Agentic security

The Identity Chain of Custody

By Robin Martherus


Somewhere in your company, there is a decent chance you employ someone who is not the person you interviewed.

That is not a hypothetical. North Korea runs an industrial-scale program that places its operatives in Western remote jobs under fabricated identities. The workers collect salaries, sometimes several at once, and route the money back to the regime — a sanctions violation with real legal exposure for the employer. The scale is startling. Okta’s threat researchers tracked just 130 of these identities and linked them to more than 6,500 job interviews across more than 5,000 companies between 2021 and mid-2025 — and they call that a small sample of the total activity. Nine security officials told Axios they have never met a Fortune 500 company that hasn’t inadvertently hired one.

The uncomfortable part is how cheap the attack has become. Researchers at Palo Alto’s Unit 42 showed that a novice, with no image-manipulation experience and an old laptop, could build an interview-ready synthetic identity in about seventy minutes. The face on the video call is an AI puppet, driven in real time to match the operator’s lip movements. One operator can interview as several different candidates. Several operators can share one candidate.

Read that last sentence again, because it is the key to this whole problem.

Point Solutions at Every Point

The industry is not ignoring this. It is responding the way it usually responds: with strong solutions at single points.

At the front of the funnel, identity proofing is getting real standards. The OpenID Foundation’s eKYC and Identity Assurance working group defines how to communicate verified claims — not just “name: Robin,” but “name: Robin, verified against a passport, by this method, on this date.” A newer effort extends that schema so a relying party can build a defensible belief in who it is dealing with. Another new group is wiring mobile driver’s licenses into the same flow.

In the middle of the funnel, deepfake detection is becoming a product category. GetReal, backed by Cisco Investments and co-founded by digital-forensics pioneer Hany Farid, now combines live deepfake detection with continuous identity verification on voice and video calls. It watches the interview while the interview is happening.

At the back of the funnel, identity threat detection and response tools mine login telemetry, device fingerprints, and behavior for signs that an account is not being used by its owner.

Each of these is necessary. None of them talks to the others. And that gap is exactly where the attack lives.

The Stage-Substitution Attack

Suppose every stage of your hiring process independently verifies that it is dealing with a real, document-verified human. You still lose. Here is how.

The fluent English speaker takes the recruiter screen. The strong engineer takes the technical interview — or a deepfake overlay lets one specialist take it for five different “candidates” in the same week. The person whose identity is being used, sometimes a paid domestic accomplice, shows up for the onboarding document check. Then the company laptop ships to a house where dozens of company laptops sit racked together, remotely operated from overseas. In May 2026, the Department of Justice sentenced two Americans to prison for hosting exactly these laptop farms.

Every stage passed its check. No single person was present across the stages. I call this a stage-substitution attack, and it defeats verification by exploiting the seams between verifications.

The lesson is one the security industry has already learned once, in another context: a checkpoint model fails when the thing you are protecting moves between checkpoints. That realization gave us zero trust for networks. Stop assuming the inside is safe. Never trust, always verify. Verify explicitly, per request. Assume breach.

Hiring needs the same shift, and the mapping is almost word for word:

  • Never trust, always verify. No hiring stage inherits trust from the previous one. Passing the screen does not authenticate you into the interview.
  • Verify explicitly, per request. Every stage — screening, each interview round, the offer, onboarding, day-one laptop issuance, day ninety — is its own verification event.
  • Assume breach. Any single check can be beaten. A deepfake beats a camera. A forged document beats a tired reviewer. So no single check gets to be load-bearing.

But zero trust for candidates has one requirement that the network version never made explicit, and it is the one that matters most.

Continuity, Not Repetition

Verifying at every stage is not enough if each verification stands alone. Ten independent checks that each ask “is this a real, verified human?” are ten opportunities for a different real human to answer. That is the stage-substitution attack again, just with more paperwork.

What hiring actually needs is an identity chain of custody: evidence, at every stage, that the person present now is the same person who was verified at the start.

That takes three pieces.

