In July 2024 a well-known security awareness company disclosed that it had recruited, onboarded and issued a laptop to a North Korean operative posing as an American software engineer. The candidate had passed several video interviews and a background check. He was identified only when monitoring software flagged him installing malware on the machine the company had sent him, days into the job.

The company published the account deliberately, and the decision was a service to everyone else, because the failure was not unusual and the controls involved were not weak.

This is identity fraud, not conduct risk

Most hiring safeguards are built to answer a question about behavior. They look for undisclosed convictions, exaggerated qualifications, gaps in employment and conflicts of interest, all of which assume that the person being examined exists and is the person in the interview.

The scheme described here begins one step earlier. The identity itself is constructed, frequently from a real person’s stolen details, and every document supporting it is internally consistent because it was assembled to be. A check that verifies the coherence of a file will pass it, and the more thorough the check, the more confidence the result carries.

United States prosecutors have pursued the infrastructure that makes this work at scale. One indictment described five defendants who obtained work from at least sixty-four American companies between April 2018 and August 2024, with payments from ten of them alone generating more than $866,000. The laptops issued to those workers sat in domestic residences, so that connections appeared to originate where the employer expected.

Empty boardroom with an oval table and tan leather chairs

The candidate passed several video interviews and a background check. Every document supporting the identity was internally consistent, because it had been assembled to be.

Remote onboarding removed checks nobody had listed

Distributed hiring is settled practice, and the argument here is not against it. What is worth being precise about is exactly which checks were lost when onboarding stopped happening inside a building.

Somebody used to hand over a laptop in person. Somebody witnessed the original documents rather than a scan. New joiners were seen by dozens of colleagues in their first week, in a setting where an inconsistency would have been noticed without anyone being assigned to look for it. None of that was ever written down as a control, which is why none of it appeared on a list when it disappeared.

What verification actually requires

The distinction that matters is between documents the candidate supplies and facts established independently of them. Screening that relies on the former can only confirm that a story is coherent.

  • Confirm the employment history with the employer rather than the referee. A supplied reference contact is part of the candidate’s submission, and in constructed identities it is frequently part of the construction.
  • Verify credentials at the issuing institution. A certificate is an artefact, and artefacts are straightforward to produce convincingly.
  • Establish continuity of the identity over time. A real person leaves a long, untidy trail across many sources; a constructed one tends to be tidy and shallow, and the tidiness is the signal.
  • Reconcile the stated location with observable reality. Where equipment ships, where the person banks and where they connect from should agree, and a mismatch is worth a conversation rather than an assumption.

For senior appointments this is the ordinary territory of executive background investigations, where the expectation is already that findings are sourced rather than collected. The change worth making is applying a proportionate version of the same logic further down the organization, because the access granted to a mid-level engineer is frequently broader than that granted to a director.

Hundreds of unsorted jigsaw pieces face up, none of them joined

A real person leaves a long and untidy trail across many independent sources. A constructed identity tends to be tidy and shallow, and the tidiness is the signal worth acting on.

The exposure is access, not payroll

Read as a fraud, the loss is a salary paid to somebody not entitled to it, which for most organizations is an irritation rather than a crisis.

Read as an access problem, it is considerably more serious. The organization has issued credentials, granted network access and admitted somebody to internal systems on the strength of an identity it never confirmed, and the person holding those credentials is inside every perimeter that was built to keep outsiders out. Whatever monitoring exists is watching for an intruder rather than for a colleague.

That is the reason this belongs alongside cybersecurity rather than in a human resources process. The hiring decision is the point at which access is granted, and it is the only point at which the question can be asked cheaply.

The question for a board

Take the last ten fully remote hires and establish, for each, which facts were confirmed with a source the candidate did not nominate. Where the answer is none, the organization has verified a set of documents rather than a person.

The second question is about proportion. Access, rather than seniority, should determine how much verification a role attracts, and most organizations have those two things the wrong way round. Our Book of the Month shelf has How Spies Think, which is useful here for its treatment of how analysts test what they are being told rather than how much of it they collect.


Falcone International

Bring us a question like this one

We handle corporate investigations, due diligence, financial investigations and duty of care — usually for people who need something established quietly, and established properly, before it turns into a problem.

Talk to usSee what we do

Discover more Insights from Falcone International

“Never Split the Difference” offers an inside look into the world of high-stakes hostage negotiations, translated into tactics for personal and business use. Chris Voss, a former FBI negotiator, shares strategies that center around empathy, active listening, and tactical mirroring to sway outcomes. This book is an essential guide for anyone aiming to improve their negotiation skills and interpersonal effectiveness.

In “On Intelligence,” John Hughes-Wilson offers an insightful journey through the clandestine world of intelligence and espionage. Covering historical events to modern dilemmas, the book illuminates the inner workings of intelligence agencies and their impact on world history. This exploration encourages critical thinking about the role of intelligence in society and the ethical issues it presents.

Fraud rises when budgets tighten. Pressure goes up, headcount comes down, and controls that quietly depended on someone having spare time stop working. This weekend read sets out where exposure concentrates during a downturn and which defenses actually hold: strong internal controls, systems that flag the patterns people miss, a crisis plan written before it is needed, and a culture in which raising an anomaly is not a career risk.

Joel Brenner sets the demand for transparency against the need for secrecy and finds that most institutions have no coherent answer to the collision. “Glass Houses” is less a privacy book than an account of what secrecy now costs, who can still maintain it, and how little of it survives in a world where nearly every action leaves a record somewhere.

Discover how we use our integrated capabilities for our clients

Case Studies and Client Stories