# The Pre-Offer Authenticity Standard for Remote Engineers

*You can grade any remote engineering candidate as clear, recheck, or reject against identity fraud so two reviewers reach the same verdict before an offer goes out.*

- Canonical URL: https://www.refolk.ai/guides/pre-offer-authenticity-standard-remote-engineers
- Pillar: Engineering and open source
- Format: Standard
- Published: 2026-08-25
- Last reviewed: 2026-08-25
- Reading time: 15 min
- Keywords: verify remote developer identity before hiring, detect fake engineering candidate, remote candidate identity verification checklist, cross-reference candidate github linkedin, fake candidate red flags hiring

## Key takeaways

- A smooth webcam feed is no longer proof of a real person: face-swap deepfakes defeat 'turn your camera on,' so liveness must be an unscripted physical action, not a video call.
- Passing interviews does not clear a candidate. The KnowBe4 fake hire passed four video interviews, a background check, and reference verification before onboarding.
- Volume is the attack. Nisos found 22 operatives submitted 166,893 applications for 76 offers, an under-1% hit rate, which means manual intake review is a bottleneck, not a control.
- Scarce-skill claims are more checkable: Refolk's index lists only 750 US Software Engineers with Solidity and 603 with Rust, so a niche identity has few real profiles to reconcile against.
- Location logistics beat documents. Stolen IDs pass; a US shipping address masking a foreign login and multi-country account access is the durable tell that survives AI enhancement.
- Least privilege caps the loss. KnowBe4 contained its fake hire within 25 minutes because onboarding access was scoped, not because screening caught the persona.

This is a pre-offer definition of done for one decision: is a remote engineering candidate a real, single, work-authorized person who matches their claimed public footprint. It is written for engineering managers, technical founders, developer-relations leads, and technical sourcers who make the offer call. The deliverable is a rubric two reviewers can apply to reach the same verdict, plus the procedure and checklist to get there before an offer goes out.

Published advice on this is a scattered pile of red flags and post-hire security telemetry. That is useful reading but it is not a bar you can grade against. This document turns those signals into a pass or fail standard, scaled to the access the role grants, that you can adopt as written team policy.

## Why a pre-offer standard, and why now

The threat is organized, high-volume identity fraud aimed at remote engineering roles, and the defensible response is a scoring bar applied before the offer, not a checklist run after. Gartner predicts that by 2028, one in four candidate profiles worldwide will be fake, and a survey of 3,000 candidates found 6% admitted to interview fraud, either posing as someone else or having someone else pose as them.

Three fraud shapes drive this standard. The first is stolen or AI-augmented identity: a real document or credential attached to a person who is not the applicant. The second is the deepfake proxy: a live face-swap on video so the person you interview is not the person who would do the work. The third is the laptop farm: a facilitator inside your country receives the company laptop and forwards access to a worker abroad, masking true location.

The scale is not theoretical. Nisos found that 22 operatives submitted 166,893 applications and obtained more than 21,000 interviews for 76 offers, an overall success rate below 1%. CrowdStrike reported that companies hiring North Korean developers grew 220% in twelve months and that workers infiltrated more than 320 companies. Reported job-related fraud losses jumped from $90 million in 2020 to over $501 million in 2024, a 457% increase.

**166,893 - Applications submitted by 22 operatives for 76 offers**

Under 1% success, per Nisos, which means the attack is volume, not skill.

The lesson inside that number is where teams lose. When a single operation submits a thousand applications to one company, manual review at intake stops being a control and becomes a bottleneck. A standard fixes this by defining what evidence must reconcile before an offer, so reviewers spend effort on the right checks rather than reacting to whichever red flag they happened to notice.

