Details
Fake applicants, fraudulent recruiters, and AI-enabled deception are creating real-time security, compliance, and reputational risks for employers. We Get Privacy cohosts Damon Silver and Joe Lazzarotti examine the issues from both sides of the hiring process, providing practical steps employers can take to verify candidates, strengthen safeguards and third-party relationships, and respond effectively when suspicious conduct arises.
Transcript
Damon Silver
Principal, New York City
Welcome to the We Get Privacy Podcast. I'm Damon Silver, and I'm joined by my co-host, Joe Lazzarotti. Joe and I co-lead the Privacy, Data and Cybersecurity group at Jackson Lewis. In that role, we receive a variety of questions from our clients every day, all of which boil down to the core question: How do we handle our data safely?
In other words, how do we leverage all the great things that data can do for our organizations without running headfirst into a wall of legal risk? How can we manage that risk without unnecessarily hindering our business operations?
Joe Lazzarotti
Principal, Tampa
On each episode of the podcast, Damon and I are going to talk through a common question that we're getting from clients. We're going to talk it through in the same way that we would with our clients, meaning we're going to focus on the practical. What are the legal risks? What options are available to manage those risks? What should we be mindful of from an execution perspective?
Damon, our question for today relates to recruitment. We know a lot of our clients and a lot of organizations have to recruit great talent. There's a whole range of technologies that help our clients do that. There's also a whole range of technologies that are emerging, and have emerged over the last several years, that help applicants submit applications for employment. Then there's a whole range of bad guys out there who are trying to screw that process up.
Putting all that stuff together, some bad actors are trying to be applicants, and other bad actors are trying to get into the company and cause damage. It's a real problem. Can you start us out by talking about that problem and laying out some of the issues? We can go from there in terms of how our clients can think about this and take some next steps.
Silver
We are seeing this problem emerge in both directions. In other words, we are seeing instances where our clients are legitimately intending to, and following through on, hiring people. It turns out that the people they thought they hired are not actually coming to work for them.
In some cases, those people are subcontracting the work out to other parties that our client has no visibility into and no relationship with. Sometimes those people might work for a hostile government or a criminal organization, and they are taking these jobs, particularly in information technology (IT) roles, for purposes of being able to exfiltrate data from our clients' systems, steal intellectual property (IP), or deploy malware within the systems as a Trojan horse approach.
There are also instances where someone is taking the job and drawing a paycheck for some period of time before someone realizes that no work is being done. It can take a surprisingly long time for anyone to pick up on that. The money is being funneled to a government entity or a criminal organization.
On the other side, Joe, we are seeing bad actors posing as representatives of our clients' businesses or as recruitment firms that our clients' businesses use. They are going out and representing to the market that positions are available with our clients' companies. They're either asking people to provide money for training or some other upfront certification needed for the job, or to provide information the way they would as part of onboarding, such as their Social Security number or driver's license number.
Both of these have created a two-pronged challenge for our clients as they try to manage their brand reputation, manage their relationships in the market, and address their true staffing needs.
Do you want to start with one or the other, Joe? Which one is more interesting to you?
Lazzarotti
They're all creating problems for our clients and businesses. The one that's of interest to me is the remote IT workers who are trying to get jobs. There's been some activity by law enforcement at the federal level, particularly the Federal Bureau of Investigation, in trying to help thwart those crimes.
What is happening, in essence, is that individuals largely from North Korea and other countries that may be sanctioned by the U.S. are using various technologies, including AI and deepfakes, as well as leveraging server farms here in the U.S. to mask where they're located. They're trying to get jobs and doing a fairly good job at it.
From what we've heard and in some of the cases that we've worked on, they also do a good job for the company when they get the job. The company may learn what happened because it is notified by law enforcement, starts to realize, "Hey, that's not the person that we hired," or sees some other indicator, such as the person changing their address to receive mail or not showing up at meetings.
The company realizes this person may be from North Korea. What it may not realize is that there are some real issues with that. It could be, as you said, exfiltrating data. It could also be that they're getting paid when they shouldn't be under federal law administered by the Office of Foreign Assets Control (OFAC). There are some pretty hefty strict liability penalties that could apply.
Now they're trying to deal with all this and figure out: How do we investigate this? Has data been exfiltrated? Is there a data breach? Can we make payroll for this person? Do we have to report this? There are all these questions because someone applied for a job and is doing a good job.
That's one of the challenges. You mentioned a couple of others, and you've dealt with them as well. We can dig into the people who are trying to help our clients recruit in some way, shape, or form, but it doesn't seem to work out.
Silver
No, not so much. We've had a number of clients learn through complaints they received from people who were contacted, apparently on behalf of their organizations, about jobs. At some point, those people came to realize that this was not a legitimate job offer.
