Scaut

Tag: Identity fraud

  • The Identity You Trust May Not Be the Identity You Think: Cross-Border Credential Fraud in the European Hiring Market

    The Identity You Trust May Not Be the Identity You Think: Cross-Border Credential Fraud in the European Hiring Market

    From Romanian passports sold to sanctioned Russians, to North Korean operatives applying for developer roles in Germany with fabricated Serbian degrees – the cross-border hiring process has become an active threat surface. Here is what the evidence says European employers must do differently.

    In December 2025, Le Monde published the findings of an investigation that should have sent a chill through every HR and compliance team across the European Union. A small commune in northern Romania called Varfu Campului, population officially around 3,400, had somehow registered more than 10,000 residents. Those residents – citizens of Russia, Moldova, and Ukraine – had been issued Romanian identity documents using fictitious addresses, sometimes without the knowledge of the property owners whose addresses were used. Civil registry officials had processed the applications in exchange for bribes. A criminal network had, in effect, manufactured European Union identities at industrial scale.

    Some of the Russian applicants had used the identities of Ukrainian soldiers killed on the front line to support their citizenship claims. Romanian passports were being sold on social media channels targeting Russian speakers for between 4,000 and 7,500 euros, with prosecutors noting one client paid 75,000 euros to an intermediary for a fraudulently obtained citizenship certificate. By the time Romanian authorities began systematic enforcement, more than 18,700 people from former Soviet republics had registered fictitious residences in the country. Hundreds had already received Romanian passports – and with them, the right to live and work freely anywhere in the European Union.

    The direct employment implication is straightforward and serious. An employer in Prague, Warsaw, or Munich who hires a worker presenting a Romanian passport has no reason, from a document authenticity perspective, to treat that document differently from one issued by the Czech or German state. Romanian citizenship is EU citizenship. Yet a subset of Romanian passports now in circulation are fraudulently obtained, issued through a corrupted administrative process, and may belong to individuals – including Russian nationals evading sanctions – whose true identity and background would disqualify them from employment in regulated environments. An employer who accepts the document at face value has completed a right-to-work check. They have not verified who the person actually is.


    The systematic targeting of European hiring pipelines

    The Romanian passport case illustrates one dimension of the cross-border identity verification challenge: the fraudulent acquisition of apparently legitimate EU documents. A separate and equally well-documented challenge involves the systematic fabrication of entire professional identities for use in European employment applications.

    In April 2025, Google’s Threat Intelligence Group (GTIG) published findings documenting a significant escalation in North Korean state actors targeting European companies for fraudulent IT employment. Investigators found fabricated personas with resumes listing degrees from Belgrade University in Serbia, claimed residences in Slovakia, and specific operational guidance for navigating European job sites – including instructions to use a Serbian time zone during communications to avoid detection. North Korean operatives were seeking work through Upwork, Telegram, and Freelancer, with facilitators in the UK and US helping to manage company-issued laptops and receive salary payments on their behalf.

    Germany and Portugal were specifically identified as primary European targets. The scheme involved not only fabricated qualifications and work histories but also stolen identity documents from real people in Italy, Japan, Malaysia, Singapore, Ukraine, and Vietnam – giving the fraudulent personas a paper trail that appeared to reference genuine individuals who could be found online. Rafe Pilling of Secureworks described the threat plainly: hiring practices are not something most people think about in terms of cybersecurity, but they should be.

    ESET Research’s findings, published in September 2025, added further granularity. Their analysis of the DeceptiveDevelopment group – a North Korean-aligned operation active since at least 2023 – documented specific targeting of developers in France, Poland, and Ukraine. The group used fake job interview processes and social engineering techniques to deliver malware and steal cryptocurrency, with the fraudulent employment pipeline serving as the access mechanism. CrowdStrike has reported investigating at least one European incident per day involving these operations.


    Why CEE employers are structurally exposed

    Central and Eastern European employers sit at the intersection of several overlapping vulnerabilities that make them particularly exposed to cross-border credential fraud.

    The first is the scale and speed of cross-border labour dependency. Eurostat data for 2022 and 2023 shows the Czech Republic received among the highest levels of net migration relative to population of any EU member state, driven by Ukrainian displacement and sustained economic migration from Central Asian countries. The International Labour Organization has estimated that approximately 1 in 4 workers in certain Czech manufacturing and logistics sub-sectors is of non-EU origin. Poland and Germany have experienced comparable dynamics. At this volume, hiring processes that were designed for a relatively homogeneous domestic labour market are being applied to an internationally diverse candidate pool for which they are structurally inadequate.

