Remote hiring, freely available deepfake tools and harvested identities have created an opportunity that organized criminals are now taking seriously. State-backed operations are training workers to apply for remote roles using stolen credentials and proxy interviewers. The aim is the salary and access to source code, customer data and intellectual property once they are inside. Recruiters are the ones meeting these people first, and in most organizations they are assessing them with a background check and their own judgment while IT, InfoSec and legal are rarely involved. So how seriously should employers be treating this, and what does a credible response look like?
My guest this week is Lauren Furey, Principal Product Manager at Proof, where she leads product work on candidate fraud and identity verification. In our conversation, Lauren explains how these attacks work, where hiring processes are most exposed, and what TA teams can do about it.
In the interview, we discuss:
- Bots, deepfakes, identity harvesting and proxy interviewers
- The criminal motivations behind state-backed infiltration
- Why the background check is no longer enough on its own
- How much recruiters overestimate their ability to spot a fake
- Why remote hiring created the gaps bad actors exploit
- Building identity continuity through the hiring process
- Making fraud prevention a shared responsibility with IT and InfoSec
- The candidate experience trade-off and where to place verification
- Verifiable credentials and protecting candidates’ own identities
- Practical first steps and what does the future look like?
Follow this podcast on Apple Podcasts.
Follow this podcast on Spotify.
Key takeaways
- Candidate fraud now includes state-backed programs that train workers to apply for remote roles using stolen identities and deepfake technology.
- The paycheck is only part of the motivation, with access to source code, customer data and intellectual property a primary objective for these operatives.
- Background checks remain a foundational part of hiring, but they are no longer sufficient on their own against this level of sophistication.
- Remote hiring removed the continuity that in-person processes provided, and every handoff to a new interviewer creates an opening for proxy interviewers and manipulated video.
- Recruiters are largely being left to spot this on their own, when InfoSec, IT, and legal teams should be sharing the responsibility.
- Identity verification and identity continuity are expected to become an organic part of the application and interview process, with a significant increase during 2027.
Transcript
Matt Alder 0:00
Most conversations about candidate fraud are about using AI to cheat in interviews and fake skills and experience. There’s a second kind of candidate fraud though that’s far more serious, where organised criminal operations are using stolen identities to get inside of organisations. So are your candidates who they say they are? And what are the implications for your business if they aren’t? Keep listening to find out.
Matt Alder 0:28
Support for this podcast is provided by Proof, the identity platform built for hiring. You’ve probably heard that by 2028, one in four job applicants is predicted to be fake. In fact, you’ve probably already seen that in your recruiting pipeline. Today, scammers are sending one person to get the offer and a totally different person to start the job. But most identity tools either only screen an application or verify a candidate’s ID. Proof does both. Integrated directly with applicant tracking systems like Lever, from the first interview through to onboarding. So you have proof that the person you interview is the same real person you hire. You can learn more by going to proof.com. That’s P-R-O-O-F dot com.
Matt Alder 1:37
Hi there, welcome to episode 825 of Recruiting Future with me, Matt Alder. Remote hiring, widely available deepfake tools, and the harvesting of stolen identities have created an opportunity for organised crime in the hiring process. State-backed operations are also training workers to apply for roles using stolen credentials and proxy interviewers. The aim is to access source code, customer data, and intellectual property once they’re inside the organisation. Recruiters are on the front line here, and in many cases, the only tool they have to manage this huge business risk is their own judgement. So how seriously should employers be treating this? And what does a credible response look like? My guest this week is Lauren Furey, Principal Product Manager at Proof, where she leads product work on candidate fraud and identity verification. In our conversation, Lauren explains how these attacks work, where hiring processes are most exposed, and what TA teams can do about it.
Matt Alder 2:44
Hi, Lauren, and welcome to the podcast.
Lauren Furey 2:46
Thank you so much for having me, Matt. It’s nice to be here.
Matt Alder 2:49
An absolute pleasure to have you on the show. Please, could you just start off by introducing yourself and telling everyone what you do?
Lauren Furey 2:56
Sure. My name is Lauren Furey. Currently, I’m a principal product manager working at a company called Proof, where we are really focused on ensuring that the candidate experience and candidate fraud pervasive problem is mitigated for our clients. And we extend into other identity validation scenarios. My background actually comes from also having built products at Lattice as well as DocuSign and a long history of being really customer-centric. So very excited to be here today talking to the people that we really care about.