## The five signal categories and what each proves

Named guidance converges on five signal categories, and the reliable verdict comes from reconciling several together, not from any one. No single indicator establishes fraud; several indicators considered together, supported by additional evidence, may warrant further review.

| Category | What a clear result looks like | What it looks like when it lies |
|---|---|---|
| Identity-document authenticity | Document passes proofing and matches the live person | A valid stolen or AI-augmented ID on the wrong face |
| Live-interview liveness | Unscripted physical actions perform cleanly | A smooth feed that is a real-time face swap |
| Public-footprint consistency | Cross-platform history predates the claim | A green wall of commits built in one week |
| Location and network | Shipping, login, and deposit reconcile | US address masking multi-country logins |
| Device and payment logistics | Laptop ships to the worker's real location | A facilitator address forwarding access abroad |

The point of the table is that each signal has a lie state, and a criterion you cannot fail is not a criterion. Identity-document authenticity proves the document is genuine, not that the holder is the applicant, which is why the KnowBe4 fake hire used a stock image augmented by artificial intelligence and still cleared a background check. Footprint consistency proves the persona has a real past only if the timestamps predate the claim.

> **Rule:** No single indicator decides
>
> Grade against reconciliation across categories, never on one red flag. A verdict of reject requires evidence in more than one category unless a single check is disqualifying on its face, such as a reverse-image hit on a stock or AI-generated face.

The ordered subset that catches most infiltrations, if you can only do a few things, is: live liveness with unscripted action, footprint timestamp reconciliation, and location logistics. The Famous Chollima investigation showed there is rarely one obvious sign; clues appear across identity documents, interviews, location data, infrastructure, and activity after onboarding.

## Liveness: what to demand and what counts as a fail

Liveness is a live, unscheduled video call in which the candidate performs spontaneous physical actions, and a fail is any glitch, refusal, or stall. Because face-swap deepfakes now defeat the old advice, a clean webcam feed proves nothing on its own.

The documented moves are simple and hard to fake in real time. Ask the candidate to wave hello, since rapid, natural movements can prompt a video glitch. Ask them to move the camera closer, which can disrupt the illusion. Ask them to hold up a specific object or move to a different part of the room. Add one un-preppable local-knowledge question tied to their claimed location.

#### The liveness interview sequence

1. **Unscheduled call** - Remove prep time by not pre-booking the exact slot
2. **Wave hello** - Rapid motion can trigger a face-swap glitch
3. **Move the camera** - A closer or angled view disrupts the overlay
4. **Hold up an object** - Forces the model to render an unplanned scene
5. **Local-knowledge Q** - Confirms the person matches the claimed location

*Each prompt targets a different weakness in a real-time face swap or a coached proxy.*

Two failure patterns matter here. First, the worker may report video or microphone issues that prohibit participation from the start; treat persistent, convenient technical failure on liveness prompts as a fail, not a courtesy to reschedule. Second, these workers operate in teams, so the individual a hiring official deals with may change depending on the time of day. That is why liveness must re-verify across sessions rather than clear a candidate on one good call.

> **Watch out:** The persona rotates by shift
>
> The interview you pass and the worker who would do the job may be different people. Re-run a liveness check in a later session, ideally at a different time of day, before you treat the identity as settled.

## Footprint reconciliation: the fields that must line up

A legitimate developer's public footprint has consistent, cross-platform history that predates the GitHub profile; a fake one has recently created or missing linked accounts despite claiming an active professional presence. Four fields must reconcile, and the timestamps are the hardest thing to fake.

- **Profile photo provenance.** A reverse-image search should surface an independent trail. A hit on a stock or AI-generated face is disqualifying on its own.
- **Account age versus claimed career length.** Real developers have years of consistent commits, not a green wall created in one week. Accounts must predate the claimed start dates.
- **Cross-platform handle and identity match.** GitHub, LinkedIn, personal site, and any bylines should point to one coherent person. Inconsistencies across resume, portfolio, and LinkedIn are a flag.
- **Commit-email identity.** Inspect who the commits are attributed to, not just that commits exist.

