Teams by Intent Ep 4: Michel Adams from Okta on Tech to Tackle Contingent Candidate Fraud
This episode of Teams by Intent features Michel Adams, Contingent Workforce Manager at Okta, about the growing challenge of candidate fraud and why contingent talent may represent one of the most overlooked areas of workforce risk.
Michel explains how proxies, fabricated identities, AI-generated profiles, and emerging deepfake technology are changing the hiring landscape. She also shares how Okta combines identity verification, background screening, technology, and human oversight to protect the hiring process from initial application through onboarding.
Candidate Fraud Is Becoming a Workforce Security Issue
Remote and hybrid work have fundamentally changed what it means to protect an organization. Workforce security was once closely associated with physical access: badges, offices, equipment, and secure facilities. Today, someone can be interviewed, hired, onboarded, and granted access to critical systems without ever entering a company location.
That flexibility has created tremendous opportunities for organizations and workers, but it has also created new vulnerabilities. A bad actor does not necessarily need to hack into a company if they can successfully navigate the hiring process, receive legitimate credentials, and gain authorized access from within.
Candidate fraud can take several forms. Some candidates use proxies because they do not possess the experience or technical skills required for a role. Another person may complete an assessment or participate in an interview, while the individual who ultimately reports for work is someone entirely different. In more serious cases, fabricated candidates may be attempting to enter an organization specifically to obtain intellectual property, company information, or sensitive customer data.
AI is making these schemes easier to execute and more difficult to identify. Fraudulent applicants can now generate convincing résumés, build artificial professional histories, create false profiles, and potentially use deepfake technology during virtual interactions. What once required significant time and coordination can increasingly be produced and distributed at scale.
Why Contingent Talent Deserves Greater Attention
Many organizations have established mature security and onboarding practices for full-time employees but apply different standards to contingent workers. That distinction can create risk because contingent professionals may perform the same work, use the same systems, and access the same information as permanent employees.
Their relationship with the organization is also more transient. Contractors may enter and leave quickly, move between assignments, or work through multiple staffing suppliers. If a fraudulent worker is discovered, that individual may disappear before the organization fully understands what happened.
This does not mean contingent workers are inherently less trustworthy. It means organizations should evaluate risk according to the access a person receives, rather than the employment category assigned to them. If two people can reach the same systems and information, there is a strong argument that they should pass through comparable identity and security controls.
The Gap Between Application and Onboarding
One of the most important vulnerabilities Michel identifies is what she describes as the “sandwich problem.” An organization might verify a candidate during the initial application process and validate that person again during onboarding, while leaving the interviews and assessments in between largely unprotected.
That gap gives someone else an opportunity to participate on the candidate’s behalf. The person interviewed may have the expected technical knowledge and communication skills, while the individual who reports for work may not. Even when the motive is simply to secure a job, the organization is not receiving the talent it evaluated and selected.
Closing this gap requires identity checks at meaningful points throughout the process—not simply at the beginning and end. At Okta, those protections include applying consistent background-screening standards to full-time and contingent workers, validating identities during onboarding, and confirming that new workers are who they claim to be before granting access to equipment and systems.
Okta is also piloting tools that can help identify questionable information earlier. These technologies can assess whether an email address appears legitimate, flag potentially suspicious phone numbers, and compare information on a résumé with a candidate’s professional profile. Identity verification can also be integrated into virtual interviews, allowing candidates to confirm who they are before entering a meeting.
Technology can complete many of these checks quickly, but it should not make every decision independently. When something appears suspicious, human review remains essential—both to investigate legitimate risks and to reduce the possibility that an automated system unfairly excludes a qualified candidate.
Security Has to Be a Shared Responsibility
Candidate fraud does not fit neatly within the boundaries of HR, IT, procurement, or corporate security. Each group sees a different part of the process, which makes collaboration essential.
Staffing partners have an important role in validating the candidates they submit, but transferring the entire responsibility to suppliers leaves the organization vulnerable. Employers ultimately remain responsible for protecting their systems, information, customers, and reputation. They must establish clear expectations, educate their partners about emerging threats, and create processes for sharing concerns.
Hiring managers also need to understand what candidate fraud can look like. They may be the first people to notice discrepancies between a résumé and an interview, differences among interview rounds, or a sudden change in a candidate’s communication or technical ability. Those signals become more valuable when managers know how and where to report them.
Michel describes this as requiring a “team sport mentality.” The objective is not to assign blame after fraud occurs. It is to connect the people who recruit, evaluate, onboard, equip, and manage talent so they can identify risks before access is granted.
Stronger Security Does Not Have to Create More Friction
Organizations may hesitate to introduce additional identity checks because they fear creating distrust or damaging the candidate experience. But security and accessibility are not inherently at odds.
Modern identity verification can often be completed in less than a minute. For a remote candidate, briefly confirming an identity before a virtual interview is still considerably less disruptive than traveling to an office for an in-person meeting.
The key is to make each safeguard proportionate, explain why it is necessary, and apply it consistently. Legitimate candidates are also invested in joining secure organizations—particularly when they will be trusted with sensitive systems, proprietary information, or customer data.
Moving From Reaction to Prevention
Organizations do not need to implement every available technology immediately. A more practical starting point is to map the existing hiring process and identify where identities are verified, where responsibility changes hands, and where unexamined gaps may exist.
Workforce leaders should consider:
- Are contingent and full-time workers screened according to the access they receive?
- Is identity confirmed only during onboarding, or throughout the hiring process?
- Could one person complete an interview while another reports for work?
- Do hiring managers know how to recognize and escalate suspicious activity?
- Are staffing partners aware of the organization’s security expectations?
- When technology flags a concern, is there a clear process for human review?
- Can new safeguards be piloted within one role, location, or talent channel before being expanded?
Every organization has information worth protecting. That may include intellectual property, financial records, customer data, employee information, healthcare records, or access to the systems that keep the business operating.
As candidate fraud becomes more sophisticated, workforce security can no longer begin on an employee’s first day. It must become part of how organizations identify, evaluate, verify, and welcome talent—regardless of whether that person joins as a full-time employee or a contingent worker.
Teams by Intent is a podcast from YUPRO Placement exploring how forward-thinking organizations are redesigning workforce strategies to build stronger, more adaptable teams. Listen now and join the conversation about what it takes to build great teams by intent, not by chance.
Stay Up-to-Date with the Latest on Skills-First Hiring Resources
Sign up for YUPRO Placement Emails
"*" indicates required fields
