The hiring pipeline became a security checkpoint

The Federal Bureau of Investigation confirmed something that should change how talent teams think about remote hiring. A foreign operative was hired into a real job at a United States agency by going through the normal application process. A resume, an interview, references, an offer. Nothing looked wrong until it was too late.

This is not a movie plot and it is not a one-time story. It is a documented and growing pattern. Skilled remote applicants who are not who they claim to be, using a real resume and a borrowed or stolen identity, get hired, collect a paycheck, and gain insider access. For years the hiring funnel was measured on speed and quality of hire. It is now also, quietly, a security boundary, and most companies never staffed it as one.

Why the usual process misses it

The uncomfortable part for talent teams is that a good hiring process is built to advance exactly the kind of candidate this abuse produces. A polished applicant who interviews well, answers cleanly, and has references that check out is what every funnel is designed to move forward. Speed and a strong first impression, the two things hiring optimizes for, are the two things this relies on. The process is not broken. It was simply never asked to confirm that the person is real, only that the person is good.

The fix is verification, not suspicion

The wrong response is to start treating every remote candidate as a threat. That poisons the experience for the honest majority and slows the funnel for no reason. The right response is narrow: treat identity verification as a real step in the process, not a formality tucked into paperwork.

Confirm that the person on the video interview is the person on the offer letter and the person who badges in on day one. Check work-authorization documents against the human in front of you, not just against a scan. And watch for the small tells that show up in remote hiring fraud: a camera that never turns on, a voice that lags the lips on video, an address or payment detail that does not line up with the rest of the story, or a candidate who resists a live, on-camera identity check for reasons that do not hold up.

Where the check fits without slowing the funnel

You do not need to verify identity on every applicant at the top of the funnel. That would be wasteful and would hurt the candidate experience. The right place is late and precise: at the offer and onboarding stage, on the small number of finalists, applied the same way every time. A consistent, documented identity step for finalists adds a day, not a month, and it is the point in the process where the stakes justify it.

Consistency is what makes this fair and defensible. A verification step that is applied to some candidates and skipped for others is both a security hole and a bias risk. The same check, run for every finalist, in the same order, recorded the same way, protects the company and treats candidates equally.

What to do this quarter

Pick one identity-verification step and make it standard for every finalist. A live, on-camera confirmation of a government identification against the person, done at the offer stage, is enough to close most of the gap. Write it into the hiring workflow so it happens the same way every time, and record that it was done. Then brief your recruiters on the tells above, so a hiring manager who notices something off has a place to raise it rather than a reason to stay quiet.

Hiring has always asked one question: can this person do the work. It now asks a second: is this person who they say they are. Both belong in the process, and the second one no longer belongs only to security teams. It belongs to the people who run the funnel.

Thabiti Adams is a CISSP, CCSP, and CCP certified cybersecurity professional and founder of Adams Cloud and Cybersecurity, which operates TrueScan HR.