    The second vulnerability is document trust. The Romanian passport fraud case demonstrates that EU identity documents are not a reliable proxy for verified identity. A document that looks genuine, was issued by a legitimate EU state authority, and passes a visual inspection may nonetheless have been obtained through a fraudulent process. The employer who relies on document presentation as their verification method is operating on a false assumption of security.

    The third vulnerability is the gap between IT hiring and security awareness. The specific targeting of European IT roles – developers, cloud engineers, DevOps professionals – by North Korean and other state-linked actors exploits a structural gap between HR hiring processes and the security sensitivity of the roles being filled. A developer with privileged access to production systems is a high-value target. The hiring manager filling that role is typically focused on technical skills, not counterintelligence.


    What makes cross-border verification genuinely difficult

    The verification challenges are specific and layered, and it is worth being precise about each rather than treating them as a single undifferentiated problem.

    Identity document authentication goes well beyond visual inspection. The Romanian passport fraud demonstrates that even government-issued EU documents can be fraudulently obtained through corrupted administrative processes. Effective authentication requires technical verification against known document standards, biometric matching between the document and the individual presenting it, and – for candidates from higher-risk originating countries – awareness of the specific fraud typologies documented in that jurisdiction.

    Criminal record verification is operationally complex for non-EU nationals. Czech criminal record checks through ISKN operate efficiently for Czech nationals. For a Ukrainian or Kazakh national, obtaining a formal criminal record certificate requires engagement with the relevant national authorities, apostille certification, and translation – a process that most employers simply skip, defaulting to a self-declared statement that carries no evidential value.

    Employment history verification must involve independent contact with prior employers through channels that are not provided by the candidate. In the Warsaw case documented in the Scaut Threat Intelligence Report, the developer’s claimed employment at Estonian and Lithuanian banks was never independently verified. The employers were never contacted. The fraud that followed cost the firm 840,000 euros and eight months of undetected data exfiltration. A verification process that calls numbers the candidate themselves supplied is not verification – it is confirmation of the narrative they want you to accept.

    Sanctions and watchlist screening must be applied consistently across nationalities and conducted in the worker’s native language. An adverse media search conducted only in English will not reliably surface entries in Ukrainian, Russian, Kazakh, or other relevant language sources. For employers in regulated sectors with NIS2 obligations, the inconsistent application of sanctions screening across the workforce is both a security gap and a compliance failure.


    The regulatory environment is tightening from multiple directions

    European employers face a converging set of regulatory obligations that are raising the standard for what constitutes adequate cross-border workforce verification.

    NIS2 and the Czech ZKI impose personnel security requirements on regulated entities that do not distinguish by nationality or employment type. A Ukrainian IT contractor with access to critical systems carries the same screening obligation as a Czech national in an equivalent role. The legal standard does not have a carve-out for workers whose background is harder to check.

    The EU Corporate Sustainability Due Diligence Directive (CSDDD), entering progressive force from 2026, will require companies to conduct due diligence on labour conditions and practices across their supply chains. For employers using staffing agencies to source foreign workers, this creates obligations that extend to the credibility of the vetting applied by those agencies.

    The Employment of Foreigners Act in the Czech Republic requires employers to retain copies of identity documents and work permits for third-country nationals. This is a documentation requirement that many employers fulfil without any meaningful verification of the documents being retained – filing a potentially fraudulent document with administrative efficiency while creating a false sense of compliance.


    What proportionate verification looks like in practice

    The cases reviewed here – the Warsaw financial services fraud, the Romanian passport network, the North Korean IT worker campaigns targeting Germany, Poland, and France – share a common characteristic. The fraud succeeded not because it was undetectable, but because the detection was not attempted, or was applied at an inadequate standard.

    Effective cross-border verification requires document authentication that goes beyond visual inspection: technical verification of security features against known standards for the issuing country, biometric matching between document and individual, and awareness of the specific fraud typologies relevant to each originating jurisdiction. The Romanian passport case in particular means that EU citizenship documents from certain issuing contexts should no longer be treated as inherently reliable.

    Employment history verification must involve independent contact with prior employers through channels researched independently, not provided by the candidate. For employers in Estonia, Lithuania, Ukraine, or Central Asia, this requires language capability and in-country partner access. This is a specialist resource, but it is the difference between confirmation and verification.