Scarce-skill claims are easier to reconcile than generic ones, because there are fewer real profiles to check against. In Refolk's index, only 750 US Software Engineers list Solidity and 603 list Rust, against a general pool of 346,161. A niche identity has almost nowhere to hide.

| Skill | US "Software Engineer" profiles | Share of US SWE pool |
|---|---|---|
| Solidity | 750 | 0.22% |
| Rust | 603 | 0.17% |
| All SWE (baseline) | 346,161 | 100% |

Footprint depth also varies by market, which changes how much reconciliation evidence you should expect to find. In Refolk's index there are 346,161 US Software Engineer profiles against 21,646 in Germany, a 16-to-1 ratio, so a thin footprint is more meaningful in a large market than a small one.

| Country | "Software Engineer" profiles | Ratio vs. Germany |
|---|---|---|
| United States | 346,161 | 16.0x |
| Germany | 21,646 | 1.0x |

Reconciling a claimed footprint by hand across GitHub, LinkedIn, and the open web is where the intake bottleneck bites. Asking [Refolk](/) in plain English for the profiles a real person would have, then checking whether the candidate's links match, collapses that search from an afternoon to a query.

I ran this search: `Solidity developers in the US whose GitHub, LinkedIn, and personal site all use the same handle` - [see the full result list](https://www.refolk.ai/s/6h230befp7).

*Returns the small set of real cross-platform Solidity identities you can reconcile a scarce-skill candidate against.*

## Scaling depth to the access the role grants

Match verification depth to what the role can touch, and cap the loss with least privilege regardless of how the screen goes. KnowBe4's damage was limited because new employees' accounts are granted only limited permissions to proceed through onboarding and training, and the fake hire's access was shut down within 25 minutes of the first alert.

#### Verification depth by role access

Horizontal axis runs from Low data and system access to High data and system access. Vertical axis runs from Low scrutiny to High scrutiny.

| Quadrant | What it means |
| --- | --- |
| Under-checking low-access roles | Run the base standard; do not over-invest |
| Right-sized deep vetting | Full standard plus independent employment proofing |
| Wasted effort | Reclaim time; base checks suffice for the access granted |
| The dangerous gap | Full standard is mandatory before any offer |

*Depth should rise with the blast radius of the access the role grants on day one.*

The most important control is not screening at all; it is scope. Least privilege caps the loss when screening misses, so grant onboarding-only permissions until identity is settled across sessions, and stage sensitive access behind post-start re-verification. Require candidates to complete any technical skills tests on the corporate IT environment so the work product is tied to your instrumentation, not their machine.

Location, device, and payment logistics are the checks that survive AI enhancement. Compare shipping address, login IP, and direct-deposit location; three locations that do not reconcile is a strong signal. North Korean IT workers often have multiple logins into one account in a short period from various IP addresses associated with different countries, and workers use overseas facilitators, including in the US, to receive company laptops and obscure their true locations. The FBI has seen up to 90 laptops at one residence and issued at least 200 victim notifications.

> Stolen IDs pass document checks. Laptop farms and multi-country logins do not survive reconciliation.

## The procedure, end to end

Run these seven steps in order, adjusting only the sequencing of identity proofing by role sensitivity. Sources disagree on order: some place identity proofing first, while the FBI and Gartner allow risk-based sequencing by how sensitive the role is.

#### From intake to recorded verdict

1. **Run the intake screen** - A recruiter logs claimed name, location, employers, and every public profile URL into one record and issues a consent or legitimate-interest notice. Done: one record with all footprint links.
2. **Reconcile the public footprint** - A sourcer reverse-image searches the photo, checks account ages, commit-email identity, and cross-platform handle consistency. Done: photo has an independent trail and account histories predate claimed start dates.
3. **Hold a live liveness interview** - The hiring manager runs an unscheduled video call requiring wave, camera move, held-up object, room move, and one un-preppable local-knowledge question. Done: no glitches or refusals and answers pass.
4. **Run a skills test in your environment** - An engineer has the candidate complete the technical test inside the corporate IT environment. Done: work product matches the interview persona.
5. **Verify employment and credentials independently** - HR checks histories against independent databases, not candidate-supplied references. Done: at least two independent confirmations.
6. **Check location, device, and payment logistics** - HR and security compare shipping address, login IP, and direct-deposit location and flag laptop-farm patterns. Done: three locations reconcile.
7. **Grade and disposition with two reviewers** - Two reviewers apply the clear, recheck, or reject rubric and must agree. Done: a recorded verdict with evidence attached.

