Skip to content
Skip to main content
Accounts & Identity Offender Viewpoint

Dodgy Dave creates a fake recruitment account

Dave creates a recruitment profile for a company that does not exist and advertises well-paid remote work. Applicants are asked for identity documents, bank details and a £95 “security-vetting fee”. Dave thinks the respectable logo and a job title containing the word “consultant” will do most of the heavy lifting.

The working principle
Dave can invent the employer, but he still needs a real service account to publish adverts, receive applications and recover access. The account becomes a continuing record of the false presentation and the activity carried out through it.
False employer
Recruiter account
Job adverts
Applications
Recovery details
Access sessions
Dave’s device

This card follows Dave’s recruitment-fraud method and the account evidence it creates. The investigator walkthrough explains how a reported account should be preserved, developed and attributed.

Dave invents a respectable employer

The false recruitment operation
Displayed employerNorthgate Renewables Recruitment
Provider accountRC-41726
AdvertRemote compliance consultant · £48,000
Recovery emailhiring@northgate-careers.example
Recovery mobileEnding 3038

Dave supplies the name “Martin Cole”, uploads a copied company logo and writes a profile describing offices in three cities. The profile is what applicants see; the account is the provider’s continuing record. The service assigns stable account ID RC-41726, which Dave does not control and cannot make more distinguished by adding “Ltd” to the display name.

The registration details are claims. They are still useful claims because the recovery address, mobile number, creation time and later changes can be tested against other services and devices. Provider account records may contain substantially more than the public page.

The account begins collecting people

Dave publishes two adverts and directs applicants to an online form. The form requests a passport image, driving licence, selfie and bank details “to prepare payroll”. It also asks successful applicants to pay £95 for security vetting.

Selected recruiter-account activity
Account IDRC-41726
Created4 Sep · 08:18:11 UTC
Advert publishedJOB-9021 · 4 Sep · 09:06 UTC
Applications opened37
Application exports3 bulk downloads
Recurring deviceAPP-73
The service records activity against the account. The repeated device identifier helps connect that activity over time; personal attribution comes from the wider evidence.

Dave now has more than a false profile. He has created records of adverts, applicant messages, document access, bulk downloads and account sessions. The files supplied by victims have their own provenance and may later appear on a device or another service.

Dave delegates the dull bits

Dave gives an associate access to answer routine questions. Several sessions can therefore exist against one account, and not every message must have the same author. Dave considers this efficient management; the criminal enterprise has apparently acquired a help desk.

EstablishedRC-41726 published the adverts and accessed the applications.
Still openWhether Dave controlled the relevant sessions and downloaded the identity documents.

Who controlled the account is tested through session times, recurring application identifiers, security changes, possession of devices, local copies of applicant documents and communications allocating work. Shared access complicates attribution to a particular action, but it may also expose the structure of the offending and identify another participant.

Dave changes the name and closes the adverts

Complaints appear, so Dave renames the account “NGR Talent Solutions”, deletes the adverts and changes the recovery email. Public searches for Northgate Renewables become less useful. The provider’s stable account ID, earlier content IDs, change events and existing victim records remain connected to the same account.

Security and change events
12 Sep 16:40 · display_name_changed · RC-4172612 Sep 16:43 · recovery_email_changed · session RS-11812 Sep 16:49 · advert_deleted JOB-9021 · device APP-73
Stable account joins the old and new presentationChange events record Dave’s attempted tidy-upDevice provides continuity with earlier activity

The timing of the changes soon after complaints may be relevant conduct. More importantly, the same device identifier appearing during document downloads and deletion strongly links those events within the provider’s records.

What Dave changed - and what he did not

EmployerDave invented Northgate Renewables Recruitment.
AccountThe platform assigned RC-41726 and recorded adverts, applications, sessions and changes.
Victim materialIdentity documents and fee payments connect real applicants to the operation.
Account controlRecurring devices, local files and communications can connect Dave and his associate to particular activity.
Still to proveWho performed each action, how the documents were used, where the fees went and whether other recruitment accounts exist.

Dave’s employer was fictional. The service account, victim applications, access events and downloaded files were not. When independent provider records and device material agree, they create a strong route from the false employer towards the people operating it.

Operational takeaway
A false identity can still organise very real evidence. Stable account identifiers, recovery changes, session activity, victim documents and device artefacts can expose both the method and the people behind it.
Reference: AI-031Accounts & Identity