Matt Alder 3:27
I think it’s a really interesting topic because we’re talking about candidate fraud. It’s a very big topic in talent acquisition at the moment, but I think there are aspects to this that people just haven’t thought of. So really looking forward to hearing your insights on some of these things. So let’s just start off and talk a little bit about the landscape. So this is a big issue at the moment. I think there are lots of things that kind of all get rolled into one, from candidates sort of using AI to embellish applications, to people not being who they say they are, all the way through to sort of serious criminal activity. Tell us a little bit about the part of that that you work in and what’s kind of going on at the moment and why it’s so important.
Lauren Furey 4:12
I would say the landscape is changing rapidly, and I’m happy to kind of take us through a little bit more on why I think that is. But at the moment, the most pressing issues that we’re seeing is clients dealing with different vectors of falsehood in the application process. So how do I sift through applications that are coming through from bots, which are these automated systems generating and submitting job applications at scale? And I’m not talking about an individual applying to 50 jobs. I’m talking about systems firing off hundreds of tailored applications. So that’s one kind of vector that folks are dealing with.
Lauren Furey 4:49
There’s also this new presence of deepfakes that’s becoming more accessible and available. These video manipulation tools used to be really out of reach of a normal consumer, and they’re not anymore. So now we see that showing up in the interview process, and it’s a really unique and sometimes off-putting or scary experience for recruiters to deal with. And generally, we’re seeing identity harvesting, which essentially means that these stolen identities, we just saw a news story about driver’s licences being made broadly available. That’s exactly what these folks are doing. They’re taking this real identity, adjusting it slightly, and applying to jobs. So it seems like they are valid, but they’re not, and they often use proxy interviewers through that process. So, a lot of different ways in which this is manifesting for our recruiters, and a lot of different ways in which they can filter through that or think about it or feel exposed right now.
Matt Alder 5:47
What are some of the motivations behind this? Because this isn’t about people trying to get a job they might not be qualified for. There’s a lot more sort of serious things going on, aren’t there?
Lauren Furey 5:58
Yeah, it’s actually quite serious. So to the point where the DOJ has put out notices to be on the lookout for these things, there’s a lot of documented cases of foreign workers essentially trying to come through and get these jobs. And I think that can feel really far away and potentially like it would never happen to us, right? It feels like something that is so grandiose, it’s like a fairy tale.
Lauren Furey 6:26
But really what’s occurring here is that these foreign governments, and we do primarily see this coming through from North Korea, but also others, they’re running these organised, funded programmes where workers are specially trained to apply for these remote jobs at Western companies. They use stolen credentials. They essentially are coming through under false identities. They can use AI-generated documents, or sometimes this is a great example of the utilisation of deepfake technology. And why they want to do this is, it sounds so obvious when we start to say it, right? But it’s, first of all, to collect the paycheck, which more often than not is going directly back into that government, which often can also be funding weapons programmes. They’ve traced it back to that, so that’s quite scary. But then also it’s to gain access to your data and your systems, your source code, your customer data, your intellectual property. So there’s a lot of heavy motivation from these operatives to get in there and get into these really high-touch jobs like the engineering side, like customer support side, like the IT side. And often these are also the roles that happen to be remote. So it feels like a nice intersection for them to sit at and just exploit from the inside of the business.
Matt Alder 7:44
It really puts talent acquisition on the front line here, doesn’t it? Doing something that they’ve not really done before, you know, validating who people are in quite a different way. Why is it falling to talent acquisition and what do they need to be aware of in terms of the bigger picture, who they should be liaising with, those kind of things?
Lauren Furey 8:04
Yeah, it’s something that we talk about a lot, even internally within our own business, right? Because we can even just go as far as our own doorstep to say, like, how are we experiencing this as a business and how are our recruiters feeling when they go through these processes? And I do think it is presenting a really novel problem to the recruiting teams, to the talent acquisition teams, because up until really recently, there was this reliance and belief that the background check was sufficient. And it is still a necessary part of this flow. So I never want to say that it’s not. It’s absolutely still a foundational part of this.