Timings are roughly 15 minutes at intake, 20 for footprint, 30 for the liveness call, 60 for the skills test, one to three days for employment verification, 30 for logistics, and 15 for grading. Note the sequencing insight from staffing sources: most firms run identity checks late, typically during background screening, after the hiring decision has already been shaped. Moving footprint and liveness before the skills investment is the single highest-leverage change.

Here is the rubric the two reviewers apply so the same case grades the same way.

**Clear / recheck / reject rubric**

```
CLEAR (offer may proceed):
- Photo has an independent, dated trail; no reverse-image stock/AI hit
- Account histories predate all claimed start dates
- Liveness passed in two separate sessions, no glitches or refusals
- At least two independent employment confirmations
- Shipping, login IP, and direct-deposit locations reconcile

RECHECK (hold; gather one more independent signal):
- Exactly one category is thin or ambiguous, none disqualifying
- Liveness passed once but not re-verified across sessions
- Employment confirmed by only one independent source
Action: re-run the weak check before any offer; do not average it away

REJECT (do not offer):
- Reverse-image hit on a stock or AI-generated face
- Refusal, stall, or persistent "tech issues" on liveness prompts
- Location logistics do not reconcile (multi-country logins)
- Two or more categories fail
```

*Adapt thresholds to role access, but keep the categories and the two-reviewer rule fixed.*

## How this goes wrong: failure modes and false positives

Most bad verdicts come from trusting a signal that has a known lie state. Each item below pairs the false positive with the check that catches it.

- **Treating "camera on" as liveness proof.** A smooth webcam feed can be a real-time face swap. Standard advice to turn your camera on is no longer a reliable identity check. Fix: demand an unscripted physical action.
- **Treating passed interviews as cleared.** The KnowBe4 fake hire passed four video interviews, a background check, and reference verification. Fix: verify against independent databases, not candidate-supplied references, and re-verify liveness across sessions.
- **Reading a green contribution graph as a real developer.** A wall of commits can be fabricated in one week. Fix: require account age to predate the claimed career and inspect commit-email identity.
- **Trusting a professional-looking photo.** The KnowBe4 case used an AI-augmented stock image. Fix: reverse-image search for an independent trail.
- **Accepting a reference or background check as the last word.** Background checks confirm only what is presented to them. Fix: reconcile employer names and dates against the public footprint independently.
- **Assuming location from the resume.** A US shipping address can be a laptop farm masking a foreign login. Fix: reconcile shipping, login IP, and direct-deposit, and watch for multi-country logins.
- **Using signals as a nationality proxy.** This is discriminatory and legally exposed. Fix: apply identical, documented, risk-based criteria to every candidate.

> **Watch out:** The most expensive mistake is confusing volume for safety
>
> Because operations swarm-apply, a candidate reaching you does not mean they were screened by the process the volume defeated. Grade every finalist against the full standard, not the ones who "felt off."

## Staying lawful while you verify

Collection is bounded by data-protection law and jurisdiction, and controls must be applied without bias. If any remote worker lives in the EU, GDPR applies, covering data protection, secure storage, and deletion rights, and ban-the-box laws delay criminal-history questions. In some countries, credit or social-media checks may be off-limits, and US right-to-work runs through E-Verify and I-9 workflows.

The non-negotiable is even-handedness. Warning signs must not be used as proxies for nationality, ethnicity, accent, disability, or country of origin, and controls should be applied through consistent, documented, and risk-based procedures. That is also what makes the standard defensible: identical criteria, recorded verdicts, two reviewers.

> **Rule:** Same criteria, every candidate, recorded
>
> Apply the exact rubric to all finalists and store the evidence and verdict. A standard applied unevenly is both worse fraud protection and a legal liability.

## Verify before you call it done

Run this checklist before recording a clear verdict. If any item is unchecked, the correct disposition is recheck, not clear.

