How to Detect Candidate Fraud That Uses Real People as Frontmen
Some of the hardest candidate-fraud cases do not rely on a synthetic face, an obvious deepfake, or a completely fabricated identity. They use a real person with clean documents.
Fraud rings recruit people to act as frontmen—also called proxies or facilitators. A frontman may lend out an identity, sit for an interview, receive a laptop, attend meetings after hire, or do several of those things while someone else applies and performs the work.
That changes what a hiring team has to look for.
Why conventional checks can pass
A frontman can make many familiar controls report exactly what they are designed to report:
- The identity is real.
- The background check belongs to a real person.
- The face on an interview call matches the documents.
- The device appears to be an ordinary remote employee's laptop.
- A live verification step is completed by the person whose name is on the application.
None of those checks proves that the same person created the resume, submitted the application, completed every interview, and will perform the job.
Fraudsters exploit that gap. They can route work through a laptop in the frontman's home, coach or replace the interviewee, and use the clean identity to pass controls that focus on a single moment.
The application can still tell a different story
While building Endorsed's fraud-detection agents, we found that application data can expose inconsistencies that a point-in-time identity check misses.
Two signal categories are especially useful.
Identity-to-resume mismatches
A fraudulent applicant may use an AI-optimized resume that is repeatedly changed for different jobs. The resulting work history can look polished while diverging from the public professional record attached to the identity.
Compare the claimed roles, employers, technologies, seniority, and dates across the resume and credible public sources. A frontman's public history may describe one career while the submitted resume describes another.
This is not a reason to reject someone automatically. Public profiles can be stale and resumes are tailored legitimately. It is a reason to investigate the discrepancy instead of treating a passed ID check as the end of the review.
Document and file history
Resume files can retain metadata about how and when they were created: author fields, editing applications, version history, timestamps, and other document properties.
Those details may expose a file assembled by somebody other than the named candidate or a document passed repeatedly through a fraud operation. Again, one metadata field is not a verdict. Multiple inconsistencies across the identity, resume, application, and device form a much stronger pattern.
Review the full journey, not one checkpoint
The practical lesson is that no single control—ID verification, background checks, device checks, or a live interview—should be treated as definitive.
Look for continuity across the entire hiring journey:
- Does the application history match the identity's credible history?
- Do document properties align with the candidate's explanation?
- Does the same person appear to be applying, interviewing, accepting the offer, and performing the work?
- Do device, network, contact, and behavioral signals remain consistent over time?
- Can a reviewer see the evidence and ask the candidate for clarification before making a decision?
The goal is not to add suspicion to every legitimate applicant. It is to find the small set of cases where the story breaks across multiple independent signals—while keeping real candidates moving through the process.