Remember the letter-writer whose company had been infiltrated by a proxy interviewer crime ring? Here’s the update.
Thank you so much for publishing my letter. A special thanks to everyone who said it wasn’t a fake letter — perhaps I spend too much time on Reddit, where everything is labeled fake. Part of the reason I said that was that before writing in, I ran this situation by a friend who is head of cybersecurity at a casino, and he was just as floored as I was by the whole thing. I guess we all know better now.
I am so sorry I wasn’t able to engage in the comments. It was posted at the end of the quarter, which is always crazy, and I don’t think I even saw it until several days later.
What Happened Next
I am not going to name the actual country, but I will say with absolute certainty it was NOT North Korea or anywhere in Asia that the “Fakeistan” employees were from.
Things got a little crazy before they got better. The Fakeistan employees worked for the rest of the week while HR, Legal, and IT all got involved. As I mentioned, we had to pull every employee we had hired over the last year onto video and send screenshots for comparison. Ironically, one employee who had a Fakeistan surname and a very slight accent was determined to be legitimate but had to undergo multiple audits to be sure. I’m not sure they even know how closely they were being watched.
We were told to use any pretense to pull employees into meetings and screenshot their faces for comparison to their interview recordings. For the employees I knew would pass, it was easy. For my two Fakeistan employees, I literally threw up from anxiety because I felt so bad. I know it had to happen, I know they were in the wrong, but it just hurt — especially with them thanking me profusely after the meeting for all of my help and saying how much they loved working at our company.
What We Believe Happened
I will never know exactly what happened since I’m way too far down in the org chart to be privy to what was found, but I do believe that commenter Specks got it right: I don’t think they were trying to steal information, just trying to get jobs. As many commenters mentioned, they were probably giving a cut of their paycheck to whoever facilitated the arrangement — they all worked a lot of overtime any time we offered it, suggesting they may have been working toward a set limit of debt they were trying to pay off.
I was told that their documents, upon closer review, didn’t match. I asked if IT could verify whether they were using VPNs and weren’t actually in the U.S., but only IT knows for certain. I do think they were in the U.S. — why would everyone pick the same state if not? I just think they were people who, if we had interviewed them as themselves, we probably would not have hired.
How They Were Let Go
Thankfully, my own boss stepped in with HR to handle the terminations, so the managers didn’t need to be directly involved. The employees were read a three-sentence message crafted by the legal department, with clear instructions not to deviate from it in any way. We did acknowledge the reason for the departure — fraudulent identities — and they all essentially responded with “okay, yeah” once they realized we knew. The ones we couldn’t reach right away were immediately locked out of their computers by IT, as a precaution in case they knew each other, even though they had never given any prior indication of that.
Changes Going Forward
I forwarded the links that commenter Madame Desmortes posted — a fascinating and validating read — to my boss. We now have several new procedures in place.
One effective change is that the training manager now has access to all interview recordings and reviews them before each training class begins.
One policy I’m more conflicted about is an AI filter in our hiring platform that automatically rejects any candidate without a digital footprint — no LinkedIn, no Facebook, no Instagram, and so on. I don’t love it. I think we’re probably rejecting candidates who may not use the same name on their resume as they do on social media, and it unfairly targets people with a name change due to divorce or marriage, people who are in the midst of transitioning, and people who simply don’t have social media accounts under the “government” names they put on a resume. Since this situation went all the way up to the CEO, I don’t think I have enough standing to push back on it, so I’ve had to let it go.
There were a couple of Fakeistan surnames still in resume review when this all happened, but they never made it to the screening stage. After that, no more came through, so whoever was running the operation must have realized we had figured it out and stopped.
A Humbling Reminder
I still see their names on reports I pull up, and I remember how happy they were to work here, how well they processed and implemented feedback, and how quickly they became valuable assets despite their rough starts. It makes me sad every time. I hope they’re doing as well as they can. I hope they’re safe.
There’s really no happy ending here — just a valuable lesson and a humbling reminder of what a privilege it is to go through life on easy mode because of where you were born.