Skip to content
McCoy
AI News

You can't be sure a remote applicant is really in the country they claim.

More applicants are hiding where they really are, and the IP address most companies check is trivial to fake. A phone's location is a much harder thing to spoof.

Josh Gafni

Josh Gafni

August 31, 2026

You can't be sure a remote applicant is really in the country they claim.

A recruiter at a remote-first company recently described a small ritual. Before an applicant gets far into the hiring process, they check the candidate's IP address. More than once they have found someone who claimed to be in Florida but was actually sitting in Brazil, as reported by the Wall Street Journal.

Location lying matters for reasons well beyond honesty. Work authorization, payroll tax, data-residency rules, and in the most serious cases sanctions all hinge on where an employee actually works. The starkest version is the North Korean IT worker scheme, in which operatives use stolen identities to get hired at Western companies and route their wages back to the regime. The U.S. Department of Justice has indicted the facilitators of a network that placed workers at at least 64 American companies, and a 2025 nationwide sweep raided 21 suspected laptop farms.

One security firm found that remote positions are roughly 10 times more likely to receive fraudulent applications than in-office ones. When no one ever meets you in person, the only thing between a false claim and a paycheck is whatever the company can verify from a distance.

An IP address isn't enough

The standard check is to examine the candidate's IP address and the network identifier visible in their web traffic. The IP address feels like it reveals a location, and it is the most common thing hiring tools inspect. The trouble is that an IP address is one of the easiest things in computing to change.

A commercial VPN reroutes someone's traffic through a server in another country, so their IP appears to be in the same place where that server is located. Residential and mobile proxies do the same thing, while looking even more like an ordinary home connection. For a few dollars a month, anyone can appear to be in the required city. The most organized schemes go further with a domestic accomplice, the laptop-farm model, where a person in the target country receives the company laptop, plugs it in, and hands remote control to a worker overseas. To the employer, everything looks local.

A phone's location is a different kind of signal

This is where the device matters. A VPN can switch your IP address, but it can't touch the location your phone reports from its own sensors, because that reading comes from GPS satellites and nearby cell and wifi signals rather than the network route. The person in Brazil with a Florida IP still has a Brazilian phone, and the two disagree.

Reading that phone location well takes a native app. A web page can ask a browser for a rough location, but the reading is easy to override and easy to refuse. A native iOS or Android app receives a precise, sensor-level fix, and just as importantly it can tell when that fix has been tampered with. Apple's App Attest and Android's Play Integrity let the app confirm it is running on a genuine, untampered device rather than a rooted phone or an emulator, which are the states a serious spoofer needs.

Put those together and the signal gets strong. A phone's GPS fix, a check that the fix is not mocked, a device-integrity attestation, and a cross-check against the IP address the same session is using. When a candidate's IP claims one country and their phone says another, that gap is the tell, and a VPN cannot close it.

Treat a location gap as a flag for review

Two cautions keep this fair. First, precise location is personal data, so under regimes like GDPR it needs a clear purpose and the candidate's informed consent. Confirming a region or a country, rather than a street address, is usually enough and far easier to justify. Second, honest mismatches happen. People travel, relocate, and interview from wherever they are that week. So a location gap belongs in front of a human who can ask about it before anything is decided.

None of this makes location fraud impossible, and the effort differs by platform. Android is the softer target, since fake-GPS apps work without rooting the phone, though the system flags those readings as mocked, so a native app can spot them. On iPhone there is no built-in way to fake GPS at all, so a spoofer has to jailbreak the device or drive it from a tethered computer, both awkward and easy to detect. A determined operator with a rooted or jailbroken phone can still beat it, and a domestic accomplice sidesteps the question entirely, but those routes are slow, costly, and detectable, a very different problem from the one a five-dollar VPN creates.

Works Cited

Bindley, Katherine. "Employers Are Making Job Candidates Jump Through Hoops to Prove They're Real." The Wall Street Journal, 30 Aug. 2026. https://www.wsj.com/lifestyle/careers/remote-job-interview-applications-fraud-c9022cbe

U.S. Department of Justice. "Two North Korean Nationals and Three Facilitators Indicted for Multi-Year Fraudulent Remote IT Worker Scheme." Office of Public Affairs, 2025. https://www.justice.gov/opa/pr/two-north-korean-nationals-and-three-facilitators-indicted-multi-year-fraudulent-remote

"U.S. Arrests Key Facilitator in North Korean IT Worker Scheme; Raids 21 Laptop Farms." The Hacker News, July 2025. https://thehackernews.com/2025/07/us-arrests-key-facilitator-in-north.html

"Remote Worker Fraud Prevention: Detecting Location and Identity Deception." Spur, 2025. https://spur.us/research/remote-worker-fraud-prevention

Before the phone screen

Hear your candidates think

Paste one of your job postings below to take the tour with your own role. No signup required.

When you’re ready to try it on a real role, it’s free and no ATS integration is required.

or

No account required

Looking for a job? Try the McCoy app instead →