Family succession is a time-honored business tradition, but at MBO Partners we recently came across a very different spin on "like father, like son."
At a recent conference, a company we spoke with shared how a routine engagement took an unexpected turn: The person who showed up to do the work wasn't the person who had been vetted and contracted. A father had secured the role; his son stepped in to perform it. By the time anyone caught on, the unauthorized worker had embedded himself in critical workflows—and the damage was already done.
We’ve been hearing variations of this story across industries and around the world, and the pattern is becoming impossible to ignore: Organizations aren’t always engaging the person they believe they are. Recognizing how these schemes work is the first step to stopping them.
Candidate fraud has come a long way. What once meant an exaggerated resume or a fabricated reference has evolved into a far more difficult challenge, fueled by AI-powered tools purpose-built to bypass modern hiring systems.
Remote work has accelerated this shift. It has opened the door to global talent—a genuine win for companies and highly skilled professionals—but it has also removed many of the in-person signals teams once relied on to confirm who they were bringing on board.
Today, candidate fraud shows up in several distinct ways. For example:
Taken together, these tactics represent a coordinated and evolving threat. The consequences for organizations that aren't prepared can be severe and wide-ranging.
The FTC reports that job scam losses rose from $90 million in 2020 to more than $501 million in 2024. Within organizations, the fallout can include unauthorized access to internal systems, exposure of intellectual property, fraudulent payments, and manipulated invoices, along with lasting damage to a company’s reputation.
Financial loss is only one of the consequences. Last year, several Fortune 500 companies reported cases involving North Korean nationals posing as remote freelancers. These individuals passed interviews and onboarding checks, gained access to internal systems, and were later linked to data breaches and attempted extortion. U.S. officials warn these efforts are part of coordinated operations believed to fund cybercrime activities or weapons development programs.
Recent cases from the tech sector and related fields highlight just how advanced and persistent these schemes have become:
These examples make one thing clear: If even high-tech companies are struggling to detect fraud, no industry is safe. At the same time, traditional screening methods are quickly falling behind and failing to keep up with today’s more aggressive threats.
Many elements of traditional background checks were designed for a different era. Take fingerprinting, for example: It verifies identity at the start of an engagement but offers no visibility into what happens next. Someone could share credentials, outsource tasks, or even have another individual complete the work entirely.
Staying ahead of today’s threats requires consistent standards across roles, regions, and worker types, plus continuous verification embedded throughout the entire engagement lifecycle.
In practice, that means:
The right tools and systems matter, but they’re only part of the equation. Real results come from how teams operate day to day, guided by clear expectations and shared accountability. The most effective organizations don’t treat compliance as a one-time task; they build it into their culture.
Here are a few ways to establish strong systems and processes across your organization:
Onboarding is a starting point, not a finish line. Evaluate where identity verification could break down over time and introduce ongoing validation across the full engagement lifecycle.
Ensure hiring managers, recruiters, and compliance teams know how to identify modern fraud tactics, including AI-assisted interviews and impersonation schemes. Ongoing training helps everyone stay prepared as these tactics evolve.
Document your standards for identity verification, contractor oversight, and escalation procedures so everyone knows what's expected. Assign clear ownership across teams to ensure those standards are followed.
Give talent engagement leaders and managers a clear, simple way to flag suspicious behavior. A convenient process for raising concerns helps ensure issues are escalated quickly and not overlooked.
Assess whether your vendors and platforms can detect sophisticated, tech-enabled fraud or whether they're still relying on outdated methods. If they aren't keeping pace with modern threats, it may be time to reconsider those partnerships.
Many organizations don’t have the internal infrastructure to manage this process or simply prefer to rely on a trusted partner. MBO Partners works with clients across industries and around the globe to reduce administrative burden for their teams while strengthening confidence in their security posture.
At MBO Partners, compliance is built into every part of our service model. That includes our dedicated Anti-Impersonation Service, which pairs advanced technology with expert human review to go beyond standard checks.
Behind the scenes, our teams evaluate more than 40 data points in combination—ranging from network infrastructure and device consistency to worker behavioral patterns—so high-risk activity is flagged before it becomes an issue. They are trained to identify and escalate only well-substantiated fraud cases, while managing dispute resolution and follow-through. The result is rigorous verification that keeps your organization secure without slowing it down.
To learn more, visit our Anti-Impersonation Service page and then check out this case study on how we helped a Big Four professional services network complete 6,500+ identity verifications and achieve 100% risk mitigation for their contingent workforce.