During a video interview for an engineering role, Vidoc's interviewer asked a candidate he suspected of using a face filter to do one small thing: wave a hand in front of his face. The candidate refused, and the interviewer ended the call. Pragmatic Engineer's writeup of the two interviews is a good story, but the test at the center of it is the point: a live, unscripted request an AI face filter can't survive.
Catching fake candidates in remote engineering hiring starts with a different question than the one most hiring teams ask during a coding round. It's not about whether someone used an AI assistant mid-interview. It's about whether the person on the call is who they say they are, whether their references check out, and whether the engineer who does the work after the offer is the same one who got vetted.
What is candidate fraud in remote engineering hiring?
Candidate fraud outside the interview room takes a few distinct shapes. A fake or AI-generated profile is a resume and LinkedIn history built to pass a recruiter's first scan, sometimes for a person who doesn't exist at all. A proxy candidate is someone more skilled than the applicant who sits the technical call in their place, then hands the job back once an offer goes out. A stolen-identity remote worker uses someone else's documents, sometimes a real person's passport, to pass a background check and get hired under a name that isn't theirs. A bait-and-switch hire is the one that shows up weeks into onboarding: the engineer doing the daily work isn't the one who interviewed.
None of that is the same problem as a candidate quietly running an AI assistant during a live technical round and passing the output off as their own thinking. That's a real risk, but it's scoped to a single stage, and it's already covered in how to run a live coding interview and catch AI cheating. This piece covers the fraud that happens before that call ever gets scheduled, and after the offer goes out.
Why remote engineering roles are the target
Remote engineering roles combine three things fraud needs: high pay, no requirement to ever appear in person, and access to systems worth a lot to whoever gets in. A senior hire clears a background check, gets shipped a laptop, and within weeks has commit access and often production credentials. None of that requires anyone at the hiring company to verify identity beyond a resume, a video call, and whatever references the candidate hands over.
The scale isn't hypothetical. The Department of Justice sentenced Christina Chapman to 102 months in prison for running a scheme that defrauded 309 U.S. companies and generated more than $17 million in illicit revenue. In a separate case, federal prosecutors indicted two North Korean nationals and three facilitators over a scheme that obtained work from at least 64 U.S. companies, laundering at least $866,255, and running on forged and stolen U.S. passports and a "laptop farm": company-issued laptops sitting in a house in the U.S., running remote-access software so someone overseas could work under the hired identity.
Both schemes passed standard hiring checks. That's the part hiring teams underestimate: a background check confirms a document is authentic, not that the person in front of you is the person named on it.
How to catch fake candidates in remote engineering hiring
1. Verify identity before the first live call
Before you schedule a first call, check whether the story the resume and LinkedIn profile tell holds together. A profile created in the last few weeks with a thin work history, a phone number that resolves to a VoIP service instead of a real carrier, and a headshot that reverse-image-searches to a stock photo site are all reasons to slow down, not automatic reasons to reject. Do this before anyone on your team spends interview time on the candidate, not after.
If the candidate sits in an EU member state, these checks aren't unlimited. Identity verification involves processing personal data, so under GDPR you'll need a lawful basis and checks proportionate to the role. Agree the scope with whoever owns data protection at your company before you start; EU engineering hiring compliance: contracts, IP and GDPR covers the wider compliance picture for cross-border engineering hires. Proportionate checks are still checks, just not "everything we could find".
2. Confirm references and employment independent of anything the candidate supplied
Call the company a candidate says they worked for using a number you find yourself, a main switchboard or a listing on the company's own site, not a number written on the resume. The FBI's IC3 issued guidance in July 2025 telling hiring teams to verify prior employment and education directly with the institutions rather than through the candidate, and to ask a candidate to wave a hand in front of their face on a video call, since that motion can break an AI-generated video filter. A reference number the candidate controls tells you nothing you didn't already know.
3. Run the hand-in-front-of-face test before any technical stage
Do this on the first live video call, before any coding or architecture discussion starts. Ask the candidate to wave a hand in front of their face and partially cover it for a second. A real face moves naturally under a hand. An AI-generated overlay tends to glitch, smear or freeze at the edges, which is exactly what tripped up the second candidate in the Vidoc story above. Pair it with one unscripted, location-specific question, something about the city or time zone the candidate claims to be in, that a script can't prepare for.
