It has also become considerably riskier. Identity fraud in remote IT recruitment, fabricated references, and candidates using AI tools to pass technical interviews are no longer edge cases; they are a documented and growing problem across the industry. For a Polish company building a distributed team, the question is not whether to vet a foreign candidate remotely — it is how to do it properly.
Below is a short, practical guide covering the checks that genuinely matter confirming the person is real, verifying their work history, and validating their technical claims — before the contract is signed, not after.
Three trends have converged.
First, the volume of fully remote applications has grown sharply, meaning recruiters now meet far fewer candidates face-to-face than they did five years ago. Second, generative AI has made it trivial to fabricate polished CVs, LinkedIn histories, and even live interview answers. Third, there has been a wave of well-documented cases of fraudulent IT workers — including state-sponsored operators — using stolen or synthetic identities to obtain remote developer jobs at Western companies.
This last point is not speculation. The FBI issued public advisories in May 2024 and January 2025 warning that North Korean nationals were posing as legitimate remote IT workers to obtain employment at Western firms, using stolen identities, AI-generated personas, and US-based intermediaries to appear credible. In a November 2025 announcement, the US Department of Justice reported that facilitators had helped such workers fraudulently obtain remote roles at more than 136 US victim companies, generating over USD 2.2 million for the regime. The scale is such that Mandiant’s Chief Technology Officer told a 2025 security briefing that essentially every Fortune 500 company has received applications from North Korean IT workers.
None of this means foreign hiring should stop. Poland and the broader CEE region remain one of Europe’s strongest engineering talent pools, and most cross-border candidates are exactly who they say they are. It means the vetting process needs to catch up with the threat.
💡 The takeaway: The risk is not that foreign candidates are untrustworthy — they overwhelmingly are trustworthy. The risk is that remote-only hiring removes the informal checks that catch the small minority who are not. A structured process closes that gap.
Start with identity, not skills. A candidate can be technically brilliant and still not be who they claim to be.
A reference list supplied by the candidate is a starting point, not proof. Fraudulent candidates increasingly provide “references” that are friends — or fake companies with a working phone number staffed by an accomplice.
| Step | What to Verify | How |
|---|---|---|
| Identity | Real person, matches CV/LinkedIn | Live video call + ID check |
| Legal entity | Candidate/company is registered | National business registry lookup |
| Employment history | Roles and dates are accurate | Independent reference calls |
| Technical skill | Claimed seniority is genuine | Live coding session |
| Digital footprint | Consistent, long-standing presence | GitHub, LinkedIn, community activity |
| Payment/banking | Details match verified identity | Cross-check invoicing entity |
📍 Building a distributed team and want the vetting handled before candidates ever reach your inbox? At Optiveum, every candidate is screened, referenced, and technically assessed by our founding team before presentation — which is one reason our replacement rate sits under 1%. Book a call with Marek Wróbel to discuss your roles.
Yes. Requesting an ID document for identity-verification purposes, with the candidate’s consent and under GDPR-compliant data handling, is standard practice in EU recruitment and is not, in itself, discriminatory or unlawful.
No. LinkedIn profiles can be fabricated or purchased, and endorsements can be exchanged between contacts. LinkedIn should be one data point among several — never the sole verification method.
The core principles are the same, but a remote-only relationship removes the informal checks that happen naturally with local hires — mutual industry contacts, in-person meetings, easy access to physical documents. Remote vetting therefore needs to be more structured and more deliberate to reach the same level of confidence.
For companies without an in-house process for cross-border verification, working with an IT recruitment agency that already screens, references, and technically tests candidates before presenting them significantly reduces both the risk and the time spent on it.
Sources: FBI Public Service Announcements (May 2024, January 2025); U.S. Department of Justice enforcement announcements (June 2025, November 2025); Mandiant / Google Cloud threat reporting (2025). Figures cited reflect publicly reported enforcement data as of late 2025.
How to Build a Nearshore IT Team in Poland
Average Time-to-Hire for Senior Developers in Poland
Forcing senior IT talent into a Warsaw or Kraków office even one day a week…
As cyber threats grow more sophisticated and regulatory pressure mounts across every major economy, Cyber…
Discover the 2026 benchmarks for hiring AI and Python developers in Poland. Learn how to…
An executive playbook for CTOs and tech founders looking to scale their engineering teams seamlessly,…
Attracting a skilled Cyber Security Engineer starts long before the interview. It starts with the…
When we began expanding Optiveum's services into the Israeli market, the conversation with our clients…
This website uses cookies.