Lauren Furey 8:45
However, we also tend to overassume how good we are at reading these deepfakes or assuming that we will be able, our intuition will tell us enough that we can kind of filter through people. But this problem is quite sophisticated. So this new sophistication is coming through at the front door of the business. And then, you know, getting into the business can really exploit a company, it can be a very massive scale of a problem. So what that puts is a really specific kind of pressure onto the folks who are going through the applications, who are talking to the individuals up front. And this does extend into the interviewer and the interview staff, but they’re not the ones I think that would have to kind of sit with that responsibility at the end. So it’s a very unique pressure that’s being applied into the talent acquisition teams. And one that I think, and we can talk about this a little more, will need to eventually and should eventually grow into this responsibility that is shared across the organisation. So we’ll see some more sophisticated teams where their InfoSec team or their security team or their IT team is working more closely with HR to say, we realise we have a weak point that is potentially going to get exploited. How do we partner to make sure that we don’t?
Lauren Furey 10:08
That is a great scenario. We don’t — we still aren’t seeing that broadly across organisations and HR is still trying to figure out how they sift through those different kind of attack vectors.
Matt Alder 10:18
That’s a really interesting point. And I think that in a lot of companies, this is — it feels like the recruiters are kind of out on their own, sort of trying to spot this and the bigger implications of it aren’t really being realised and they’re not getting that kind of support. Where are the gaps in the typical processes at the moment? Because you mentioned background checks, which are something different. People are doing video interviews, those kind of things. Where’s the risk? Where are the gaps at the moment?
Lauren Furey 10:44
I think it varies. The shorter answer of this is that it can vary by organisation. And it also varies by the type of fraud or attack that you might be dealing with. So maybe to back up just a moment and give a little bit of additional context. The reason why we’re here is that in March of 2020, we took these processes that were really a lot of in-person processes, a lot of in-person interviewing and handoffs, and you’d come and sit on site for a day, and that all went remote. So as soon as COVID happens, right, everything goes remote. So this was a process that was immediately pushed into a new kind of setting, and we are still catching up with how do we make sure that this feels as thorough and complete as possible. And I think this has been a really wonderful forcing function for that.
Lauren Furey 11:31
Now in 2020 — so that was 2020 — roughly in 2022, we saw these consumer-grade deepfakes start to really accelerate. So that we started to see them become more pervasive and available, and they started to become largely free. And now with less technical acumen needed to operate them, we’re starting to see more people apply them.
Lauren Furey 11:50
Roughly similar timing in 2022, generative AI starts to come through that’s a kind of different — presents different types of fraud. So now normal consumers could start to make up things about themselves in a way that is maybe more sophisticated than they previously could, more elaborate than they previously could. And then we start to see these things really converge in this kind of fourth moment that we’re in right now, where it’s, hey, now we have remote hiring, we also are using these deepfakes that are exceptionally good at scale, we’re seeing generative AI come into play. And now, you know, we’re probably on the cusp of seeing agentic AI really push into this space as well. So I think there’s just this really interesting intersection that we’re sitting at, and companies are feeling that exploitation across the funnel. So what that can look like is upon application, am I seeing a candidate that feels genuine or am I seeing somebody who does match their LinkedIn, who seemingly matches a LinkedIn, but there’s maybe some bits of that LinkedIn that don’t feel completely correct?
Lauren Furey 12:55
Then we’ll start to see throughout the process that there could be proxy interviewers. So I’m interviewing for this role in this moment. When we get to the skills assessment, I’m going to tag somebody else in. There’s no through line for who were you expecting to meet with. It’s a new interviewer, new individual on my side. It kind of works out. Every break or every introduction of a new interviewer allows for those tools in this toolkit to come through and be utilised by these bad actors. So the way that we kind of think of it is however your funnel, however your hiring funnel is structured, anytime you’re introducing someone new from your side into that mix, which is right to do, we want to vet them culturally, we want to look at the candidate from all different facets of their skill set and aptitude. This is the right thing to do. But when you bring someone new in, there’s not that connective tissue of who is it I’m supposed to be talking to. So that was kind of that analogue process had solved for it when we were in person. You just walk them to the next conference room. We’re not doing that anymore.
Lauren Furey 13:59
So something we’ve really looked at is how do you start to build continuity before we get to background check? So that once we’re at background check, we know that this thing we’re vetting is the individual we’ve seen throughout. So we need to start building that kind of forward funnel of assurance so that by the time we get closer to background check, I-9, and onboarding, we have something that can also follow them through those processes. And then we’ve got confidence of we know who we’re dealing with here.
