Case Study: When the Hire Is the Intrusion | Breacher.ai
HR Social Engineering: When the Hire Is the Intrusion
We were scoped to reach a North American organization through its hiring pipeline. We built a candidate who does not exist, and the screening cleared him. Nothing had to be broken into, because the organization was preparing to hand over the credentials itself.
The engagement was authorized, scoped, and signed. The objective was plain: reach the organization through talent acquisition rather than through the perimeter, and document where the process stopped us.
The persona was assembled the way an adversary would assemble one. A professional profile with a history that had been in place long enough to look unremarkable. A resume written against the open requisition. A working phone number. Then a live video interview held by a synthetic face that stayed in character for the full session.
The screening cleared him. Not because anyone was careless, and not because the recruiting team was under-trained. It cleared him because at no point in the process was there a step whose purpose was to establish that the person on the call was a real individual with a verifiable identity. There was assessment, and there was a lot of it. There was no verification.
That distinction is the whole article. Given a scope that permits it, we expect to reach an offer, and the reason has nothing to do with how good our video is. It is that most hiring pipelines have never had a control designed to answer the question we are quietly asking them.
Sources for the figures above: Gartner newsroom, 31 July 2025 for the projection and the survey, and Fortune, 11 April 2025 for the single-role figure. Each carries its own denominator, which is the only form in which a number like this is worth quoting.
Why the Hiring Pipeline Is the Softest Path Into an Organization
Every other social engineering route has to work around the fact that the target already has access and the adversary does not. The hiring path removes that problem. The organization issues the credentials, ships the hardware, creates the payroll record, and adds the account to the groups the role requires. The access is not stolen. It is provisioned, correctly, according to policy, to a person who was never verified.
Security teams have spent a decade mapping consequential actions in finance, in IT, and at the help desk. Wire transfers have a callback rule. Credential resets have a procedure, even where it is weak. Ask the same team to produce the written verification requirement that governs granting a new joiner their first set of credentials, and the usual answer is that identity was somebody else's step, and that somebody else believed it had already happened.
There is a second reason this path holds up, and it is organizational rather than technical. Talent acquisition is measured on time to fill. Every verification step is friction against the number the team is judged on, in a market where a strong candidate is assumed to have other offers. The pressure inside the process runs toward advancing the applicant, and a control that runs against the grain of the incentive is a control that gets waived first.
How the Sequence Runs
This is the shape of it, as we build it and as the public reporting describes real cases. Nothing in it is exotic. It is patience, research, and a process that never asked the question.
The persona exists before the requisition does
A professional profile with age on it, a history that matches the market it claims, a phone number that rings, and a resume tuned to the role. None of this touches your environment, so none of it generates an alert. The work happens entirely in public and entirely in advance.
The application arrives through a normal channel
Job board, referral, or agency. The agency route is the more interesting one, because it inserts a third party who is assumed to have done a check and who is being paid on placement. Two parties each believe the other verified the applicant, which is how an uncovered path forms without anyone deciding to leave it uncovered.
The recruiter screen
A short call about availability, notice period, and salary expectations. It is a qualifying conversation, not a verification step, and the questions it asks are questions any competent operator can answer. This is the stage most often described afterwards as the point where somebody should have noticed something, which is a request for a person to substitute for a procedure.
The live video interview
A synthetic face and a cloned voice hold a real conversation about real technical content. The interviewer's task is to assess capability, and capability is demonstrable by whoever is answering. Watch what the interview actually compares: an impression formed in forty minutes against no authoritative record of any kind. It is a strong assessment instrument and it was never an identity instrument.
The offer and the access grant
This is the consequential action, and it is the one worth measuring. Between the signed offer and the first login there is a sequence of steps that each assume identity was settled earlier: right to work paperwork collected but not verified against the issuing source, hardware shipped to whatever address was supplied, accounts created from the requisition rather than from a proofing record. If a single one of those steps required an independent check, the sequence stops here. In most organizations, none of them do.
The payroll period, and the turn
An employee who performs adequately draws no attention. The access matures, the tenure normalizes, and repositories, customer records, and internal documentation become routine reads rather than anomalous ones. The exfiltration, when it comes, looks like work. The extortion demand arrives after the departure, addressed to a former employer who is holding an offboarding checklist rather than an incident.
The Prediction, and the Filing
A year ago we said on camera that this would end in double extortion, that the fraudulent worker model would not stay a salary scheme, and that the natural progression was employment, then access, then data, then a ransom demand against the employer. That call is on the record, and it was not a difficult one to make. Once an adversary is inside the trust boundary with legitimate credentials, holding the data is simply a higher-yield exit than collecting a paycheck.