    Criminal record verification for non-EU nationals requires structured engagement with the relevant authorities in the originating country – either through direct request processes or through specialist partners with established access. The shortcut of accepting a self-declaration is not a proportionate response to the documented risk.

    Sanctions and adverse media screening must be applied consistently across the full workforce, regardless of nationality, and conducted in the candidate’s native language. The convergence of state-sponsored employment fraud, sanctions evasion through document manipulation, and the industrial-scale falsification of professional credentials means that the cross-border hiring process is now an active threat surface. The employers who recognise this and build their verification processes accordingly will be better protected. Those who continue to rely on a document check and a reference call to a number the candidate provided are leaving a door open that motivated bad actors already know how to walk through.

  • Need a fake ID? No problem, its so easy!

    Need a fake ID? No problem, its so easy!

    Need a Fake ID? No problem, it’s easy!

    The identity black market has gone mainstream. Services that churn out fake driver’s licenses, passport cards and “verification” files are cheap, fast and marketed like everyday e-commerce.

    In the last year alone, law enforcement shut down VerifTools, an online marketplace that sold fraudulent identity documents for as little as $9, paid in crypto. In a separate U.S. case, a counterfeiter told investigators he sold state IDs for $250 to people seeking gig-work accounts—showing just how low the entry price is for evading ID checks.


    How easy is it to get a fake ID today?


    Very.
    Counterfeiters operate on open web storefronts, in closed social and messaging groups, and on the dark web – shipping physical cards by mail or delivering digital “packs” instantly. Europol and national police have repeatedly taken down rings that used dark-web listings, instant-messaging apps and postal services to distribute counterfeit IDs across the EU.

    U.S. border inspectors routinely seize bulk shipments of counterfeit licenses at mail facilities, thousands at a time (illustrating industrial-scale supply). And in 2024–2025, European raids dismantled multiple document labs and distribution hubs (including one disguised as a travel agency in Athens), with thousands of forged documents recovered.


    What are fake IDs being used for?


    1) Employment and gig onboarding

    • Right-to-Work evasion and “job identity” fraud (including digital checks). UK verifiers report UK/Irish documents are the most commonly faked in these flows.
    • Gig platform abuse: a 2025 federal case alleges fake IDs were produced and sold to create or pass driver accounts on a major delivery app.

    2) KYC/financial access

    • Regulators warned banks about counterfeit U.S. passport cards used to commit identity theft and open/operate accounts.
    • Global watchdogs note document fraud’s role in enabling money muling and cross-border crime, which depend on “breeder” documents to build synthetic or assumed identities.

    3) Right-to-Rent & access to services

    • The UK raised Right-to-Rent fines significantly in 2024, reflecting the scale of document abuse in housing markets.

    4) Age gates & restricted goods

    • Bars, dispensaries and e-commerce age checks continue to face high volumes of fraudulent IDs; one commercial analysis logged 1,000,000+ fake IDs flagged in a 12-month span across venues.

    5) Immigration and travel fraud

    • Counterfeiters sell green cards and Social Security cards for hundreds of dollars, with recent U.S. convictions underscoring the availability and price point.


    Why this matters: the ripple effects from economies to individuals


    Economic drag & compliance risk.
    Fraud doesn’t end at the first loss. The FBI’s 2024 Internet Crime Report tallied $16+ billion in reported losses (up 33% year over year). That excludes unreported cases and many identity-led schemes. The U.S. FTC separately logged $12.5 billion in consumer fraud losses for 2024, even as the number of reports stayed roughly flat, meaning a higher share of victims are losing money.

    For businesses, every dollar of fraud triggers multiple dollars in operational, chargeback, recovery, remediation and compliance costs. Current benchmarks show financial firms and merchants losing $3–$5+ for every $1 of fraud, depending on sector.


    Public safety & organized crime.
    EU agencies call document fraud a key enabler for migrant smuggling, trafficking and other cross-border crime. Europol’s recent actions in Greece illustrate the scale and sophistication: print shops, distribution hubs and thousands of forged IDs serving illicit networks.


    People get hurt.
    Identity theft drains savings and damages credit; FinCEN and the FBI have warned that criminals now pair fake documents with AI-generated media to bypass verification and manipulate victims.


    The “easy button” problem: speed, price, and scale

    When a usable fake costs $9–$250 and can be delivered in minutes (then reused across employers, platforms and banks) the attack surface grows exponentially. Recent seizures and takedowns show low prices, quick delivery and industrial production are the rule, not the exception.


