How to spot fake candidates before the interview

Interviews test whether someone can do the job. A constructed identity usually can.

HiringCandidate FraudIdentity ResolutionInsider RiskNorth Korea IT Workers
How to spot fake candidates before the interview

Most advice about spotting fake candidates is advice about interviews. Ask harder questions, call the references, add a live coding round. That catches someone who inflated their experience. It does not catch a constructed identity, because the person on the call has been coached, the references answer the phone, and the portfolio contains real work.

In July 2024 the security training company KnowBe4 hired a North Korean operative into a principal software engineer role. By KnowBe4's own account, the candidate used a valid US identity stolen from a real person and a photograph that was an AI-manipulated stock image, cleared a background check, and appeared on camera in four video interviews on four separate occasions. The company laptop was shipped to an address that turned out to be a laptop farm, and it began loading malware the day it arrived. KnowBe4's security team contained the machine about 25 minutes after the first alert, and says nothing was taken.

That company sells security awareness training. Its hiring process was not careless. The point of the story is that every stage of a normal, competent process returned a pass.

The operation behind it

The people doing this are funded and organised, which is why they will spend months on one identity.

The Justice Department's June 2025 actions against North Korean IT worker schemes give a sense of the machinery. Searches of 29 known or suspected laptop farms across 16 states, carried out between October 2024 and June 2025, seized roughly 200 computers along with financial accounts and fraudulent websites. In one Massachusetts case, now resolved by guilty pleas and sentencing, the government says the defendants compromised the identities of more than 80 US citizens to obtain remote jobs at more than 100 US companies, costing those companies at least 3 million dollars in legal fees and remediation.

A single facilitator gives the clearest picture of the scale. Christina Chapman ran a laptop farm out of her home in Arizona and was sentenced in July 2025 to 102 months for wire fraud conspiracy, aggravated identity theft and money laundering conspiracy. According to the Justice Department, that one operation used 68 stolen identities, defrauded 309 US businesses, and generated more than 17 million dollars. Investigators seized more than 90 laptops from her house, and she had shipped 49 more overseas, some to a city in China on the North Korean border.

North Korea is the best documented version of this and it is not the only one. The same techniques serve proxy interviewing, one engineer quietly holding four jobs, and contractor fraud through staffing chains. What they share is that the identity is the product, and the identity is built to survive inspection.

What this looks like from inside a security company

Casco builds an agentic security engineer, software that probes your own code for what is exploitable in it. That makes Casco worth the setup cost, and their founder describes the result without much drama.

Sixtyfour
We see fake North Korean workers apply to Casco. Sixtyfour flags adverse media and resume inaccuracies before we ever get on a call.
Rene BrandelCEO and founder, Casco

He talks about it at more length in our case study with Casco.

The phrase worth sitting with is "before we ever get on a call." KnowBe4's process failed at four separate interviews. Screening that runs on the application never asks the interview to be the thing that catches it.

Why the interview is the wrong place to look

An interview tests whether someone can do the job, and a fabricated candidate is often a real engineer working under a false name, so they can. Every artifact the hiring process inspects is an artifact that was prepared for it.

A background check has the same blind spot, and it is a more specific blind spot than it first appears. A background check confirms that a real identity exists and that nothing bad is attached to it. It does not confirm that the person in the interview is the one that identity belongs to. When the identity is stolen from a real US citizen with a clean record, a background check returns clean because the record is clean. It is answering a different question from the one you need answered.

Why you cannot do this by hand

An analyst can run the checks in the rest of this piece manually. It takes a few hours per candidate, and it costs the same few hours whether the answer turns out to be interesting or not.

At real hiring volume that budget does not exist, so one of two things happens. The check gets skipped, or it gets run only on candidates who already looked wrong. The second is worse than it sounds. A prepared identity is built specifically to not look wrong, so screening on suspicion searches the population least likely to contain one.

Filtering by stage is different from filtering by suspicion. Running the check on everyone who reaches a given stage is fine, because the stage is not correlated with the thing being hidden. Running it on the people who struck someone as off is close to useless, because that is the one filter the operation has already been built to pass.

What a real person leaves behind

Someone who has been online for a decade leaves a trail they never curated. Three questions on Stack Overflow from 2019. A comment on somebody else's bug report. An attendee list from a conference in a city they used to live in. An expired domain. A username that also appears on a forum about mechanical keyboards, tied to the same address as a Steam profile.

None of that was created to prove anything, and that is what makes it expensive to reproduce. One convincing profile is cheap. Ten years of incidental presence, spread across services that do not talk to each other and that nobody thought to coordinate, is not.

The four signals

Thinness. Presence exists but has no age and no incidental edges. Every account was created inside a narrow window, and none of them connect to anything outside the professional story.

Contradiction. The timeline does not survive cross-referencing. Two roles overlap by eight months. A degree comes from a university whose alumni records do not carry the name. A stated location disagrees with the timezone on the commits.

Reuse. The same photograph, phone number, device fingerprint or payment detail appears under a different name somewhere else. Reuse has real innocent explanations, and they are common: people change names on marriage or transition, carriers recycle numbers constantly, and families share devices. What survives that is narrower and still useful, which is the same photograph presenting as two different people on two currently active professional profiles. Its value is that it is invisible to anyone looking at one application at a time, because it requires a corpus the candidate cannot see.

Infrastructure. The residential address is a mail forwarder. The phone number is VOIP. The bank account was opened six weeks ago. The laptop's traffic terminates somewhere the CV never mentions.

How the check runs

Sixtyfour's agent starts from whatever the application already contains: an email address, a phone number, a code hosting handle, a name. It never takes the CV's account of the person as its starting point, so it cannot be steered by what the CV chooses to mention.

