Face Rental: The Candidate Fraud That Passes Every Document Check

Researchers at Silent Push found a job ad in a Discord server for computer mouse reviewers. Turn on your camera during interviews, communicate with clients, represent the necessary skills confidently, and keep 35% of the salary.
They contacted the recruiter on Telegram and got the rest of the arrangement. He would feed answers by chat during live interviews, and offered more if wanted: "I can remotely access your screen and complete coding tasks while you continue the conversation smoothly." He suggested the proxy use ChatGPT for anything he missed. Silent Push assesses with high confidence that the operator is a North Korean IT worker recruiting Western and Latin American citizens as "the 'face' and legal identity to bypass sanctions, KYC (identity verification) controls, and regional hiring restrictions."
The person on that camera is real. The government ID is theirs, genuinely issued. Their face matches it because it is their face, and they are demonstrably alive and present. Every check built to catch a fake returns a clean pass, because nothing in front of the camera is fake.
Key takeaways
- Document authentication, face match and liveness all clear a rented face, since the person, the document and the face are all genuine.
- Silent Push documented active recruitment offering a 35/65 split to citizens who sit interviews while the operative supplies answers by chat and, where permitted, takes remote control of the machine.
- The countermeasures in that same alert still tell employers to watch for documents that "appear forged or altered," which a genuine ID never does.
Why the document check clears
Candidate verification is built to answer three questions. Is the document real, does the face match it, and is the face a live human rather than a photo, a mask or an injected video stream.
Against synthetic attacks, those questions work well. Against a rented face, all three pass on the first attempt. The assumption underneath most hiring stacks is that a fraudulent candidate cannot match the identity they arrived with, and a consenting proxy breaks exactly that. The fraud has moved out of the document and into the arrangement behind the person holding it.
Better detection accuracy will not help, because there is no artifact to detect. The evidence lives in behavior, in the session, and in whether the same human keeps showing up.
What the scheme asks for
The pitch Silent Push documented is specific:
- Geography. The operator solicited people in the US, EU, and Latin America, naming Brazil, Mexico, Argentina, Colombia and Chile, to bypass "geographic IP/location blocks and regional tax compliance checks."
- Face rental. The ad asks the proxy to appear on camera, speak with clients, and "represent the necessary skills confidently."
- Live coaching. Real-time messaging supplies answers and code while the proxy holds the conversation.
- Remote desktop control. The operator offers to complete technical assessments directly through remote management software.
- AI for the gaps. The proxy is told to generate responses with tools like ChatGPT.
- Payment through the proxy. Salary lands in a local US or EU bank account, and 65% moves back through crypto, wire or third-party processors.
Everything a verification system can inspect is authentic. Everything fraudulent sits outside the frame.
What it looks like when it works
Minh Phuong Ngoc Vong presented a Maryland driver's license and a US passport for a software development role on a federal contract. Both were genuine, he was who he claimed to be, and the FAA authorized him to receive a Personal Identity Verification card. Then, according to the Justice Department, which sentenced him in December 2025, "between March 2023 and July 2023, Doe used Vong's credentials to perform the software development work from his location in China."
Four months of work by someone else, with every control functioning as designed.
The volume is significant. Christina Chapman was sentenced to 102 months for a scheme generating $17.1 million across 309 US companies using 68 stolen American identities, with workers hired "often through temporary staffing companies or other contracting organizations." Which is why the FBI tells employers that when workers arrive through a third party, they should request documentation of the vetting process, and absent it, "assume it did not conduct the background check and conduct your own."
What defenses catch a rented face
A trained human in the session.
An automated check evaluates a document and a face. A person evaluates the situation: eyes tracking to a second screen before each answer, a pause that does not match the fluency of the response, an inability to speak to the work on the résumé. At the high-stakes stages, Proof puts a trained identity agent in a live session carrying the risk signals and prior verifications from earlier in the funnel, so a hesitation gets weighed against everything already known about the person.
Continuity, so one clean pass is not enough.
Renting a proxy for a single scheduled call is cheap. Keeping one available across shortlist, the interview loop, the offer, onboarding and every check after that is not. Proof re-checks the person in the room against the identity already on file, which is a comparison rather than a fresh verification, and cheap enough to run repeatedly. If someone does slip through, that same identity record is what catches them later, when they move into a sensitive role, convert from contractor to staff, or call the help desk for access.
Signals outside the document.
Silent Push recommends verifying applicants' physical locations during interviews, and the scheme's own hunt for proxies who can bypass location blocks explains why. Proof screens application data passively at intake against risk signals covering contact data and behavioral anomalies, scoring candidates in the ATS before anyone spends interview time.
A rehearsed proxy may still pass one live session. Layering does not catch every instance; it forces the arrangement to survive every stage instead of one, and each contact is another chance for the coordination to show.
Four changes you can make right now:
- Stop treating a clean document result as an identity conclusion. It confirms the document and the face, and says nothing about who does the work.
- Put a trained person at the stages with real exposure, before an offer on any role with system access, regulated data or financial authority.
- Verify at more than one stage, and make re-checking cheap enough that your team actually does it.
- Hold third-party workers to the same standard. An agency placement was verified in a process you did not run, against a standard you have not seen.
The people renting out their faces are told this is a "100% legitimate" subcontracting arrangement, in the operator's own words, and some believe it. Your candidate may be exactly who their ID says, and still not be the person who would do the job.
















































.jpg)





























































.jpg)






