    What resilient screening looks like in 2025


    High-fidelity document checks, plus:

    • Document forensics: security-feature inspection (microprint, UV/IR, OVD), template libraries, MRZ/1D/2D barcode verification, and tamper detection for screenshots/printed photos. (FinCEN’s passport-card alert is a reminder that “looks real” isn’t enough.)
    • Biometric binding: selfie liveness with challenge-response; texture/reflectance analysis to catch screens/deepfakes. (Regulators flag rising deepfake-assisted document fraud specifically targeting onboarding.)
    • Data corroboration: authoritative databases (work authorization/right-to-work, sanctions/PEP), address and phone tenure, device fingerprint, risk signals.
    • Contextual trust: velocity, geolocation consistency, repeated photo/ID reuse across accounts, known mule patterns.
    • Human escalation with the right evidence: clear audit trails (who, what, when), second-factor re-verification for sensitive roles.

    Bottom line: when fake identities are this cheap and this fast, layered verification is the only sustainable defense.

  • North Korean Worker Infiltrations Are Exploding – Why Companies Must Act Now

    North Korean Worker Infiltrations Are Exploding – Why Companies Must Act Now

    A recent report in Yahoo News has revealed a dramatic surge in North Korean infiltration attempts targeting Western companies. According to U.S. and allied security agencies, thousands of IT professionals with hidden ties to Pyongyang are disguising themselves as freelancers or remote job applicants to funnel money and intelligence back to the regime.

    While the story is only now breaking into mainstream coverage, this is far from new. At Scaut, we have been warning about the growing threat of foreign infiltration for years.

    A Threat We’ve Been Documenting for Years

    What is becoming headline news today, we have been actively fighting for years.

    Why North Korean IT Workers Are a Unique Threat

    North Korean operatives are often highly skilled, disciplined, and trained to operate in the shadows. They use stolen or fake identities, sometimes even deepfake videos for interviews, to infiltrate remote teams. Once inside, they gain access to sensitive systems, intellectual property, and financial assets—all while secretly sending profits back to fund weapons programs.

    The explosion in these cases is not surprising. It is the logical consequence of:

    • Growing demand for remote IT talent.
    • Lack of proper background verification processes.
    • Increasingly sophisticated deception techniques.

    Scaut’s Role: Europe’s First Mover in Screening Technology

    At Scaut, we are proud to say we were the first screening company in Europe to bring this issue to light and to actively build technology solutions to detect and prevent infiltration.

    Our work combines:

    • AI-based fraud detection to flag fake CVs and manipulated documents.
    • Identity and background verification across jurisdictions.
    • Continuous research and monitoring of emerging threats.

    This is why hundreds of European companies rely on us—not just to hire, but to hire securely.

    What Companies Should Do Today

    1. Stop relying solely on resumes and LinkedIn profiles.
    2. Verify identities using independent screening tools.
    3. Train recruiters to recognize deception techniques.
    4. Implement ongoing monitoring of your workforce—not just pre-hire checks.

    Conclusion

    The North Korean infiltration wave confirms what Scaut has been saying for years: the hiring process has become the new frontline of corporate security. Companies that fail to adapt will expose themselves not just to fraud, but to espionage and national security risks.

  • Chinese infiltrate Czech companies. Startups encounter “fake IT” applicants!

    Chinese infiltrate Czech companies. Startups encounter “fake IT” applicants!

    When domestic IT companies and startups are looking for employees for specialized programming positions, they often hire a foreigner who then works remotely. This is common in the IT environment. However, Czech companies have recently encountered a remarkable phenomenon: job applicants who, according to the documents they provided to their prospective employer, should be sitting at a computer somewhere in Europe are actually Chinese.

    According to experts, this is not just a ploy to get a lucrative job in Europe with a salary of several thousand euros a month, but may be a way to gain access to sensitive data and business information. In other words, it may be an attempt at industrial espionage.

    This was the case of one of the Czech technology startups that MF DNES met (due to the sensitivity of the case, the editors did not mention the name of the company). A person interested in the job of a developer applied for the job via the social network LinkedIn. According to the documents he provided to the company, he was a Danish citizen living in Estonia. He successfully passed several rounds of the recruitment procedure, which tested his programming skills. However, the information in his passport was suspicious to the company. So it decided to thoroughly vet the programmer.

