Cloudflare, and Splunk). Now helping teams use client-side intelligence to catch & reduce fraud.

FAQ

Frequently Asked Questions

Companies detect fake job applicants by combining identity verification with signals from the application and interview itself. Identity checks confirm the person is real and matches their documents. Device and network intelligence reads how the applicant connects: whether the session runs inside a virtual machine, through a VPN or proxy that hides its true origin, or under remote-control software that lets someone elsewhere operate the machine. Process controls add live video, unannounced identity re-checks, and cross-referencing of contact details. No single check is enough on its own; the reliable approach is to layer identity, device intelligence, and human judgment so a fabricated applicant has to defeat all three at once.

North Korean IT workers typically apply with stolen or fabricated identities and work from outside the country while appearing to be domestic, often using a US-based facilitator's home as a laptop farm, a VPN to mask their real location, and remote-access tools to operate that laptop from abroad. Preventing them means catching those tells: verify identity against government documents and live video, watch for a connection whose network origin does not match the stated location, flag sessions running through VPNs, proxies, virtual machines, or remote-control software, and treat mismatches between resume, IP geolocation, and payment or shipping addresses as a reason to slow down. US authorities including the FBI and Department of Justice have issued repeated advisories on this scheme, so a documented, layered screening process is now a baseline expectation.

The strongest red flags are inconsistencies that a real applicant would not produce: a connection that routes through a VPN, proxy, or virtual machine during the application; a network origin that contradicts the stated location; reluctance to turn on the camera or a video feed that looks manipulated; audio that lags the lips as if a proxy is relaying the interview; a request to ship the work laptop to an address that differs from the home address on file; and repeated identities or resumes tied back to one device. Any one of these can have an innocent explanation, so the point is not to auto-reject but to escalate to a closer human review.

Yes. Device fingerprinting reads the browser, device, and network characteristics of the session while the applicant fills in the form or joins the portal, so it can flag a virtual machine, a VPN or proxy connection, an anti-detect browser, incognito mode, or a single device submitting many separate identities, all before a recruiter has spent time on the candidate. cside collects 250+ signals per session from one first-party JavaScript snippet and returns a verdict alongside the device ID, which turns a slow, manual investigation into an early filter that surfaces the suspicious sessions for a human to review.

Interview proxies (where someone other than the applicant answers the questions) and real-time deepfakes are countered with live, interactive video rather than pre-recorded answers, unpredictable questions that a coached stand-in cannot rehearse, and asking the candidate to perform simple real-world actions on camera. Device and network signals help here too: a session running through remote-control software or a VPN during a live interview is a reason to verify identity again on the spot. Pairing an attentive interviewer with device intelligence makes it much harder for a proxy or a synthetic face to survive the full process.

Yes. Device and network intelligence runs passively in the background of the application form or hiring portal, so genuine candidates complete the form as usual and never see an extra step. cside is a single first-party JavaScript snippet that reads the session while the applicant is in it and returns a verdict, so only the flagged sessions get a closer human review while everyone else moves through untouched. The friction stays where it belongs, on the small number of suspicious sessions rather than on your whole applicant funnel.

A single signal should never auto-reject anyone, because a real candidate may sit behind a corporate VPN, work while travelling, or simply value their privacy. The way to keep false positives low is to treat each signal as one input rather than a verdict, and to escalate only when signals stack up: a VPN plus a virtual machine plus remote-control software plus a network origin that contradicts the stated location is a very different picture from a lone VPN. cside returns 250+ signals per session and a combined verdict instead of a yes-or-no on any one attribute, so a human reviews the genuinely suspicious sessions rather than penalizing ordinary privacy-conscious applicants.

Device and network screening is added where applicants already are: the careers site, the application form, or the applicant portal. cside deploys as one first-party JavaScript snippet with no DNS change and no separate collector, so it sits alongside your existing applicant tracking system rather than replacing it. The verdict and stable device ID it returns can be surfaced to recruiters next to the candidate record, so suspicious sessions are flagged inside the workflow your team already uses instead of in a separate tool.

A repeatable process layers several checks. Verify government-issued identity with a document-verification provider rather than eyeballing a scan. Match the document to a live video call, not a static selfie. Cross-reference email, phone, address, and professional profiles for corroboration outside the resume. Read device and network signals during the application to catch virtual machines, VPNs, proxies, and remote-control software. Use live, unpredictable interview questions a stand-in cannot rehearse. Ship equipment only to a verified address confirmed on camera. No single step is sufficient, but together they force a fake applicant to defeat identity, device intelligence, and human judgment at the same time.

Both leave detectable traces in the session. A virtual machine exposes characteristics in the browser and device environment that differ from real hardware, which is why fraudsters favor VMs as clean, disposable environments. Remote-control and screen-sharing tools change how the session behaves and are the signature of a laptop-farm setup where someone abroad drives a domestic machine. Device fingerprinting reads these characteristics while the applicant is in the form or portal and flags them, so a recruiter learns the machine is virtualized or remotely operated before spending time on the candidate rather than after.

Yes. Applications from a mobile browser are covered by the same first-party web snippet that screens desktop sessions. For hiring flows that run inside a native app, cside also offers native iOS and Android SDKs, currently in beta, that run the same engine: the same 250+ signals as the web client plus signals only an app can see, such as emulator detection and app tampering. The mobile SDKs are early access, so access is arranged by request. Together they mean a fake applicant cannot simply switch to a phone to slip past desktop-only screening.

A mismatch between the location on the resume and the network origin of the session is one of the strongest tells in the North Korean IT worker scheme and in ordinary fraud rings, but it is not proof on its own, because VPNs and travel produce the same effect. Treat it as a reason to slow down and verify, not to auto-reject: re-confirm identity on a live video call, ask location-specific questions, and check whether the connection also shows a VPN, proxy, virtual machine, or remote-control software. When the geolocation mismatch stacks with those signals, or with a laptop shipping address in a different place from the home address, escalate to a closer review before making an offer.

Monitor and Secure Your Third-Party Scripts

Gain full visibility and control over every script delivered to your users to enhance site security and performance.

Start free, or try Business with a 14-day trial.

cside dashboard interface showing script monitoring and security analytics
Related Articles
Book a demo

Want to walk through this with an engineer?

Thirty minutes, on your own site. Not a slide deck.

We'll show you:

Which third-party scripts are running on your site right now
Where you stand on PCI DSS 6.4.3 and 11.6.1
How much of your traffic is bots and AI agents

Rather just send a question?

Finding open slots…

Real humans only. We'd know.

Having trouble booking? Open scheduler in a new tab

What are you trying to solve?

Tell us in a line and we'll come back with something useful, not a generic pitch.

We usually help with:

Seeing which third-party scripts run on your site
PCI DSS 6.4.3 and 11.6.1 evidence
Bots, AI agents and account takeover

Prefer to just book a time? Pick a slot instead