The public record has caught up. In January 2025 the FBI issued an advisory reporting that fraudulent remote IT workers had escalated to stealing proprietary data and code from their employers and holding it for ransom, releasing it publicly where the demand was refused. The same advisory described repositories copied to personal cloud accounts and session cookies harvested to work from devices the employer never issued.
The enforcement record gives the scale. In one prosecution, workers placed through a single facilitation network obtained employment at more than 64 United States companies, and the victim organizations reported more than one million dollars in costs auditing and remediating the systems those workers had touched. In a separate case, the Department of Justice described a scheme that reached more than 100 companies using the stolen identities of at least 80 people.
Read those numbers as coverage findings rather than as news. Every one of those companies ran a hiring process. The process worked exactly as designed. Design was the problem.
Why Interview Detection Fails Against This
The reflex is to train the interviewer. Teach recruiters the tells, add a module, and call it a control. It fails for three separate reasons, and each one is sufficient on its own.
It teaches this quarter's defects. The standard advice is to ask the candidate to turn their head, or to pass a hand in front of their face, because older rendering breaks under occlusion and fast motion. That advice worked. It works less well every release, and the rate at which it decays is set by the adversary rather than by the buyer. A control whose value is scheduled to decline is not a control, it is a countdown.
It puts the decision on the person with the least support for making it. A recruiter on their fifth call of the day, holding a requisition that has been open for eleven weeks, is being asked to make a media forensics judgment with no tooling and no second opinion. Trained analysts get this wrong with software assistance.
It produces confidence, which is the ingredient the pretext needs. A hiring manager who has completed deepfake awareness training and believes they can tell is a more useful target than one who knows they cannot, because the first one stops looking for a procedure and starts trusting a feeling.
That distinction is worth holding precisely, because the honest version of this argument is stronger than the loud one. Improving synthetic media does not break a procedural control. The procedure returns the same result against a crude fake and a perfect one, because it never examines the artifact. What rising quality changes is the rate at which people grant an exception to the procedure, and exception rate is measurable. Claiming perfect invariance is an invitation for somebody to falsify it in front of you.
The other bound worth stating: procedure is executed by people, so this is not an argument that users are irrelevant. It is an argument about which human behavior to measure. Perception is not trainable in any durable way. Compliance under pressure is trainable, observable, and repeatable, which makes it the better variable.
The Controls That Hold
Each of the following returns the same answer whether the person on the interview is real or rendered.
- Proof the identity against the issuing source. A government-issued document checked against the authority that issued it, with supervised proofing, and in person where the role and geography allow it. The FBI's guidance to employers is to complete as much of hiring and onboarding in person as the business permits, which is a control statement rather than a preference.
- One standard, regardless of worker type. Direct hires, contractors, agency placements, and rebadged staff pass the same proofing step. A requirement that applies to permanent employees and not to the contractor with the same access is not coverage, it is a documented exception with a queue forming behind it.
- Cross-check the pipeline for reuse. Run duplicate detection across the applicant tracking system on phone numbers, email addresses, and resume text. Reused contact details across applicants presented as different people is one of the specific indicators the FBI advisory names, and it is a query rather than a project.
- Bind hardware and payroll to a verified address of record. The device ships to the verified address, and a change of address or payment platform during onboarding triggers re-verification rather than a routine update. That change request is the single most reliable signal in the entire sequence.
- Verify references on the number of record. Reach the referring organization through its published line rather than the number supplied on the resume. This is the same out-of-band callback control finance already applies to a vendor bank detail change, pointed at a different consequential action.
- Separate the access grant from the hiring decision. Provisioning requires a completed proofing record, not merely a signed offer. This is the change that converts hiring from an uncovered path into a covered one, and it can be made without buying anything.
- Give the recruiter an escalation path that costs less than proceeding. If raising a concern means a form, a delay, and a conversation about the requisition slipping, the process has already chosen its outcome. One route, one owner, no judgment call required about whether the concern was worth raising.
None of these ask anyone to be a detector. They ask the organization to have a procedure at the point where something consequential happens, which is a thing organizations already know how to build, staff, and audit.
Measure the Right Thing
If the reporting on a hiring exercise says how many people felt suspicious, it has measured a mood. These are the questions that produce a remediation plan.