Usually, there wasn't anything inherently suspicious at the front end. Maybe they weren't interested in the job, communicated that, and kept being bugged by the recruiter or by a member of what appeared to be the organization's talent acquisition team. Maybe they started to go down the path toward getting the role, and at some point it became clear that it wasn't what it seemed to be.
For these clients, this put them in a defensive posture right off the bat because they had no idea it was going on. They had to learn what had happened from people who were upset that they had been caught up in this scam.
As they dug into it a little more, they saw that email addresses had been created that appeared to be associated with their organization. The addresses would use a similar email domain formulation, but there might be a change in a couple of letters here and there.
Or they would create new Gmail addresses using our client's name as part of the address, such as recruiting.organizationname@gmail.com. A lot of the materials that were sent out are shockingly good frauds. The logo looks right, the language looks right, and the material references information pulled from our client's website.
In some instances, even relatively high-level people within the client's industry were being contacted about confidential executive roles and started going back and forth. Those people understood that our client was not perpetrating the fraud, but it nevertheless creates problems from a brand perspective.
In situations where someone gives over their Social Security number, driver's license number, or something else, you have people who feel they are at much greater risk of identity theft.
Joe, in both of these situations, the bad actors tend to be pretty far ahead of the curve because there's a big financial incentive for them to be there. With the help of AI, they are able to generate a lot of this content much more easily and figure out new methods of exploiting it.
What are some of the things our clients can be doing? We can start with dealing with fraudulent applicants to try to detect this stuff earlier and proactively make it harder for it to be effective. What are some of the things they can be doing from the standpoint of having a program, almost like an incident response plan, to deal with some of this stuff?
Lazzarotti
From what I've seen, what can be helpful, although it's not perfect, is evaluating your recruiting program. Are your people doing the recruiting? Is it a third party? If it's a third party, you probably want to talk to that third party and ask what they’re doing. Inquire about whether the recruiting staff at a third party are trained to look for indicators that law enforcement has published.
The FBI has put out a lot on this. We did a webinar on it with an FBI agent who went through some of this. Law enforcement has been very helpful and is open to sharing information about how companies can better identify this activity. Some of those indicators are, as I mentioned, someone changing their address right away or not wanting to be on camera.
Look at the resume and the materials. You'd be surprised when you get this. Sometimes the timing doesn't match up. If you read the timeline made by the resume, the person could be 10 years old and applying for the job. They're not 10 years old, but it's a mistake in the resume.
Or you look at the resume and say, "This person went to the University of Ohio," and you happen to know something distinct about the University of Ohio that anybody who went there would know. You should ask the person about it because they probably don't know the answer if they didn't go there.
It's those kinds of steps that try to assess what's going on with that individual. It tends to be remote IT workers. Look for those signals and inform your recruiting group, whether external or internal, so they can spot those things.
Then try to figure out, "Is this person a real person or not?" In some cases, clients have reached out to law enforcement for help because law enforcement is tracking a lot of this, may have a sense, and may be able to help you determine whether that person is valid. A lot of other clients I've talked to are starting to use greater levels of identity verification procedures.
That means trying to get identification together with a picture and taking some other steps. Some tools and services are doing that. That could raise other issues. It could involve the collection of biometric information, but that might be okay because you can comply with those requirements and still avoid the pitfalls of hiring someone from a country sanctioned by the U.S. Companies are trying to evaluate that.
Those are some of the things clients can do for that particular type of fraud. In the other case you were talking about, where people try to dupe those who are trying to find a job, they also ask them to pay for equipment in order to start their job. That's also part of the complaint. Can you talk about some of that and how companies can try to stop those activities?
Silver
One of the most important things to do is create a verifiable source of information for your job applicant pool. On your careers page, include a warning that this type of activity is happening, similar to what banks do when they say, "We will never ask you for your account information or password over the phone."
Set rules of the road around what will and won't happen if you're legitimately communicating with the company you think you are. Identify what recruiting firms you work with so people can recognize when they're being contacted by someone who isn't you, identify what job boards you post on, and provide warnings and similar information on those job boards.
If there's a certain set of job boards or third-party platforms where you advertise positions, such as LinkedIn or Facebook, make it clear in those locations as well what is going on in the market generally. You don't have to say it's happening specifically to your organization, but make people aware of this type of issue and direct them to credible sources of information about you.
There are also services that can help you proactively scan job sites and social media platforms and see whether there's any apparent misuse of your company's name. That can be helpful so you're not waiting until you get complaints from people who have been contacted before realizing there's a problem.