    “When we followed the trail of the linkedin profile, we found that it was interlinked with others. They all have common characteristics, they try to give the impression that these people are graduates of European universities and usually work remotely for a long time, for example from Serbia or Estonia,” says Petr Moroz from Scaut, which screened job candidates for the company.

    The club of hundreds of linkedin profiles then converges on the Chinese city of Dandong, a city of two million near the border between China and North Korea. The city is home to, among other things, a Chinese army base.

    That the Chinese intelligence services may be behind the activities of the ‘fake A.I.’ is just one theory. However, the largest domestic secret service, the BIS counterintelligence agency, has long warned against Chinese activities on Czech territory.

    “We have long warned about their efforts to engage in various variations of so-called industrial espionage. This concerns mainly technology companies, but also scientific projects, where there is an attempt to exploit various financial offers, invitations to China for cooperation, congresses and symposia. We are therefore working very intensively with scientific and academic institutions to be prepared for these efforts,” said BIS spokesman Ladislav Šticha.

    State vs. TikTok

    Just days after Koudelka’s speech, the National Cyber Security Bureau (NCSB) issued a warning about the popular Chinese app TikTok. Because of the fact that it collects a large amount of data about its users that is unrelated to the short videos that have made the app a global phenomenon. This includes data from the user’s calendar or contacts.

    “I have come to issue the warning based on a comprehensive analysis of information about the TikTok app that we have obtained from both public sources and our allies,” said Lukáš Kintr, director of the National Cyber Security Authority.

    Some state institutions, ministries and authorities had banned TikTok for their employees even before the NCIB warning. Universities, for example, responded to its warning by urging students not to use the app if they are connected to the university network. According to a survey by NMS Market Research, one in ten Czechs stopped using TikTok after the cybersecurity bureau’s warning.

  • After all, falsifying a resume is so easy…

    After all, falsifying a resume is so easy…

    Case one: Fake IT professionals

    Prominent consulting and IT companies Accenture and Cognizant have recently discovered that they employ fake IT professionals. These programmers have embellished or completely fabricated their previous experience, falsified recommendation letters, and landed their dream jobs.

    The agencies have not disclosed the extent of the damage caused by these fake programmers or the cost of verifying and rectifying their actions. However, both companies now know that cutting corners in employment verification does not pay off.

    Case two: Fake pilots

    Do you think that a fake IT professional cannot cause much harm? It depends on the perspective. If you hire them to develop or test something for you, the damage they could cause due to their lack of knowledge can be significant. However, most of the time, it will be financial losses that can still be resolved.

    But what about a fake pilot? A commercial airline pilot who has also “improved” their resume?

    A few years ago, there was a case of forged resumes for 200 commercial airline pilots in China. These were 200 successful fraudsters who obtained jobs with local airlines and flew with passengers on board. Let us hope that not only Chinese airlines learned from this and are now more thorough in verifying their pilots’ history. In the case of a fake pilot, the consequences of their failure could be truly tragic…

    Case three: Fake doctors

    Are you afraid of planes and don’t like to fly, and therefore the case of fake pilots didn’t bother you?

    Alright.

    And what about a fake doctor or paramedic right here in the Czech Republic? Yes, it happens. Fake doctors have operated in several dermatology clinics in the Czech Republic, often from abroad. They may have studied biology or nothing at all, are not doctors, are not members of the medical chamber, and yet they perform surgeries on patients.

    Are you still not afraid?

    So let’s go to the largest Czech hospital, Motol in Prague. And also to the ambulance service in Kralupy nad Vltavou. A fake healthcare worker also worked there. At Motol, he was trying to work as a healthcare assistant in the Pediatric Intensive Care Unit, and at the ambulance service as a regular paramedic with medical education.

    How did he prove himself upon joining? With a doctored high school diploma and a fake German diploma. He passed through, started working, and treated both children and adults…

    Don’t be afraid to verify employees

    No, we don’t want to scare you. We don’t live in a perfect world, and everyone makes mistakes. But when we know about a mistake, it’s important to eliminate it and prevent it from happening again.

    Fake pilots, doctors, as well as teachers, welders, call center operators, or train drivers, can cause many problems and cause significant damage. Employers, clients, suppliers, actually everyone who comes into contact with them, can be affected. If you don’t want the next scandal to involve you, consider a more systematic approach to verifying new employees.

    A forged high school diploma really shouldn’t pass through.