Leadership1 publisher3 min readPublished
Candidate fraud lands on recruiters while InfoSec, IT and legal stay out of the interview loop
A hiring podcast argues that state-backed operations now train workers to apply for remote jobs with stolen credentials and proxy interviewers. The guest making the case works for the vendor selling the fix.
The Board Room · Leadership desk

What happened
- Episode 825 of the Recruiting Future podcast says state-backed operations are training workers to apply for remote roles using stolen credentials and proxy interviewers.
- The stated objective is the salary plus access to source code, customer data and intellectual property once the operative is inside the organisation.
- In most organizations, according to the episode, recruiters assess these applicants with a background check and their own judgment while IT, InfoSec and legal are rarely involved.
- Remote hiring removed the continuity in-person processes provided, and the episode says every handoff to a new interviewer creates an opening for proxy interviewers and manipulated video.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- decision Two choices sit with an executive this quarter: where in the interview process verification runs, and who signs off when a hiring manager wants it skipped.
- constraint A one-time check at application cannot cover a loop with multiple handoffs, so the control has to be designed into every stage of it.
- exposure The loss from a bad hire here lands on the security and legal side of the house, while the miss happened in a recruiting workflow measured on speed.
- contradiction The diagnosis and the remedy come from the same commercial interest. That bears on how much weight the incidence forecast can carry next to the described attack mechanics.
A tool purchase leaves ownership open. Verification sits inside a process recruiting is measured on, and a control placed there gets waived when a role is urgent, unless someone outside recruiting signs the waiver. The show notes for episode 825 of Recruiting Future put the current state plainly: recruiters are largely being left to spot this on their own, when InfoSec, IT and legal should be sharing the responsibility [6]. Host Matt Alder said recruiters are "on the front line here, and in many cases, the only tool they have to manage this huge business risk is their own judgement" [5].
The gap described sits between the checks. An in-person process supplied continuity by default, and remote hiring removed it, so each handoff to a new interviewer opens room for a proxy interviewer or manipulated video [8]. One verification at application does not close that. The check has to hold from first screen to first day. That means changing who does what at each stage of the loop.
Background checks remain a foundational part of hiring, the episode says, and are no longer sufficient on their own against this level of sophistication [7]. A check confirms a record against a name. Whether the person on the fourth video call is the person attached to that record is a separate question, and the episode argues recruiters overestimate their ability to spot a fake [13].
On incidence, the evidence thins. Lauren Furey, the guest, is Principal Product Manager at Proof, where she leads product work on candidate fraud and identity verification, and Proof provides the podcast's sponsorship [1][14]. The most quotable number comes from the sponsor read, where Alder said "You've probably heard that by 2028, one in four job applicants is predicted to be fake" [10]. The read does not name who made that prediction [18]. In the same segment, Alder said "Today, scammers are sending one person to get the offer and a totally different person to start the job" [11], and described Proof as integrated with applicant tracking systems including Lever, covering first interview through onboarding [12].
That leaves two kinds of material at different strengths. The mechanics are specific enough for a security team to test against its own interview records: stolen credentials, proxy interviewers, handoffs between panels [2][8]. The 25 percent figure is a forecast from a party that sells the remedy [16][14].
The decision this quarter is narrow. Where verification sits in the process, and who is allowed to skip it, are both listed by the episode as the live trade-off against candidate experience [13]. The longer question is verifiable credentials and protecting candidates' own identities, which the episode also raises [13]. Its notes expect identity verification and identity continuity to become an organic part of the application and interview process, with a significant increase during 2027 [9], one year ahead of the date in the sponsor's prediction [15].
What to watch
- Whether published hiring policies name InfoSec as the owner of a verification waiver.
- Incidence data on fake applicants from a party that does not sell identity verification.
- Whether applicant tracking vendors ship verification natively. That would change the buy decision from tool to configuration.