Consider a hiring process that worked. A candidate came through a recruiter, cleared a screening call, was interviewed over video by three people on separate days, and answered the technical questions well enough that two of them argued for moving quickly. References checked out. The offer went out, the laptop shipped to an address in Arizona, and the work that followed was competent and on time.
Every stage did what it was designed to do. Not one of them established who the person was, because that isn't what any of them are for.
That is not a hypothetical. In a scheme prosecuted by the US Department of Justice, more than 100 American companies, many of them in the Fortune 500, had hired remote IT workers who were not the people whose names appeared on the contracts. The workers were based overseas. The identities belonged to real Americans who had no idea their details were in use, and the wages funded a sanctioned regime.
Hiring was never designed to answer this question
It is worth being precise about where the failure sat, because it was not a security failure in any conventional sense. No system was breached. No credential was stolen from the employer.
Each stage of a hiring process tests something real, and every one of them takes identity as given. An interview tests whether someone can do the work. A reference check tests whether a claimed history holds up, assuming the referee is genuine. A background check compares a name against records, which confirms that the name has a clean history rather than that the applicant owns it. Everything downstream inherits the assumption made at the top.
The discipline built specifically to answer that question sits in regulated finance, where kyc software confirms that a person is who they claim to be before an account is opened in their name. The question an employer now faces is the same one, arriving at a different department. A company is about to enter a contract with someone, pay them, report them to a tax authority and grant them access to its systems, on the strength of a name nobody has verified.
The difference is that a bank has been told to answer it and an employer has not.
How the scheme defeated ordinary employers
The methods described in the indictments are worth knowing, because none of them attack the interview.
The workers used stolen identity documents, including US passports carrying the personal information of real US citizens. Facilitators registered shell companies with names chosen to read as unremarkable American businesses. The operation ran pseudonymous email, social media, payment platform and job site accounts, together with false websites, so that a recruiter checking whether an employer or a profile looked legitimate would find that it did.
The laptop farms are the detail that tends to change how people think about this. Facilitators based in the United States received company laptops at their homes, installed remote access software, and used keyboard-video-mouse switches so that a worker overseas could operate the machine as though sitting in front of it. The equipment an employer shipped genuinely arrived at a US residential address, and the device checked in from the expected country every day.
What the scheme attacked, in other words, was corroboration. Each signal an employer relied on to confirm the story was itself supplied by the people telling it.
What the employer is left holding
The consequences fall unevenly, and most of them land on functions that had no part in the hiring decision.
There is the sanctions question, since paying a prohibited party is a problem regardless of whether the payer knew, and an employment relationship involves a long series of payments rather than a single transaction that might be caught and reversed.
There are the records. Payroll entries, tax filings, contracts and equity grants all exist in a name that belongs to someone else, and unwinding them is slow work that involves finance, legal and often an external adviser.
There is access. A remote engineer holds credentials to source code, customer data and internal systems, granted on the basis of an identity nobody confirmed, and the security review that follows has to assume everything that identity touched is in question.
There is also the part that rarely appears in the legal summaries. Colleagues worked alongside this person for months, and a manager wrote performance reviews for someone who did not exist. Telling a team what happened, and deciding what to say to customers whose data sat within reach, is work that falls to people who had no involvement in the hire.
And there is the cost of the response itself. In the case above, victim companies incurred substantial damages in legal fees and remediation, none of which was recoverable from the people who caused them.
Where a check would actually go
The instinctive objection is that verifying identity at application would be intrusive, slow and hostile to candidates, and that objection is correct.
Identity verification does not belong at the top of the funnel. It belongs at the point where an employer stops evaluating a person and starts committing to one, which is the moment between offer acceptance and onboarding. At that point the relationship has changed. The company is about to put someone on payroll, and asking them to confirm who they are is proportionate in a way it would never be for an applicant who has sent a CV.
The check itself is brief. The person photographs a government-issued document, the document is tested for authenticity rather than simply read, a live selfie is matched against the photograph on it, and the name is compared against the name on the contract. The outcome is recorded against the employment file with its date.
That last part matters more than it sounds. The value is not only the moment of confirmation. It is that a year later, when someone asks how the company established who it hired, there is an answer that does not depend on anyone's memory.
The harder version of the problem is the one most organisations meet first, which is contract and agency-supplied staff. A worker placed by a supplier is onboarded by that supplier, so the client company often has a name, an email address and a rate, and no direct relationship with whoever holds the document, which means the verification obligation has to be written into the supplier agreement and evidenced rather than assumed. Asking a staffing partner what they verify, and what record they keep of it, is a reasonable question that many procurement processes still do not ask.
The data you take on by checking
An honest version of this argument has to acknowledge what verification costs, and the cost is data.
Confirming identity means handling government documents and, if a face match is used, biometric information. Both carry retention limits, consent requirements and access restrictions, and an HR function that collects them without deciding where they will live has traded one exposure for another. Recruitment systems are already an attractive target, and this publication's own piece on security gaps that put recruitment data at risk sets out how much sensitive material an ATS accumulates without anyone intending it.
The practical answer is to keep the result rather than the evidence. A verification service can return a confirmation, a timestamp and a reference, while the document images stay out of the applicant tracking system entirely. Storing a passport scan in a recruitment folder creates a liability that lasts as long as the folder does.
What the case does not prove
Two limits are worth stating, since a guest article that oversells its own remedy deserves the scepticism it gets.
Verification confirms that a person matches the document they present. It does not establish what they intend to do afterwards, and it would not catch a genuine document holder who is knowingly working on someone else's behalf. Several people in these cases were real Americans acting as facilitators, and no identity check would have flagged them.
It also does not make the wider problem an HR problem alone. Device management, access control and the monitoring of unusual remote access patterns all did work in exposing these schemes, and they continue to matter.
What the case does establish is narrower and harder to argue with. The hiring process is now the point at which an organisation decides who to trust, and it has been operating without the one check that question requires. Adding it costs a new employee a few minutes in the week they join, and it gives the company something it currently does not have, which is a documented basis for believing that the person it pays each month is the person it agreed to hire.