Matt Alder 14:30
And tell us a little bit more about how that’s done, because I know that at the moment, there are lots of TA people who are — the only tools they have at their disposal are their kind of insight and judgement and some really unsophisticated things that probably don’t even work anymore like asking people to put their hands in front of their face and those kind of things. What is it that’s kind of available to kind of help with this problem?
Lauren Furey 14:53
I guess I want to say too that we had mentioned previously like, man, this falls to our TA staff and our recruiters and they’re sitting in this really kind of tough intersection. I think something that’s important to talk about here too is, they’re those folks, although it feels like you’re dealing with this novel problem, and perhaps you don’t want to do it alone. These folks are actually made for this as well. Like, going back to that intuition, this group of people that excel in this career path do have great intuition, they do know how to really engage with humans, they know how to, you know, bring somebody into the fold and ask the right questions. So as much as it can feel like tense or like uncomfortable to sit here in this space at this moment, we also know these folks are made for it, which is great. Because then when we start to talk about how do we actually start to resolve these issues, especially at scale, they’re the right people for the job, which is perfect.
Lauren Furey 15:50
So what we’ve started to see is there’s levels of sophistication that you can start to do here, right? The highest level of sophistication is to build that through line, is to say, how do I start to put candidates through identity verification early. And then have them have a point of reference from that identity verification? So as an example, and this also, by the way, I’m going to caveat that some of these will depend on how you feel with your legal team, your compliance team, how you feel as a business for hiring. But what we have seen is folks taking an image from that identity verification and saving it to the ATS so that every time somebody comes back through and is doing that interview and they’re meeting that person remotely, there’s a point of reference — who is supposed to be here. That can grow in sophistication to saying we’re actually going to gate your access to these interviews and to these conference calls or to these skills assessments by a selfie through biometric now.
Lauren Furey 16:50
You can also do this in a much more available or accessible way. And that is just through simple identity verification. These are easy tools to access. They are becoming increasingly familiar on the candidate side. And essentially all they do is to say, can you let me scan your driver’s licence or another kind of documented credential? And sometimes it’ll also include that biometric. Can I scan your face to kind of match it to that documented credential?
Lauren Furey 17:19
What this does is it does say up front, how am I pairing the applicant with that résumé, with that, say, LinkedIn or other additional research? And then how are we following that person through the process? So as much as you want to kind of automate that or make it systematic, or if you want to just kind of do it in touch points, both of those are available to teams. I think the important part is don’t feel so overwhelmed to do nothing. Start somewhere. Start somewhere and see how things adjust.
Matt Alder 17:54
And how does that fit with the candidate experience? So those candidates who are not trying to commit a crime or fraudulently get the job, how does that sort of affect their experience of the process?
Lauren Furey 18:05
This is such a great question because we’ve had clients actually articulate to us, you know, and I love this quote, but they said, the passive candidates are the best candidates. The ones that you really want to attract are often the ones that are not actively seeking. So you want to give them low friction, high, like white glove, high touch, high availability kinds of interview processes. And this can feel like friction that you may not necessarily want.
Lauren Furey 18:30
Something Proof is doing that I think is really critical is understanding the candidate experience. What is the willingness of candidates to engage in these types of identity verifications? Does it change? Does that willingness change based on where you put it? So, for example, if your identity verification is occurring right at application, does that drive your funnel and conversion down a lot, like to a point where you’re actually losing a lot of great candidates? Does it raise great signal? The people who are willing to complete the identity verification are the folks that are really interested in your company and they really want this job. So like that kind of tradeoff is up to the client to make, I’d say. But full transparency, candidates are still getting used to this new space. I will say this is becoming increasingly normal. I think we’re going to see a really big tick in 2027 of identity verification and identity continuity being an organic part of the application and interview process.
Matt Alder 19:35
And I think that kind of takes me to the next question, which is what does the future of this look like? So you mentioned earlier as this gets agentic and happens at scale, how do you think it’s going to pan out over the next few years?
