Skip to main content

Stop Fake Job Applicants Before They Reach Your ATS

Remote hiring has turned the job application process into an entry point for fake job applicants who use fabricated identities and technical evasion to slip past traditional screening.

Remote Hiring Created New Attack Vectors

Well-funded hackers, many from North Korea, submit hundreds of resumes and pose as candidates to infiltrate your intellectual property.

They use fake identities, deepfake interviews over Zoom, VPNs, and virtual machines to bypass traditional screening.

One successful attack exposes code and customer data. At the very least it wastes your recruiter time and budget in the process.

WITH CSIDE
Fingerprint browser sessions to detect suspicious signals (VMs, VPNs, bots)
Block fraudulent applications before they reach your ATS
Protect against nation-state impostors looking to gain access to your code, data, or credentials
Free up time for recruiters to focus on legitimate candidates

How a DPRK IT worker gets flagged

One click is all it takes. The moment an applicant confirms interest, cside cross-references their devices, network, environment, and writing, before they ever reach an interview.

Application portal
Re: Senior Frontend Engineer, next stepsConfirm you're interested in this role and want to be considered going forward.
Applicant's answer
Confirm interest
csidecside · live signals
MONITORING
DevicesAwaiting signal…
NetworkAwaiting signal…
EnvironmentAwaiting signal…
WritingAwaiting signal…
FLAGGED: DPRK_IT_WORKER_INDICATORSAuto-rejected · Team notified
WIRED Magazine logo
Read more on the featured report in WIRED Magazine North Korea Stole Your Job: How AI is making remote hiring fraud more sophisticated
Read Article

Stop Fake Job Applications with Client-Side Signals

Screen Res
Canvas
Audio
WebGL
Fonts
Timezone
Fingerprint
Unique Fingerprint
Ready
Fingerprint every browser A website script collects privacy-compliant technical clues and turns them into a unique code.
Browser
Normal Browser
Headless Server
VM_DETECTED
HEADLESS_CHROME
Ready
Detect suspicious environments Our engine checks for signs of fraud: virtual machines, VPN, headless browsers, mismatched time zones or other odd patterns.
Applicant Tracking System
Candidate
Status
Verified
SC
Sarah Chen
Interview
Verified
MJ
Mike Johnson
Pending
Verified
Instant alerts Suspicious fingerprints send an alert to your ATS to auto-reject or flag for further review.

How cside Applicant Check Outperforms Traditional Screening

Feature
Applicant Check Device ID
Traditional Screening
Covers every browser and operating system Relies on IP / email only
Detects VMs, VPNs, and headless browsers Usually ignored
Privacy-friendly (non-sensitive signals) Often stores PII or cookies
Real-time API / webhook for ATS Manual log review

Recruiters Aren't Trained to Fight Fraudsters. Filter Them Out Early.

"cside helped our insider risk program prevent infiltration before it happened. Helping security and recruiting teams focus on what really matters."

Security Expert company logo- Security Expert, Fortune 500 Company

FAQ

Frequently Asked Questions

View all FAQs

The most effective fraud detection tools for fake job applicants pair device fingerprinting with network and environment analysis instead of relying on IP or email alone. cside deploys as one first-party JavaScript snippet that fingerprints each browser session across 250+ signals, flagging virtual machines, VPNs, residential proxies, and headless browsers in real time. That lets your team auto-reject or review suspicious applications before a fake job applicant ever reaches an interview.

At various level bypass methods are being used. To prevent you from seeing where the user is applying from VPN services are used. To apply for many applications fast they generate answers to questions in forms using LLMs. When going through identity verifications fake ID cards are being used sometimes using stolen identities. During interviews life answering bots help them respond to questions. There have even been videos circulating on the web where the bad actor used deep fake technology to cover their face.

Drawing on a baseline of 250+ browser, device, and network signals, the device fingerprinting looks for signals indicating that the application is made from automated or remote environments. Essentially separating real human devices from automated environments.

Cside simply detects signals that indicate VPN use as well as using virtual machines. There are a number of methods we use. None of the methods we use compromise a users privacy, they purely relate to system hardware identifiers.