4. Delay laptop shipment and system access until checks clear
Don't ship a company laptop or grant repository and production access until background and identity checks are complete. The laptop farm at the center of the Miami case existed because a company shipped hardware to an address before anyone confirmed who'd actually be using it. A short delay between offer and full system access costs you a few days. A compromised laptop sitting in someone else's house costs a lot more.
5. If you're hiring through a vendor, confirm the engineer who shows up is the one who was vetted
Bait-and-switch doesn't require identity theft. It just needs a staffing vendor with an incentive to place someone, anyone, once a contract is signed. Ask how the vendor's vetting process works, who runs it, and whether the person you interviewed is contractually the person who does the work. HighCircl runs every one of its own hires through four stages before an offer goes out, background and experience verification, a communication and product-thinking conversation, a take-home project mirroring real work, and a live technical session focused on architectural reasoning, and about 1 in 10 applicants clear all four. What engineer-led vetting means in practice explains why having senior engineers run that process, instead of a recruiter or an algorithm, is what makes it hard to route around.
Red flags across the hiring pipeline
| Stage | Red flag |
|---|---|
| Sourcing | Phone number resolves to VoIP rather than a carrier; LinkedIn profile created in the last few weeks; headshot matches a stock photo |
| Interview | Refuses to remove a video filter or do the hand-in-front-of-face test; audio and lip movement don't quite match |
| Reference | Only a number or email the candidate supplied, with no independent listing to confirm it |
| Onboarding | Shipping address doesn't match the ID used for background checks; candidate asks to be paid in crypto or to a different name |
Any one of these alone is thin evidence. Two or three together, at the same stage, are worth a direct conversation before you move the candidate forward.
Fake candidates vs. AI-assisted interview cheating: what's the difference
Fake candidates and AI-assisted interview cheating are different problems that get lumped together because both involve AI. A fake candidate is a question of identity: is this the person who applied, and are they real? AI-assisted cheating is a question of skill: did the person on the call produce the reasoning behind the code they're showing you, or did a tool produce it while they read it back.
The identity problem needs the checks in this article, run before a candidate ever reaches a technical stage. The skill problem needs a different toolkit, covered in how to design a technical screening process, including how to run a take-home that survives an AI assistant and a live session that catches someone who can't defend their own code.
FAQ
What is a proxy candidate?
A proxy candidate is someone other than the applicant who sits the interview, usually a more technically skilled person, while the actual hire takes over once the job starts. It's different from a stolen-identity hire, where the same person does both the interview and the job, just under someone else's identity documents.
How common is candidate fraud in remote engineering hiring?
There's no reliable industry-wide rate for this specific category, so treat any number you see with suspicion. What's not in doubt is scale: the two DOJ and FBI cases above, involving 309 and 64 defrauded U.S. companies respectively, weren't isolated incidents run by a lone scammer. They were operations with facilitators, laundering infrastructure, and enough organization to sustain years of fraudulent placements.
Can a background check alone catch a fake candidate?
No. Both cases described above involved forged or stolen government identity documents that passed standard checks, because a background check verifies that a document is authentic, not that the person holding it is who the document says. Catching identity fraud takes the checks in this article: independent reference verification, a live unscripted test, and a delay on system access until everything clears, on top of whatever background check you already run.
What do North Korean IT-worker schemes have to do with hiring a developer?
They're the most organized version of the identity-fraud problem this article covers. In the cases described above, operatives used stolen or forged American identities to get hired as remote IT workers at U.S. companies, then ran the actual work from laptop farms, houses where company-issued hardware sat running remote-access software so someone overseas could work under the hired name. Any company hiring a remote engineer sight unseen is a plausible target for the same playbook, not just the companies named in the indictments.
How does HighCircl prevent fake or proxy candidates?
HighCircl runs a four-stage, engineer-led vetting process, background and experience verification, a communication assessment, a take-home project, and a live architectural session, that passes about 1 in 10 applicants. Every engineer is based in one of the seven European countries HighCircl hires from, and the first vetting stage is background and experience verification.
