The fake applicant who cleared three interview rounds before Brainner caught him

Ignacio Iglesias Raggio

Ignacio Iglesias Raggio

August 10, 2026

The fake applicant who cleared three interview rounds before Brainner caught him

How a newly onboarded client discovered, on their first days using Brainner, that a candidate who had already cleared three interview rounds was not who he claimed to be.


When intuition outpaces the data

A few weeks ago, a Talent Acquisition team we just onboarded onto Brainner ran into a case that captures exactly where fraud in recruiting is heading. We will call the candidate "Daniel K." to protect the confidentiality of the process, but every detail that follows is real.

Daniel had applied to a Senior Software Engineer role focused on AI platforms and automation. On paper, he was ideal. Solid resume, relevant experience, coherent answers, and even the LinkedIn photo matched the person who showed up on camera for the first interview.

He advanced to the second round. Then to a panel. He completed a technical assessment. Only after hours of the hiring team's time had been invested did something start to feel off.

By the time the recruiter uploaded his resume into Brainner during onboarding, he was already deep in the pipeline. Brainner flagged him as High Risk on the spot. That single result validated what the team had already been sensing, and opened the door to the deeper analysis that followed.


The signals that do not show up on a resume

On his initial application, Daniel listed a phone number that Brainner flagged on two fronts at once: the line was identified as VoIP, and it carried a high fraud score based on prior activity associated with that number. Either signal on its own would have deserved a second look. Together, they were what pushed his profile into High Risk from the moment the identity check ran.

VoIP is a well known vector. VoIP services are commonly used to spin up disposable identities, so many fake applicants rely on them for the first point of contact. A high fraud score adds a second dimension: it means the number itself has been previously reported or connected to suspicious activity across other databases.

When the hiring team asked Daniel for an alternate phone for the interview stage, he provided a second number. This one was a real phone line, not VoIP, and it did not carry the same fraud score. On the surface it looked clean. But when the recruiter ran it against public databases to confirm ownership, no name came back attached to it. Same story with the California address he had listed.

None of this, on its own, was conclusive. A real phone without a listed owner could be a new number, a prepaid line, or simply an unlisted one. An address with no public match is not proof of anything either. What mattered was the sequence: a first number that Brainner had already classified as high risk, followed by a second number that a legitimate candidate would normally have tied to their identity somewhere.

What ultimately confirmed the team's suspicion was something else entirely: the feeling, across multiple interviews, that other people were in the room with him. Background voices. Unnatural pauses. Answers that seemed rehearsed in a way meant to buy time.


Everything else about him looked perfect

Set the phone signals aside for a moment and Daniel would have cleared any surface check a hiring team runs. His LinkedIn was fully built out: several years of history, connections in the hundreds, endorsements, regular activity on the feed. The profile picture matched the person who joined the interview on camera. His work history on LinkedIn lined up cleanly with what the resume claimed. Stack, tenure at each company, stated location, all internally consistent.

The technical performance held up too. He knew the frameworks he claimed to know. He spoke fluently about past projects. His technical assessment came back solid enough to advance him.

If a recruiter had run a quick manual sanity check, googling his name and clicking through his LinkedIn, nothing would have stopped the process. This is exactly why the case matters. Sophisticated fake applicants are not sloppy. They know that the first thing a recruiter does is compare the resume against a public profile, so they build a public profile that matches. They know that a working assessment moves the process forward, so they invest in the technical prep.

The part they cannot forge as easily is the coherence check across less visible surfaces: whether the phone traces back to them, whether the address ties to their residential history, whether the same identity has been quietly applying to a dozen other companies over the last few months.

A genuine candidate typically has:

  • A phone tied to their name in some public database, with no fraud history attached
  • An address consistent with their residential history
  • A LinkedIn profile whose activity holds up under scrutiny
  • No trail of near identical applications submitted to other companies in a short window

Professional fake applicants solve the first three fronts. They buy partial identities, rent addresses, and build or acquire aged LinkedIn accounts with realistic histories. Each front, on its own, is convincing enough to survive a busy recruiter's manual review. The fourth front, cross referencing against a broader dataset of applications across companies, is the one they almost never solve.

That is exactly what Brainner's High Risk classification is designed to surface. The VoIP number and fraud score were the trigger. The real value came from combining that single flag with the broader pattern once the team knew where to look.


The cross reference that changed the picture

When we checked our internal application database, we found that Daniel had applied to more than six different companies over the last six months. Always Senior Software Engineer or Senior AI Engineer roles. Always following a similar data pattern.

This kind of cross reference is what separates amateur fake applicants from professional ones. A fake applicant who applies once, to one company, is hard to detect. A fake applicant who applies to ten companies using variations of the same resume, or the same phone with different names, or the same LinkedIn with a shifting history, leaves a trail.

That trail only becomes visible when you have visibility beyond your own pipeline.


What a recruiting team can do today

While tooling keeps adding controls, three practices help reduce the risk of investing time in candidates who do not exist:

1. Put technology on your side. Manually cross checking phone fraud scores, VoIP status, address ownership, and application history across dozens of companies is not realistic for any recruiter operating at scale. That is why platforms like Brainner exist: to run those checks automatically on every candidate entering the pipeline, and to surface the combinations of signals that mark a profile as High Risk. Any single flag can be a false positive. What is much harder to explain away is three or four flags stacking up on the same candidate, and that is the pattern automation catches best.

2. Make LinkedIn URL a required application field. Many fake applicants prefer not to leave a public trace. A candidate who does not provide a LinkedIn is itself useful information. And when one is provided, checking connection count, verification date, and consistency with the resume filters out a meaningful share of the noise.

3. Ask us for a second opinion. Not every suspect profile can be resolved with tools alone. Sometimes the flags are ambiguous, sometimes the pattern only makes sense once you have seen it before. When you find yourself in that gray zone, send us the profile. We evaluate hundreds of candidates every week across our client base, so what looks unusual to one team is often part of a pattern we recognize immediately. A second read from us can turn a gut feeling into a confident decision, in either direction.


What is coming: broader cross checks

Daniel's case is not an exception. It is the new baseline. Fake applicants are professionalizing because the economic return on landing a senior remote role at a US company paying in dollars justifies investing weeks in building a convincing identity.

That is why we are expanding our controls toward checks that operate at the network level, not just at the individual candidate level. Detecting the same phone number applying under different names. Detecting the same resume with modified data showing up at multiple companies. Detecting LinkedIn URL patterns that shift systematically every few weeks.

None of these controls would have marked Daniel as High Risk on the strength of a first application alone. But together, layered on top of cross pipeline visibility, they mean that the next time he applies to another company in our network, he will not make it to the second round.


In summary

If your team is seeing more "too perfect" candidates who do not quite hold together, it is not just an impression. The fake applicant profile has changed. The controls that worked a year ago are not enough for the more advanced ones.

The good news is that these candidates, however professional, leave traces when you look at them collectively. The combination of automated flags, cross application verification, and good human judgment remains the most effective defense.

And if there is a candidate you are unsure about, reach out. Often it takes just one cross check of a phone number or resume against our database to get a clear answer in minutes.

Save up to 40 hours per month

HR professionals using Brainner to screen candidates are saving up to five days on manual resume reviews.