First, an anchor. At the front of the funnel, establish identity once, with the strongest provenance available. The right model here is older than the deepfake problem. Years ago, working in identity federation, I proposed a SAML design in which each attribute in an assertion would be asserted by its primary source. The Social Security Administration would vouch for the SSN, the postal service for the mailing address, the phone carrier for the number. One assertion, many authoritative signers. The idea went nowhere then, because the authoritative sources were not issuing. It is now arriving anyway, as verifiable credentials and mobile driver’s licenses: the DMV signs the license, the university signs the diploma. The eKYC standards get partway there but stop short. Today’s verified claims describe the evidence one asserting party saw, rather than carrying signatures from the primary sources. That difference matters. A deepfake defeats a camera. It does not defeat a signature chain.

Second, binding. Every later stage must match the person present against that anchor — face, voice, and behavior compared to enrollment, not just checked for liveness. This is the difference between asking “is this a real human?” and asking “is this that human?” In-call deepfake detection answers the first question. Only binding to the anchor answers the second, and the second is the one the attack targets.

Third, a handoff — not an ending. Today, verification stops at onboarding. That is precisely when the scheme starts profiting. The chain of custody has to hand off to post-hire monitoring: same anchor, new sensors. Device fingerprints. Typing and interaction patterns compared against the interview-stage baseline. Work-hour geography against the claimed residence. And one signal nobody sees alone: the same operator fingerprint appearing behind several “different” employees. Assurance should behave the way trust behaves everywhere else in security. It decays with time and must be re-earned by observed behavior. Day ninety deserves evidence, not memory of day one.

The current standards have no notion of this. A verified claim is a statement about the past with no expiry on its confidence. Adding temporality — assurance levels that decay and must be refreshed — is, I would argue, the most important extension the identity-assurance community could take up next.

Who Can Actually Build the Chain

Here is the structural problem: no single employer sees enough to run this chain well. Each company sees its own funnel and nothing else.

The parties that own the funnel — job platforms, sourcing tools, background-check networks — see something no employer can: the cross-employer graph. The same synthetic persona applying to forty companies. The same voice behind six names. The same residential IP address receiving laptops from five employers. Fraud that is invisible in any single funnel is obvious across funnels.

That suggests where this capability should live. Verification becomes a funnel-level service: anchored at enrollment, bound at every stage, handed off to the employer’s monitoring at hire. The platform that builds it first turns its biggest liability — being the front door the fake candidates walk through — into its moat.

The Human Cost, Handled Honestly

There is a real objection here, and it should be said out loud before someone else says it: zero trust for people is not the same as zero trust for machines.

Continuous biometric checking of employees runs into consent, labor law, and disability accommodation. It also runs into the very real harm of false positives: the genuine employee flagged as an impostor because they bought a new webcam, or because their voice changed after surgery. A regime that treats every worker as a suspect all day will deserve the resistance it gets.

The design answer is proportionality. Spend high-assurance checks at the stage transitions, where the attack actually operates — screen to interview, interview to offer, offer to onboarding, onboarding to device. Between transitions, rely on passive, low-friction signals. And reserve humans for what humans are for. I have argued before that a human in the loop is not a governance strategy at machine speed and scale. Hiring is no exception. A person cannot manually re-verify thousands of interviews, and asking them to try produces rubber stamps. Humans belong above the loop — setting the thresholds, arbitrating the ambiguous cases the system escalates, and auditing the machinery — not inside it clicking approve.

The Bottom Line

The deepfake hiring problem is not a document problem, an interview problem, or an insider-threat problem. It is a continuity problem. The industry keeps buying stronger snapshots — better identity proofing, better in-call detection, better post-hire analytics. The attack lives in the gaps between the snapshots.

Verification is not an event. It is a chain: anchored once with primary-source provenance, bound at every stage to the same person, and carried past onboarding with assurance that decays unless behavior renews it.

One-time verification tells you who showed up on day zero. A chain of custody tells you who is actually doing the job. In an era when a convincing face costs seventy minutes to build, that difference is the whole game.

Leave a Reply