It cross-references breach records, public records, social profiles, code hosting, forums and archived pages, and weights each hit by how hard that hit would have been to manufacture. An account opened last year counts for very little. A forum post from 2016, sitting in a thread with other people replying to it, counts for a lot.

What that looks like on one candidate

The run below is a composite assembled from the pattern, not one real case.

A backend role. The candidate gives an email address, a CV listing four years across two companies, and an active GitHub.

The agent runs the address. Inside a minute it has the GitHub, a LinkedIn created in the same month as the GitHub, one social account with nine followers, and nothing else. There are no breach records at all, which is unusual for an address a CV implies has been in use for eight years. The phone number sits in a VOIP range.

Then the timeline. The CV puts four years at a company in one city. The commit timestamps cluster in a working day nine hours away from it.

One thing does not resolve. There is a GitHub contribution history going back six years, which is older than everything else and does not fit the rest of the picture. It could be a purchased account, or it could be the one genuine thing in the application. The check cannot say which, and reporting it as suspicious would be guessing.

So the output is three concrete inconsistencies and one open question. That is a list of things to ask about, and it arrives before anyone has spent an hour on a call.

What defeats this

An identity that was aged deliberately. Any operation prepared to open accounts two years before it uses them, post in real threads, and let the presence accumulate will produce a footprint that looks earned, because in the sense that matters it was.

A purchased account with real history attached. A real person renting out their own past, which leaves genuine incidental presence and a genuine owner who will answer a reference call.

This method raises the cost of a convincing identity. It does not close the door, and anyone selling it as a door is selling something else. The public cases are the operations that did not spend enough.

Where this gets it wrong

Plenty of real people have thin footprints. Someone who stays off social media. Someone who moved countries recently and left their earlier presence in another language and another alphabet. Someone who is twenty-two. A system tuned to read thinness as fraud rejects all three, and those rejections are invisible, because nobody appeals a hiring decision whose reason they were never told.

Some of the published advice on this topic is worse than useless. Guidance that treats an accent, a non-US phone number, or a name that does not match an interviewer's expectation of a face as a fraud signal is describing national origin, and acting on it is both illegal in most places we operate and a reliable way to reject real engineers. None of the four signals above are that, and that is deliberate.

There is a legal shape to this as well. Obtaining a report about a candidate from a third party and using it in a hiring decision can bring the check inside the Fair Credit Reporting Act in the US, with consent and adverse action obligations attached, and there are equivalents elsewhere. Sixtyfour is not a consumer reporting agency and the output is built to inform the questions you ask, not to be the decision. Where that line sits for your process is a conversation to have with your counsel before you wire anything up.

So thinness on its own only justifies looking closer. Contradiction and photo reuse are stronger, and both call for an explanation rather than a conclusion.

The setup we recommend is a review queue: the check runs on every candidate who reaches a defined stage, and anything it flags goes to a person. The scoring is good enough to act on. A person sits at the end of it because the question being answered is whether to take someone's job away from them before they have it, and somebody should have to look at that and decide.

“Every artifact the hiring process inspects is an artifact that was prepared for it.”
Julian Wong Head of Trust & Safety, Sixtyfour
1200 × 630 — ready to share

Frequently asked

Usually not. A background check confirms that a real identity exists and that nothing bad is attached to it, which is a different question from whether the person in the interview is the one that identity belongs to. When an identity is stolen from a real citizen with a clean record, the check comes back clean because the record is clean. Gartner makes the same point in its own research: background checks assess whether someone is safe to hire, not whether they are who they say they are.

Largely you cannot, and building the process around it is the mistake. The North Korean operative KnowBe4 hired appeared on camera in four separate video interviews and passed all four. Real-time face and voice manipulation keeps getting cheaper, so the interview is the wrong place to carry the load. Screen the application, before anyone books a call.

That figure is a Gartner projection, and it is quoted more often than it is read. It covers a spectrum of misrepresentation running from AI-polished resume wording at one end to a fully constructed identity at the other, so it is not a forecast that a quarter of your candidates will be impostors. Treat it as a direction of travel rather than a rate.

Someone inside the target country who receives the company-shipped laptop and keeps it running on a domestic network, while the actual worker connects to it from somewhere else. It is what makes the shipping address and the network location look ordinary. In one US case the Justice Department seized more than 90 laptops from a single home in Arizona.

Skilled engineers working under stolen or invented identities to take remote jobs at Western companies, with the wages routed back to North Korea. The Justice Department's June 2025 actions covered searches of 29 known or suspected laptop farms across 16 states, and in one case alone the government says the identities of more than 80 US citizens were used to obtain jobs at more than 100 US companies.

Look for age and incidental connections rather than completeness. A profile built to pass inspection is complete, recent and self-contained, while a real one has a messy trail around it: people who worked at those companies at those times, activity that predates the job search, and traces on services that have nothing to do with hiring. A polished profile with a narrow creation window and nothing around it is the one to look at twice.

Sanctions exposure can attach whether or not you knew, so it is a legal question before it is an IT one. Published guidance is consistent that you should not confront the worker, because tipping them off destroys evidence and can invite extortion. Contain the access, preserve what you have, and bring in counsel and law enforcement.

Get started

See how Sixtyfour resolves an applicant's identity across public records, breach data and code hosting.

Request a Demo
  1. The operation behind it
  2. What this looks like from inside a security company
  3. Why the interview is the wrong place to look
  4. Why you cannot do this by hand
  5. What a real person leaves behind
  6. The four signals
  7. How the check runs
  8. What that looks like on one candidate
  9. What defeats this
  10. Where this gets it wrong