The distinction between skipped and waived is the one worth instrumenting, because the two failures need different fixes. A verification that was never attempted is a coverage problem, solved by writing the requirement and putting it in the workflow. A verification that was attempted and then granted an exception is an adherence problem, solved by removing the authority to waive it at that level. Reporting both as one number sends the remediation budget to the wrong place.
Findings are named against procedures, not against people. A recruiter who advanced a persona through a process that contained no verification step did their job correctly, and a report that says otherwise will be rejected by the business, deservedly.
Coverage can be assessed on paper. Adherence cannot. Writing down which steps in the joiner process carry a verification requirement is a desk exercise, and it is the right place to start because it costs nothing and it can be done this week. What no document review, no questionnaire, and no policy audit will tell you is whether that requirement survives contact with a candidate who is patient, credible, and pushing against a requisition that has been open for eleven weeks. Only an authorized red team engagement answers that, because it is the only instrument that builds the persona, puts it through the real pipeline, and keeps going until a control stops it or nothing does.
That is the difference between a hiring process that has controls and one that has assumptions with a workflow attached. Both look identical in a policy document. They stop looking identical the moment somebody applies for a job who is not real.
What We Would Do First
Three things, none of which require a purchase, a project, or our involvement.
Write down the joiner process as a list of consequential actions. Offer issued, right to work collected, identity proofed, hardware shipped, accounts created, groups assigned, first login. Mark each one with the written verification requirement that governs it. The blanks are the finding, and most organizations have never produced this list even once.
Run the duplicate query. Search the applicant tracking system for phone numbers, email addresses, and resume passages appearing under more than one applicant name. It takes an afternoon and it is one of the few checks in this whole domain that is both cheap and specific.
Move the proofing gate. If identity proofing currently sits after the offer as a paperwork exercise, move it in front of the access grant and make provisioning refuse to proceed without it. That single change is the difference between a process that assumes identity and one that establishes it.
Then test it. We wrote up the mechanics of building and running a synthetic candidate against a live pipeline in our deepfake candidate research. Where your exposure sits in the customer onboarding stack rather than the hiring pipeline, that is a KYC penetration assessment, and where the same pretext arrives on the phone against a help desk, that is AI vishing simulation.
Frequently Asked Questions
What is HR social engineering?
HR social engineering is the manipulation of a hiring or people operations process to obtain something the organization would not otherwise grant, most often employment itself. The pretext is a candidate rather than an executive or a help desk caller, and the consequential action is the access grant at the end of onboarding: credentials, a device, a payroll record, and a place inside the trust boundary. It also runs in the other direction, where a caller impersonating a candidate, an employee, or a payroll provider persuades a people operations team to change a direct deposit record or release personal data.
How does a fabricated candidate get through a live video interview?
The interview is a conversation, not an identity check. A synthetic face and a cloned voice delivered into the meeting are enough to satisfy an interviewer whose actual task is assessing competence, and competence can be demonstrated by whoever is answering. The stronger reason is structural: nothing in a standard interview compares the person on the call against an authoritative record. The interviewer forms an impression, and an impression is not a verification step.
Can recruiters be trained to spot a deepfake candidate?
Not durably, and it is the wrong control to build a hiring program on. Detection training teaches the current generation of defects, such as asking a candidate to turn their head or pass a hand in front of their face, and those defects are being engineered out release by release. The control also sits with the wrong person, because a recruiter is measured on time to fill and is being asked to make a forensic media judgment with no tooling. Procedural identity proofing returns the same result regardless of how convincing the video is.
What controls actually stop a fraudulent hire?
Identity proofing against the issuing source rather than against a video feed, applied to remote hires, contractors, and agency-sourced staff at the same standard. Duplicate checks across the applicant tracking system for reused phone numbers, email addresses, and resume content. Hardware and payroll bound to a verified address of record, with a change during onboarding treated as a re-verification trigger rather than a routine update. Reference checks placed to the referring organization's published number rather than one supplied by the candidate. And a provisioning gate that requires a completed proofing record before any access is granted.
How should a hiring pipeline simulation be measured?
On coverage and adherence rather than on whether anyone felt suspicious. Coverage is the share of consequential actions in the joiner process that carry a written, channel-independent verification requirement. Adherence is whether that requirement was executed, skipped, or consciously waived when a persona applied pressure. Alongside those, record how far the persona advanced, which control stopped it, and how long elapsed before the first independent identity check. Findings are reported against the procedure, never against the recruiter who took the call.
Find Out Where Your Hiring Process Stops Us
We run the persona through your real pipeline under signed authorization, report how far it advanced and which control caught it, and hand back the coverage gaps at the organization level.