#### Pre-offer authenticity checklist

- [ ] A single intake record holds the claimed name, location, employers, and all profile URLs
- [ ] The candidate received a consent or legitimate-interest notice appropriate to their jurisdiction
- [ ] The profile photo has an independent, dated trail and no reverse-image stock or AI hit
- [ ] Linked-account histories and commit dates predate every claimed start date
- [ ] Cross-platform handles and identity are consistent across GitHub, LinkedIn, and personal site
- [ ] A live, unscheduled liveness interview passed with unscripted physical actions, in two sessions
- [ ] The skills test was completed inside the corporate IT environment and matches the persona
- [ ] At least two independent databases confirmed the employment history, not candidate references
- [ ] Shipping address, login IP, and direct-deposit location reconcile to the same place
- [ ] Onboarding access is scoped to least privilege pending post-start re-verification
- [ ] Two reviewers agree on the clear, recheck, or reject verdict, recorded with evidence

## Keeping the standard current

This is a moving target, so re-check the mechanisms rather than the specific tools. The liveness prompts work because they exploit real-time rendering limits; when a vendor claims those limits are gone, add a new unscripted action and test whether it still glitches before trusting the old ones. Facilitators host laptops using remote-access tools, so treat the category of remote-access-from-an-unexpected-origin as the durable signal, not any one tool name.

Two anchors will not move. Least-privilege scoping caps the loss no matter how screening evolves, so keep onboarding access minimal by default. And the footprint's timestamps stay the hardest thing to fake: accounts and photos can be created on demand, but a years-long, cross-platform history that predates the claim cannot. Build the standard's spine on those, review the rest each hiring cycle, and keep the two-reviewer rule so drift in any one person's judgment does not become policy.

## Frequently asked questions

### How do I verify a remote developer's identity before hiring without discriminating?

Apply the same documented criteria to every candidate and grade footprint, liveness, and employment evidence, not the person. Warning signs must never be used as proxies for nationality, ethnicity, accent, disability, or country of origin. Controls should be consistent, documented, and risk-based, scaled to the access the role grants. If a remote worker may live in the EU, GDPR governs collection, storage, and deletion, and some jurisdictions bar credit or social-media checks entirely.

### Is turning the camera on enough to confirm a candidate is real?

No. Real-time face-swap deepfakes now produce smooth webcam feeds, so a clean video call proves nothing on its own. Standard 'turn your camera on' advice is no longer a reliable identity check. Instead, require unscripted physical actions during a live, unscheduled call: a rapid wave, moving the camera closer, or holding up a specific object. Glitches, refusals, or reported audio-video problems on these prompts are the fail condition.

### Why isn't passing multiple interviews enough to clear a candidate?

Because interviews test the persona, not the person. The KnowBe4 fake hire passed four video interviews, a background check, and reference verification, and operatives work in teams so the individual you interview may change by time of day. Background checks confirm only what is presented to them. You must verify employment against independent databases rather than candidate-supplied references and re-verify liveness rather than trusting one pass.

### What single check catches the most fake IT workers?

Location and device logistics. Stolen or AI-augmented IDs pass document checks, but laptop farms and multi-country logins do not survive reconciliation. Compare the candidate's shipping address, login IP, and direct-deposit location; if they point to different countries, or one account shows logins from several countries in a short period, treat it as a strong signal. The FBI has seen up to 90 laptops at one residence forwarding access on behalf of overseas workers.

### How common are fake candidate profiles?

Gartner predicts that by 2028, one in four candidate profiles worldwide will be fake, and a survey of 3,000 candidates found 6% admitted to interview fraud, either posing as someone else or having someone else pose as them. SentinelOne alone tracked roughly 360 fake personas across more than 1,000 applications. This is a base-rate problem, not an edge case, which is why a gradeable standard beats a loose red-flag list.

---

*From the Refolk guide library. I revise these guides rather than replacing them, so the current version is always at https://www.refolk.ai/guides/pre-offer-authenticity-standard-remote-engineers*