If you realize it sooner, you can reach out to the job board platforms, social media platforms, and email service providers. You can let them know that fake posts are out there or that an email address spoofing yours is being used. It's not always the quickest process, but you can get the ball rolling on trying to have the fake job posts taken down or the invalid email address disabled.
The last piece I would mention, similar to having an incident response plan for a data incident, is having a playbook for how you're going to deal with this. Who will it be escalated to? What will the communications be to the impacted individuals? What will the communications be to the email service provider or job platforms?
Ideally, establish points of contact at those places so you're not sending your fraud report into the general abyss, where it might take a very long time to be acted on. All of that can help smooth things out and allow things to move more quickly for you.
One other thought, Joe, based on something you were talking about with the other side of this coin: when you have potentially bad actors who have taken positions with you, it increases the urgency to have some of the important safeguards in place that we've talked about in other contexts.
Think about permissions, for example. What does this particular remote IT role need access to in order to do the job? Assume that, in the same way a bad actor can get access to someone's account through a phishing attack or by exploiting a vulnerability, there's a higher chance now that some bad actor is going to get into your systems because you gave them an account. If you limit what that account can access, you're going to mitigate some of that risk.
The same is true of having active monitoring of your system so you notice abnormalities, such as logins from places that don't make sense or at times of day when you wouldn't expect your employee to work.
If you think you hired someone who's remote in Ohio, but they're constantly doing work in the middle of the night, Central Time, that could be an indication that this person isn't actually in Ohio. The same would be true of bulk downloads of data. At the very least, that should be flagged so someone can look into whether there's a legitimate reason why this remote IT employee is initiating those bulk transfers.
Those are all things that are probably being done, or at least being considered, for other reasons. This increases their value because this is a new frontier of threat actor activity.
Lazzarotti
The bad guys are thinking about those things as well. You almost have to take those steps and then be prepared to be a little more thoughtful.
If you start to suspect it, you probably shouldn't raise it right away with the person. You probably want to do a little investigating on your own, particularly if you think somebody already has access, as you were talking about, Damon. Get a sense of whether this person is accessing information and what they're doing before you take any steps.
In a lot of cases, some of these individuals from other countries are doing their job, and in some cases they're doing it well. That's their mission because, at least in some of these cases, the North Korean government is taking care of their families. That's some of what I see in the reports. They're concerned about their family, so they want to do a good job and keep the operation going.
They may appear to be located in a particular state, but that may be because they're using a server farm. They may be up at night, as you were saying, Damon, and that may be an indicator.
As you're talking to them, if it happens to be stormy in Ohio, which it is from time to time, say, "How's the weather where you are?" See what they say and ask those kinds of real-life questions that they may not be able to answer quickly on the fly.
When you see those kinds of hesitations, people unwilling to get on camera, missing meetings, or changing addresses, follow up on the measures you outlined, Damon. Be prepared to ask the follow-up question because sometimes they're prepared for that initial safeguard. What they're not prepared for is the next step after that. That can be helpful as part of the game plan you talked about.
Also, have access to law enforcement. Even with the other type of fraud, a lot of state governments have put resources on their websites where you can report this. Some clients have done that. They realize something is going on, isolate the domains where this is happening, and share that information.
It may not solve the problem, but at least it helps law enforcement triangulate and catch the people who set these sites up. It's a cat-and-mouse game trying to stop some of this. Thinking it through and having a good plan certainly makes a lot of sense.
Silver
Never a dull moment with all this stuff, Joe.
Lazzarotti
No. It's not like the old days, just getting a resume and sending it in, making sure it's on the right paper and looks nice. Those days are over.
Silver
It has all become much more sophisticated and hard to detect, but it keeps things interesting around here. That's a good spot for us to wrap up, Joe, unless you had anything else.
Lazzarotti
Thank you.
Silver
Thank you all for joining us. As always, you can send us any feedback or ideas for future episodes at privacy@jacksonlewis.com. Joe, thanks as always.
Lazzarotti
Damon, take care.
© Jackson Lewis P.C. This material is provided for informational purposes only. It is not intended to constitute legal advice nor does it create a client-lawyer relationship between Jackson Lewis and any recipient. Recipients should consult with counsel before taking any actions based on the information contained within this material. This material may be considered attorney advertising in some jurisdictions. Prior results do not guarantee a similar outcome.
Focused on employment and labor law since 1958, Jackson Lewis P.C.’s 1,100+ attorneys located in major cities nationwide consistently identify and respond to new ways workplace law intersects business. We help employers develop proactive strategies, strong policies and business-oriented solutions to cultivate high-functioning workforces that are engaged and stable, and share our clients’ goals to emphasize belonging and respect for the contributions of every employee. For more information, visit https://www.jacksonlewis.com.