Follow your favourite podcasts, listen offline and in the car with CarPlay and Android Auto, and always pick up where you left off. Free to try.
Remote hiring, freely available deepfake tools and harvested identities have created an opportunity that organized criminals are now taking seriously. State-backed operations are training workers to apply for remote roles using stolen credentials and proxy interviewers. The aim is the salary and access to source code, customer data and intellectual property once they are inside. Recruiters are the ones meeting these people first, and in most organizations they are assessing them with a background check and their own judgment while IT, InfoSec and legal are rarely involved. So how seriously should employers be treating this, and what does a credible response look like?
My guest this week is Lauren Furey, Principal Product Manager at Proof, where she leads product work on candidate fraud and identity verification. In our conversation, Lauren explains how these attacks work, where hiring processes are most exposed, and what TA teams can do about it.
In the interview, we discuss:
Bots, deepfakes, identity harvesting and proxy interviewers
The criminal motivations behind state-backed infiltration
Why the background check is no longer enough on its own
How much recruiters overestimate their ability to spot a fake
Why remote hiring created the gaps bad actors exploit
Building identity continuity through the hiring process
Making fraud prevention a shared responsibility with IT and InfoSec
The candidate experience trade-off and where to place verification
Verifiable credentials and protecting candidates' own identities
Practical first steps and what does the future look like?