A Contractor Passed Every Check. Endorsed Flagged What Others Missed
An enterprise customer recently hired a contractor through a major staffing firm valued at more than $10 billion. The contractor passed the staffing firm's vetting, a background check, and two I-9 verifications.
On the surface, he looked legitimate. Then Endorsed flagged him.
Nothing Looked Suspicious
The contractor had many of the signals teams normally associate with a real candidate:
- A custom email domain bearing his name
- IP and device data consistent with his stated location
- A LinkedIn identity verification and an account dating to 2016
- A thoughtful personal website
- Friendly, natural interviews with no apparent communication issues
- No evidence that different people interviewed at different stages
Traditional checks did not reveal a problem.
The Signal That Changed the Investigation
After Endorsed's algorithm flagged the contractor, a member of the customer's security team asked us to take a second look.
The deeper review surfaced an inconsistency: although his profiles looked established, we could not find a meaningful public trace of him before the previous two months. We also found another person with the same name and matching professional experience.
Neither finding proved fraud. Together, they were enough to justify verifying whether the person who had interviewed was the person using the customer's systems.
A First-Day Verification
The customer had endpoint and identity monitoring in place. We suggested confirming two things:
- Was the contractor using the company laptop that had been shipped to him?
- Had any unauthorized remote-access software been installed?
The customer invited us to an impromptu Zoom call. It was the contractor's first day, and he was not using the company laptop. When asked to switch to it, he said the device was beside him but its battery was dead.
The team told him to charge the laptop and begin using it. About 30 minutes later, their monitoring showed the machine powering on and installing Jump Desktop, a remote-access application. The contractor continued to say the laptop was out of battery even though the team could see that it was active.
At that point, the combined integrity concerns were too significant to discount, and the customer ended the engagement.
Why the Remote-Access Software Mattered
Remote desktop software is not inherently malicious. It is commonly used for legitimate support and administration.
In this context, however, an unauthorized installation could allow a person or device in another location to control the company laptop over the internet. That can make activity appear to originate from the laptop's expected IP address and physical location even when someone elsewhere is operating it.
The FBI has warned that fraudulent remote IT-worker schemes can involve facilitators receiving company laptops and enabling overseas access through the unauthorized installation of remote-access software.
The software alone did not establish what happened here. The decision came from the full pattern: a shallow digital history, duplicated professional details, avoidance of the company device, an unauthorized installation, and statements contradicted by the customer's own telemetry.
What Teams Should Learn
There are obviously fake profiles, and then there are sophisticated candidates who pass interviews, identity checks, and background screening.
This case required Endorsed and the customer's security team to investigate together before the risk became clear. That collaboration is the important part:
- Treat automated fraud signals as reasons to investigate, not automatic verdicts.
- Escalate integrity concerns to security before granting broad system access.
- Confirm that remote workers are using the devices shipped to them.
- Monitor for unauthorized remote-access tools and unexpected device behavior.
- Evaluate the complete pattern instead of relying on any single red flag.
If a candidate's signals do not add up, ask your security team to take a closer look. A short investigation before access expands can prevent a much larger incident.