Valuable intellectual property, access to user data, source code and API access keys to sensitive environments like payment platforms mean that bad actors have the highest chance of finding high value substance to exploit your business. Independent of the role, they will try to get their hands on the highest value items to resell or extort your business.

Common red flags include a resume that fits the role a little too perfectly, reluctance to turn on a camera or a video feed that looks unnatural in interviews, a stated location or time zone that contradicts the candidate's availability, and requests to ship a company laptop to an address that is not the candidate's own. cside surfaces the technical red flags automatically: it fingerprints each browser session across 250+ signals and flags virtual machines, residential proxies, VPNs, geo mismatches, and sessions where many devices are linked to one applicant.

The scheme, documented by the U.S. Department of Justice and the FBI, involves IT workers acting on behalf of North Korea who use stolen or fabricated identities to get hired into remote roles at Western companies, then funnel their wages back and, in some cases, steal data or extort the employer. They typically hide their real location behind VPNs and residential proxies, run their work inside virtual machines, and rely on local facilitators to receive company laptops. cside does not verify identity documents, but it exposes the technical infrastructure these operations depend on, fingerprinting each application session to flag VPNs, residential proxies, geo mismatches, virtualized environments, and clusters of devices tied to a single applicant.

cside is device intelligence, not video analysis, so it does not inspect a webcam feed or score a face for deepfakes. What it does do is flag the environment these tactics rely on. Applicants who use a deepfake or a live stand-in on a call are usually operating from a virtualized or remote-controlled environment behind a VPN or residential proxy, often from a session already linked to many other applications. cside catches those signals at the application stage, before an interview is ever scheduled, so a suspicious candidate can be reviewed rather than waved through.

cside deploys as a single first-party JavaScript snippet on your application or careers page, so there is no DNS change and nothing is routed through cside. Once an applicant's session is fingerprinted, the verdict can be sent to your ATS to auto-reject or flag suspicious applications for manual review, so recruiters see the risk signal alongside the rest of the candidate record. Legitimate applications flow through untouched.

No. cside runs quietly in the browser session while a candidate fills out the application, with no extra step, no CAPTCHA, and nothing for the applicant to install. Real candidates experience the normal application flow, while the fingerprint and its verdict happen in the background. The friction lands only where it should, on the fraudulent sessions your team chooses to reject or review.

cside does not reject anyone on a single signal. It evaluates each session across 250+ signals and looks for combinations that legitimate applicants rarely produce together, such as a virtualized environment behind a residential proxy with a geo mismatch and many devices tied to one session. A candidate who simply uses a corporate VPN is not treated the same as one running inside a VM from a proxied, high-risk session. You stay in control of the threshold and whether a flagged application is auto-rejected or sent for human review.

cside fingerprints the browser session using non-sensitive technical signals about the device, network, and environment, not personal data, and it does not rely on cookies to do so. It does not read identity documents or store the kind of PII that traditional screening often keeps. That keeps applicant screening privacy compliant while still separating real human devices from the automated and remote environments fake job applicants tend to use.

Book a demo

Want to walk through this with an engineer?

Thirty minutes, on your own site. Not a slide deck.

Book a personalized demo to see:

How to achieve PCI DSS requirement 6.4.3 & 11.6.1 compliance in 1 day
Why third-party scripts are a security risk for you and your visitors
Monitoring privacy and consent leakage (GDPR, CCPA) across every third party
Stopping signup abuse, account sharing, and chargeback fraud with device intelligence
Detecting and controlling AI agents and bots hitting your site in real time

Rather just send a question?

Finding open slots…

Real humans only. We'd know.

Having trouble booking? Open scheduler in a new tab

What are you trying to solve?

Tell us in a line and we'll come back with something useful, not a generic pitch.

We usually help with:

Seeing which third-party scripts run on your site
PCI DSS 6.4.3 and 11.6.1 evidence
Bots, AI agents and account takeover

Prefer to just book a time? Pick a slot instead