Book Your DemoHR Social Engineering: When the Hire Is the Intrusion
We were scoped to reach a North American organization through its hiring pipeline. We built a candidate who does not exist, and the screening cleared him. Nothing had to be broken into, because the organization was preparing to hand over the credentials itself.
The engagement was authorized, scoped, and signed. The objective was plain: reach the organization through talent acquisition rather than through the perimeter, and document where the process stopped us.
The persona was assembled the way an adversary would assemble one. A professional profile with a history that had been in place long enough to look unremarkable. A resume written against the open requisition. A working phone number. Then a live video interview held by a synthetic face that stayed in character for the full session.
The screening cleared him. Not because anyone was careless, and not because the recruiting team was under-trained. It cleared him because at no point in the process was there a step whose purpose was to establish that the person on the call was a real individual with a verifiable identity. There was assessment, and there was a lot of it. There was no verification.
That distinction is the whole article. Given a scope that permits it, we expect to reach an offer, and the reason has nothing to do with how good our video is. It is that most hiring pipelines have never had a control designed to answer the question we are quietly asking them.
Sources for the figures above: Gartner newsroom, 31 July 2025 for the projection and the survey, and Fortune, 11 April 2025 for the single-role figure. Each carries its own denominator, which is the only form in which a number like this is worth quoting.
Why the Hiring Pipeline Is the Softest Path Into an Organization
Every other social engineering route has to work around the fact that the target already has access and the adversary does not. The hiring path removes that problem. The organization issues the credentials, ships the hardware, creates the payroll record, and adds the account to the groups the role requires. The access is not stolen. It is provisioned, correctly, according to policy, to a person who was never verified.
Security teams have spent a decade mapping consequential actions in finance, in IT, and at the help desk. Wire transfers have a callback rule. Credential resets have a procedure, even where it is weak. Ask the same team to produce the written verification requirement that governs granting a new joiner their first set of credentials, and the usual answer is that identity was somebody else's step, and that somebody else believed it had already happened.
There is a second reason this path holds up, and it is organizational rather than technical. Talent acquisition is measured on time to fill. Every verification step is friction against the number the team is judged on, in a market where a strong candidate is assumed to have other offers. The pressure inside the process runs toward advancing the applicant, and a control that runs against the grain of the incentive is a control that gets waived first.
How the Sequence Runs
This is the shape of it, as we build it and as the public reporting describes real cases. Nothing in it is exotic. It is patience, research, and a process that never asked the question.
The persona exists before the requisition does
A professional profile with age on it, a history that matches the market it claims, a phone number that rings, and a resume tuned to the role. None of this touches your environment, so none of it generates an alert. The work happens entirely in public and entirely in advance.
The application arrives through a normal channel
Job board, referral, or agency. The agency route is the more interesting one, because it inserts a third party who is assumed to have done a check and who is being paid on placement. Two parties each believe the other verified the applicant, which is how an uncovered path forms without anyone deciding to leave it uncovered.
The recruiter screen
A short call about availability, notice period, and salary expectations. It is a qualifying conversation, not a verification step, and the questions it asks are questions any competent operator can answer. This is the stage most often described afterwards as the point where somebody should have noticed something, which is a request for a person to substitute for a procedure.
The live video interview
A synthetic face and a cloned voice hold a real conversation about real technical content. The interviewer's task is to assess capability, and capability is demonstrable by whoever is answering. Watch what the interview actually compares: an impression formed in forty minutes against no authoritative record of any kind. It is a strong assessment instrument and it was never an identity instrument.
The offer and the access grant
This is the consequential action, and it is the one worth measuring. Between the signed offer and the first login there is a sequence of steps that each assume identity was settled earlier: right to work paperwork collected but not verified against the issuing source, hardware shipped to whatever address was supplied, accounts created from the requisition rather than from a proofing record. If a single one of those steps required an independent check, the sequence stops here. In most organizations, none of them do.
The payroll period, and the turn
An employee who performs adequately draws no attention. The access matures, the tenure normalizes, and repositories, customer records, and internal documentation become routine reads rather than anomalous ones. The exfiltration, when it comes, looks like work. The extortion demand arrives after the departure, addressed to a former employer who is holding an offboarding checklist rather than an incident.
The Prediction, and the Filing
A year ago we said on camera that this would end in double extortion, that the fraudulent worker model would not stay a salary scheme, and that the natural progression was employment, then access, then data, then a ransom demand against the employer. That call is on the record, and it was not a difficult one to make. Once an adversary is inside the trust boundary with legitimate credentials, holding the data is simply a higher-yield exit than collecting a paycheck.
