Case File 001
The laptop was online. He said it was dead.
Endorsed
Case File 001David Head4 min readJUL 22, 2026
Greenhouse500-1,000 Employees

Fraudulent contractor from a $20B+/yr staffing firm who passed I-9 and background check


An enterprise customer recently hired a contractor through a major staffing firm valued at more than $10 billion. The contractor passed the staffing firm's vetting, a background check, and two I-9 verifications.

On the surface, he looked legitimate. Then Endorsed flagged him as High Risk.

Nothing Looked Suspicious

The contractor had many of the signals teams normally associate with a real candidate:

  • A custom email domain bearing his name
  • IP and device data consistent with his stated location
  • A LinkedIn identity verification and an account dating to 2016
  • A thoughtful personal website
  • Friendly, natural interviews with no apparent communication issues
  • No evidence that different people interviewed at different stages

Traditional checks did not reveal a problem.

The Signal That Changed the Investigation

After Endorsed's algorithm flagged the contractor, a member of the customer's security team started investigating the signals.

Although his profiles looked established, there was no meaningful public trace of him dating back more than two months. The team also found another person with the same rare name and overlapping professional experience.

Neither finding proved fraud. Together, they were enough to justify verifying whether the person who had interviewed was the person using the customer's systems.

A First-Day Verification

The customer had endpoint and identity monitoring in place. Endorsed suggested they confirm two things:

  1. Was the contractor using the company laptop that had been shipped to him?
  2. Had any unauthorized remote-access software been installed?

It was the contractor's first day, and he was not using the company laptop yet. When asked to switch to it, he said the device was beside him but its battery was dead.

The team told him to charge the laptop and begin using it. About 30 minutes later, their monitoring showed the machine powering on and installing Jump Desktop, a remote-access application. The contractor continued to say the laptop was out of battery even though the team could see that it was active.

At that point, the combined integrity concerns were too significant to discount, and the customer ended the engagement.

Why the Remote-Access Software Mattered

Remote desktop software is not inherently malicious. It is commonly used for legitimate support and administration.

In this context, however, an unauthorized installation could allow a person or device in another location to control the company laptop over the internet. That can make activity appear to originate from the laptop's expected IP address and physical location even when someone elsewhere is operating it.

The FBI has warned that fraudulent remote IT-worker schemes can involve local facilitators receiving company laptops and enabling overseas access. Fraudulent IT workers may also have others perform the work on their behalf.

The software alone did not establish what happened here. The decision came from the full pattern: a shallow digital history, duplicated professional details, avoidance of the company device, an unauthorized installation, and statements contradicted by the customer's own telemetry.

What Teams Should Learn

There are obviously fake profiles, and then there are sophisticated candidates who pass interviews, identity checks, and background screening.

This case required Endorsed's fraud detection AI model and the customer's security team to investigate before the risk became clear. That collaboration is the important part:

  • Treat automated fraud signals as reasons to investigate, not automatic verdicts.
  • Escalate integrity concerns to security before granting broad system access.
  • Confirm that remote workers are using the devices shipped to them.
  • Monitor for unauthorized remote-access tools and unexpected device behavior.
  • Evaluate the complete pattern instead of relying on any single red flag.

If a candidate's signals do not add up, ask your security team to take a closer look. A short investigation before access expands can prevent a much larger incident.

Share
Learn how Endorsed can protect your hiring pipeline