Lauren Furey 19:45
This is really fun to always like theorise on this. So not only do I think we will have to start — we’re already seeing this trend occur in the market — we’re going to have to see identity validation done earlier in the process that will become normal. What I think will be an optimistic future is that we then build these continuity pieces that can allow us to say — and, I don’t know that I’ve done a great job of explaining what I mean by identity continuity, so let me do it here — but essentially saying, where do we put this in the process, to your point, not lose a ton of great candidates, right? There’s a funnel optimisation that we get to play with. Great.
Lauren Furey 20:27
And in the course of that, how do we take attributes of that identity or give that individual a digital certificate or a verifiable credential such that at any recurring touchpoint, they just use a biometric, they get access to that next stage, it is a comparison to the previous biometric or a comparison to their identity credential image, and we say, this is enough, allow them through. Now, I think there’s also a benefit that we are going to realise in the coming years that is actually on the consumer side, is on the candidate side, which is to say, if all these driver’s licences are actually made available at scale, if we all kind of know that our socials are out there, at one point, it’s going to have to be, how am I being protected? Almost like your credit score. Who is applying to jobs right now is Lauren Furey with my background with a manipulated LinkedIn that looks just like me and they’re using the data and attributes off of my licence with just an edited image. How do I start to feel protected? So there is a value prop that I think the businesses will start to get to articulate back into applicants and into, you know, the audience at large to say, we’re protecting you. We’re not hiring people that are not real. This is a very intentional step in making sure our business has high integrity and wants to take care of its individuals. So I think we’ll start to see that narrative and that motivation shift. And we’ll start to see that it’s expected not only from my side to have a verifiable credential where I can then apply to different jobs, use that thing, it feels more seamless, and they get to know who I am with assurance without a reveal of any sensitive data, without any kind of bias being introduced into the process. I think there’s ways that we’re going to see sophistication rise.
Lauren Furey 21:51
I’m really excited. I’m very optimistic about the future. That is because, by the way, and I didn’t necessarily articulate this, but those systems and the development of these really interesting tools is not going to slow down and the bad actors are not going to slow down. So we’ll continue to see that occur. So I think we just have to realise the value for both the candidates as well as the businesses.
Matt Alder 22:25
Finally, give us a really practical tip. So lots of people listening will be worried about this. They’re worried that they’re exposed to it. What can people sort of do tomorrow, first steps, to help safeguard their employer?
Lauren Furey 22:38
Yeah, I think the best thing that you can do is to build — start to consider your defence in three layers. And I do think some of that is going and talking, like initially going and talking internally to your IT teams, to your legal teams, to a finance team, your CHRO. I think starting that conversation right away is point one. Hey, we are feeling this point of exposure. We want to make sure that we are protecting the business. We have an idea for how we can begin this. Can we start and test? None of this has to be a fully baked commit. Let’s start to test. Then what that test might look like is — so that’s probably step one, right? Step two is to test it. Work with an identity verification vendor who can help to do standard IDV early in your funnel. Put it in front of — I would not say put it at the outset of application. Put it before either the hiring manager interview or a phone screen such that the candidate feels like an interest. There’s a motivation for them to complete it. Make sure you’re articulating that to your candidate and then see how we do. See how that conversion rate affects you, see if you can play with the language, start to truly use this as an experimentation in your funnel, but allowing it to also surface for you, hey, we’re seeing a lot of bad actors come through and like, let’s feel them get filtered out.
Lauren Furey 24:19
Now, during that process, I’d say what you need to talk through, this is probably part three, is how are we looking at the data such that we can then make a decision of what next, what has to come next? Do we need to kind of have this persist in another way down funnel? Do we have another point of exposure that feels really obvious to us at point of onboarding and making sure that we are still tying back to that first person we met? How do we close that kind of trust gap? So maybe it’s go talk internally, map out your experience, map out your process, start to test upstream, and then make a plan for how is this going to get implemented at scale.
Matt Alder 24:58
Lauren, thank you very much for talking to me.
Lauren Furey 25:00
Oh my gosh, thank you so much for having me, Matt. This was really enjoyable.
Matt Alder 25:04
My thanks to Lauren. You can follow this podcast on Apple Podcasts, on Spotify, or wherever you listen to your podcasts. You can search all the past episodes at recruitingfuture.com. On that site, you can also subscribe to our weekly newsletter, Recruiting Future Feast, and get the inside track on everything that’s coming up on the show. Thanks very much for listening. I’ll be back next time, and I hope you’ll join me.