The public record has caught up. In January 2025 the FBI issued an advisory reporting that fraudulent remote IT workers had escalated to stealing proprietary data and code from their employers and holding it for ransom, releasing it publicly where the demand was refused. The same advisory described repositories copied to personal cloud accounts and session cookies harvested to work from devices the employer never issued.
The enforcement record gives the scale. In one prosecution, workers placed through a single facilitation network obtained employment at more than 64 United States companies, and the victim organizations reported more than one million dollars in costs auditing and remediating the systems those workers had touched. In a separate case, the Department of Justice described a scheme that reached more than 100 companies using the stolen identities of at least 80 people.
Read those numbers as coverage findings rather than as news. Every one of those companies ran a hiring process. The process worked exactly as designed. Design was the problem.
Why Interview Detection Fails Against This
The reflex is to train the interviewer. Teach recruiters the tells, add a module, and call it a control. It fails for three separate reasons, and each one is sufficient on its own.
It teaches this quarter's defects. The standard advice is to ask the candidate to turn their head, or to pass a hand in front of their face, because older rendering breaks under occlusion and fast motion. That advice worked. It works less well every release, and the rate at which it decays is set by the adversary rather than by the buyer. A control whose value is scheduled to decline is not a control, it is a countdown.
It puts the decision on the person with the least support for making it. A recruiter on their fifth call of the day, holding a requisition that has been open for eleven weeks, is being asked to make a media forensics judgment with no tooling and no second opinion. Trained analysts get this wrong with software assistance.
It produces confidence, which is the ingredient the pretext needs. A hiring manager who has completed deepfake awareness training and believes they can tell is a more useful target than one who knows they cannot, because the first one stops looking for a procedure and starts trusting a feeling.
That distinction is worth holding precisely, because the honest version of this argument is stronger than the loud one. Improving synthetic media does not break a procedural control. The procedure returns the same result against a crude fake and a perfect one, because it never examines the artifact. What rising quality changes is the rate at which people grant an exception to the procedure, and exception rate is measurable. Claiming perfect invariance is an invitation for somebody to falsify it in front of you.
The other bound worth stating: procedure is executed by people, so this is not an argument that users are irrelevant. It is an argument about which human behavior to measure. Perception is not trainable in any durable way. Compliance under pressure is trainable, observable, and repeatable, which makes it the better variable.
The Controls That Hold
Each of the following returns the same answer whether the person on the interview is real or rendered.
- Proof the identity against the issuing source. A government-issued document checked against the authority that issued it, with supervised proofing, and in person where the role and geography allow it. The FBI's guidance to employers is to complete as much of hiring and onboarding in person as the business permits, which is a control statement rather than a preference.
- One standard, regardless of worker type. Direct hires, contractors, agency placements, and rebadged staff pass the same proofing step. A requirement that applies to permanent employees and not to the contractor with the same access is not coverage, it is a documented exception with a queue forming behind it.
- Cross-check the pipeline for reuse. Run duplicate detection across the applicant tracking system on phone numbers, email addresses, and resume text. Reused contact details across applicants presented as different people is one of the specific indicators the FBI advisory names, and it is a query rather than a project.
- Bind hardware and payroll to a verified address of record. The device ships to the verified address, and a change of address or payment platform during onboarding triggers re-verification rather than a routine update. That change request is the single most reliable signal in the entire sequence.
- Verify references on the number of record. Reach the referring organization through its published line rather than the number supplied on the resume. This is the same out-of-band callback control finance already applies to a vendor bank detail change, pointed at a different consequential action.
- Separate the access grant from the hiring decision. Provisioning requires a completed proofing record, not merely a signed offer. This is the change that converts hiring from an uncovered path into a covered one, and it can be made without buying anything.
- Give the recruiter an escalation path that costs less than proceeding. If raising a concern means a form, a delay, and a conversation about the requisition slipping, the process has already chosen its outcome. One route, one owner, no judgment call required about whether the concern was worth raising.
None of these ask anyone to be a detector. They ask the organization to have a procedure at the point where something consequential happens, which is a thing organizations already know how to build, staff, and audit.
Measure the Right Thing
If the reporting on a hiring exercise says how many people felt suspicious, it has measured a mood. These are the questions that produce a remediation plan.
