Stephen Daniel · September 16, 2026

The Fraud Flood in Remote Tech Hiring

Post a remote engineering role today, and more than a thousand applications can arrive inside two weeks. That used to be a filtering problem. It has become something else, because a growing share of those applications are fraudulent—and they are built well. I screen remote engineering candidates for a living, and this piece covers what the fraud actually looks like from inside those screens, why the traditional filters miss it, and what I have changed about my own process because of it.

What actually happens when you post a remote engineering role?

The volume arrives first. A remote engineering role I posted recently passed 600 applications in its first three days and a thousand within ten. A decade ago that pile was mostly real people, some qualified and some not, and screening meant sorting one from the other.

The pile is different now. Mixed into it, in numbers that keep growing, are applications that were never a person looking for this job. They exist to get through your first filter, and they are engineered for exactly that.

I am not the only one seeing it. Endorsed, a startup that screens applications for identity fraud, told Fortune that among the US remote IT roles it screens, applications carrying North Korean fraud patterns went from 11 percent of the total to 44 percent in a single year. They sell the detection, and those are flagged risk patterns rather than confirmed cases, so discount it how you like. The direction is not in question.

What do the fraudulent applications look like?

Two patterns keep showing up in my screens.

The first is possibly a real, even capable, person, but the resume was written to match the job description line by line. Every requirement answered, every keyword present. When I probe into any of the listed experience, there is nothing underneath. No real work with any of it.

The second is worse. Stolen identities— resumes and profiles lifted from real people on LinkedIn, clearly run by organized operations. The person who shows up to the interview, if anyone shows up at all, is not the person on the profile.

Why do resumes and interviews miss it?

The filters on which most processes rely were built for a different problem. Keyword matching assumed the resume was an honest attempt to describe real work. Location filters assumed the applicant lived where they said they did. Neither assumption holds against applications built to beat them.

Here is the part that took me a while to accept: the fraudulent resumes are often built to look better than the real ones. A qualified engineer writes an honest resume that matches maybe 70 to 80 percent of your posting, because real careers are not shaped like job descriptions. A fabricated resume matches all of it. Rank the pile by match quality and the fakes rise to the top.

What does the flood do to real candidates?

This is what concerns me most. Solid, qualified people are drowning in that pile. They did the real work, but the honest resume now loses to the overly qualified manufactured one in most screening tools.

Every fraudulent application that gets an interview slot took that slot from someone real. The cost of this problem lands on good candidates before it lands anywhere else.

When I wrote about this on LinkedIn, candidates showed up in the comments and confirmed their experience. One put it plainly: a North Korean spy can get an interview and he cannot; make it make sense. Another described what he had started doing instead, which is writing to someone at the company before applying and naming the thing he does not have. His reasoning stuck with me. A resume built to match the posting line by line never has a gap in it. Real ones do, and some candidates will tell you what theirs are before you have to go looking.

What is actually working?

I now score validity before job fit. Whether the person and the work are real gets established first; whether they match the role comes second. That ordering sounds small. It changes what the whole screen is doing.

A few things I have learned along the way:

A perfect match is a caution now, not a shortlist. One idea I picked up from another poster on LinkedIn: search for resumes that are a 70 to 80 percent match instead of 100 percent. It works because the fakes match line by line, and real people rarely do. I do not expect it to work forever. Real candidates curate their resumes too, and the bots will learn to be mostly perfect instead of perfect. But it moves the odds today.

Plant something a bot will take. A commenter on that post suggested asking for twenty years of experience in something that has only existed for five, then filtering out every resume that claims it. A real candidate reads that requirement and either laughs or explains what they actually have. An engineered resume answers it, because answering every requirement is the whole point. I liked this one immediately.

Ask directly, and say that you check. Another commenter described asking applicants outright whether AI assisted the application, stating plainly that they verify and that dishonesty disqualifies. He puts the reliability somewhere around seventy percent, which is his estimate rather than a measured figure. The reasoning underneath it is the interesting part: nearly all of these tools run on the same handful of underlying models, and those models have guardrails that make them reluctant to help deceive someone even when they are instructed to.

Use AI to fight AI fraud. The volume is the problem, and no human screen reads a thousand applications with the care each one deserves. The same class of tools generating fraudulent applications can be put to work probing them, at the depth and scale the pile requires, with a person deciding what the findings mean.

Do more outbound hunting. When I go find candidates instead of waiting for applications, fraudulent profiles are a much lower percentage of what I see. For now. I hold that loosely, because every tactic in this space has a shelf life.

Eventually I built the tool. Doing this by hand, across a downloads folder and an inbox and three other apps, stopped scaling. GilbertHire is where it ended up: an ATS built for the screening stage, with validity checks running before anything gets ranked on fit. Find it at gilberthire.com. It is early, and it is being shaped by the recruiters using it, so if you work this stage every day I would like your feedback on it.

What did people push back on?

The strongest disagreement in that thread was not about whether the fraud is real. It was that I had described half the problem.

More than one person made the same point independently: a lot of this volume is self-inflicted. Postings written for a candidate who does not exist, requirements assembled by committee, and a hiring manager staring at a thousand applications who leans on filtering tools as a crutch because no person can read that pile. One commenter put the fix bluntly: get hiring managers comfortable with good enough instead of holding out for perfect.

I think that is right, and it is uncomfortable, because it means some of the flood is a response to what we are asking for. A posting that demands a unicorn will attract resumes engineered to look like one.

Where does this go next?

I do not think this gets solved so much as continuously answered. Each filter works until it gets studied, and the operations running stolen-identity applications are studying them full time.

The response to that post was larger than anything else I have shared there, which tells me how many hiring teams are staring at the same pile. If you are hiring for remote roles, the question worth asking your process is simple: at what point do we actually establish that this person is real? If the honest answer is "the interview" or "never," the flood is already costing you your best candidates.

remote hiring · hiring fraud · candidate screening · recruiting

Run one live requisition with us · More from the blog