The distinction between skipped and waived is the one worth instrumenting, because the two failures need different fixes. A verification that was never attempted is a coverage problem, solved by writing the requirement and putting it in the workflow. A verification that was attempted and then granted an exception is an adherence problem, solved by removing the authority to waive it at that level. Reporting both as one number sends the remediation budget to the wrong place.
Findings are named against procedures, not against people. A recruiter who advanced a persona through a process that contained no verification step did their job correctly, and a report that says otherwise will be rejected by the business, deservedly.
Coverage can be assessed on paper. Adherence cannot. Writing down which steps in the joiner process carry a verification requirement is a desk exercise, and it is the right place to start because it costs nothing and it can be done this week. What no document review, no questionnaire, and no policy audit will tell you is whether that requirement survives contact with a candidate who is patient, credible, and pushing against a requisition that has been open for eleven weeks. Only an authorized red team engagement answers that, because it is the only instrument that builds the persona, puts it through the real pipeline, and keeps going until a control stops it or nothing does.
That is the difference between a hiring process that has controls and one that has assumptions with a workflow attached. Both look identical in a policy document. They stop looking identical the moment somebody applies for a job who is not real.
What We Would Do First
Three things, none of which require a purchase, a project, or our involvement.
Write down the joiner process as a list of consequential actions. Offer issued, right to work collected, identity proofed, hardware shipped, accounts created, groups assigned, first login. Mark each one with the written verification requirement that governs it. The blanks are the finding, and most organizations have never produced this list even once.
Run the duplicate query. Search the applicant tracking system for phone numbers, email addresses, and resume passages appearing under more than one applicant name. It takes an afternoon and it is one of the few checks in this whole domain that is both cheap and specific.
Move the proofing gate. If identity proofing currently sits after the offer as a paperwork exercise, move it in front of the access grant and make provisioning refuse to proceed without it. That single change is the difference between a process that assumes identity and one that establishes it.
Then test it. We wrote up the mechanics of building and running a synthetic candidate against a live pipeline in our deepfake candidate research. Where your exposure sits in the customer onboarding stack rather than the hiring pipeline, that is a KYC penetration assessment, and where the same pretext arrives on the phone against a help desk, that is AI vishing simulation.
Frequently Asked Questions
What is HR social engineering?
HR social engineering is the manipulation of a hiring or people operations process to obtain something the organization would not otherwise grant, most often employment itself. The pretext is a candidate rather than an executive or a help desk caller, and the consequential action is the access grant at the end of onboarding: credentials, a device, a payroll record, and a place inside the trust boundary. It also runs in the other direction, where a caller impersonating a candidate, an employee, or a payroll provider persuades a people operations team to change a direct deposit record or release personal data.
How does a fabricated candidate get through a live video interview?
The interview is a conversation, not an identity check. A synthetic face and a cloned voice delivered into the meeting are enough to satisfy an interviewer whose actual task is assessing competence, and competence can be demonstrated by whoever is answering. The stronger reason is structural: nothing in a standard interview compares the person on the call against an authoritative record. The interviewer forms an impression, and an impression is not a verification step.
Can recruiters be trained to spot a deepfake candidate?
Not durably, and it is the wrong control to build a hiring program on. Detection training teaches the current generation of defects, such as asking a candidate to turn their head or pass a hand in front of their face, and those defects are being engineered out release by release. The control also sits with the wrong person, because a recruiter is measured on time to fill and is being asked to make a forensic media judgment with no tooling. Procedural identity proofing returns the same result regardless of how convincing the video is.
What controls actually stop a fraudulent hire?
Identity proofing against the issuing source rather than against a video feed, applied to remote hires, contractors, and agency-sourced staff at the same standard. Duplicate checks across the applicant tracking system for reused phone numbers, email addresses, and resume content. Hardware and payroll bound to a verified address of record, with a change during onboarding treated as a re-verification trigger rather than a routine update. Reference checks placed to the referring organization's published number rather than one supplied by the candidate. And a provisioning gate that requires a completed proofing record before any access is granted.
How should a hiring pipeline simulation be measured?
On coverage and adherence rather than on whether anyone felt suspicious. Coverage is the share of consequential actions in the joiner process that carry a written, channel-independent verification requirement. Adherence is whether that requirement was executed, skipped, or consciously waived when a persona applied pressure. Alongside those, record how far the persona advanced, which control stopped it, and how long elapsed before the first independent identity check. Findings are reported against the procedure, never against the recruiter who took the call.
Find Out Where Your Hiring Process Stops Us
We run the persona through your real pipeline under signed authorization, report how far it advanced and which control caught it, and hand back the coverage gaps at the organization level.
Book Your Demo
