Publication

Remote Worker Fraud: A Growing Risk for Employers and Government Contractors

June 9, 2026

Remote work has introduced a new category of risk: remote worker fraud. What initially surfaced as a productivity issue—employees not fully engaged or difficult to supervise—has evolved into something much more complex. Employers now confront a mix of non-performance, undisclosed outside employment, data exposure, and, in some cases, activity that raises serious cybersecurity and regulatory compliance concerns.

What Remote Worker Fraud Actually Looks Like in Practice

In many organizations, the first signs of trouble are relatively ordinary. An employee appears constantly “online” but struggles to produce meaningful work. Deliverables are delayed or uneven in quality. Colleagues notice that work product seems to vary in tone or technical approach, suggesting more than one author. Over time, these issues can point to a range of underlying conduct.

In some cases, employees are simply not performing at the level expected. In others, they are splitting their time across multiple full-time roles without disclosure—a practice that has become increasingly common in remote environments. There are also situations where employees quietly outsource their assignments to third parties, sometimes without regard to confidentiality or data security obligations.

Individually, these issues may be addressed through performance management or discipline. Taken together, however, they reveal a broader challenge in which employers often lack visibility into how work is being performed and even more concerning, by whom.

One example of remote worker fraud includes an increasing amount of deliberate identity-based misrepresentation tied to professional networking platforms such as LinkedIn, where applicants present fabricated or stolen digital personas to gain employment. This can include false credentials, misrepresented work history, and inaccurate location information, often supported by highly polished LinkedIn profiles built using synthetic identities, stolen photos, or referencing real accounts of other people. Because hiring teams often rely on LinkedIn as a proxy for credibility, these profiles can allow applicants to pass initial screening and background checks without independent verification. In practice, this means an individual may be granted employment—and system access—based on a made-up profile or one that does not correspond to the actual person performing the work. Once onboarded, the risk quickly escalates beyond a traditional employment issue. The individual may have access to internal systems, client data, proprietary code, financial platforms, or export-controlled information, creating exposure to data theft, fraud, and regulatory violations.

Even more serious, federal authorities have identified schemes in which foreign actors obtained remote positions at U.S. companies using stolen or fabricated identities. The U.S. Department of Justice has recently prosecuted multiple “laptop farm” cases, involving U.S.-based facilitators that enabled North Korean IT workers to fraudulently obtain remote employment with U.S. companies by hosting employer-issued laptops at U.S. residences and installing remote-access tools so the workers—who were actually overseas—appeared to be domestic employees. The North Korean workers used stolen or false identities to get hired, while the facilitators helped them pass hiring checks and maintain the deception. This scheme affected more than a hundred U.S. companies, which unknowingly paid salaries that were funneled to the North Korean regime and, in some instances, gave the workers access to sensitive systems and data, resulting in financial losses, cybersecurity risks, and the potential exposure of proprietary or export-controlled information.

While certainly not every remote hire presents this level of risk, the same structural features that make remote work efficient—distance, reliance on digital verification, and decentralized supervision—also make it easier for bad actors to operate undetected.

Why This Matters to Employers

Even for companies working outside highly regulated sectors, the downstream consequences can be large and operational, not just theoretical. Financially, employers face direct wage loss and productivity erosion where individuals are not performing the work as represented or are simultaneously working for multiple employers (“polyworking”), which can degrade output quality, extend delivery timelines, and create downstream impacts on project execution and customer commitments. Over time, these inefficiencies tend to manifest in missed deadlines, uneven workloads across teams, and diminished morale, particularly where legitimate employees are forced to compensate for underperformance.

More significantly, however, remote worker fraud creates a loss of control over system access and data governance. When an employer cannot reliably confirm the identity and location of the individual performing the work, it cannot ensure that access to internal systems is limited to authorized personnel. This risk is amplified where employees are using unmanaged or personal devices, connecting through VPNs or anonymized networks, working across multiple geographic locations, or involving undisclosed third parties (e.g., subcontractors or facilitators). In these scenarios, access credentials may effectively be shared or reassigned without the company’s knowledge, increasing the likelihood of unauthorized access to proprietary systems, client information, financial platforms, source code, or other sensitive data. Fraudulent hires are not limited to passive misconduct. They may actively exploit access to exfiltrate data, compromise systems, or introduce malware, exposing the organization to operational disruption, contractual liability, and potential regulatory or client-facing consequences.

Additional Complexity for Government Contractors

For government contractors, these same issues carry an added layer of risk because they intersect directly with regulatory obligations.

Where a contractor submits claims for payment that include (or imply) representations regarding the identity or qualifications of personnel, or compliance with contractual or regulatory requirements, a misrepresentation can give rise to liability under the False Claims Act, 31 U.S.C. § 3729(a)(1)(A)–(B), if the misrepresentation is made knowingly and is material to the government’s payment decision. See Universal Health Servs., Inc. v. United States ex rel. Escobar, 579 U.S. 176 (2016) (recognizing implied false certification theory where claims misrepresented compliance with requirements governing staff qualifications).

Similarly, undisclosed remote access to company systems by foreign nationals can implicate multiple federal control regimes, including Export Administration Regulations (EAR), International Traffic in Arms Regulations (ITAR), and, where applicable, Office of Foreign Assets Control (OFAC) sanctions frameworks. Where controlled technical data, software, or defense-related articles are accessible, such access may constitute a deemed export or reexport to the individual’s country of nationality, irrespective of the company’s intent. So, a failure to maintain proper identity verification, access controls, and geographic visibility over system users can give rise to strict liability exposure under these regimes, as well as derivative compliance risks (e.g., false certifications, breaches of contractual representations, and potential enforcement actions), even in the absence of deliberate misconduct.

Key Risk Indicators of Remote Worker Fraud

In practice, these issues typically surface through a combination of operational and access anomalies rather than an overt admission of fraud. Employers should scrutinize patterns such as repeated use of VPNs or IP addresses inconsistent with the purported work location, logins occurring outside expected time zones or in rapid succession from geographically disparate locations, and remote access to company-issued devices that are physically located at a different address than the employee’s stated residence.

Other red flags include requests to ship laptops to third-party or commercial addresses, use of multiple identities or discrepancies in employment documentation, refusal or inability to participate in live video verification, and installation or persistent use of unauthorized remote-access software on company devices. Standing alone, any one of these indicators may be explainable; however, in combination they present a materially heightened risk that the employee is not who or where they claim to be, and calls for immediate escalation, enhanced verification, and potential suspension of system access pending investigation.

How to Mitigate Risk

To mitigate against these risks, employers need to have layered, concrete controls across hiring, IT, and compliance. From a practical standpoint, employers need to ensure they can verify who is accessing their systems, where that access is occurring, and what data is being accessed, particularly for roles involving sensitive or technical information. This means implementing basic but disciplined controls such as verifying identity through government identification and live confirmation of the employee’s physical work location, and re-checking that information if anomalies arise.

Employers should also limit access to sensitive or export-controlled data based on role, monitor logins for access from unexpected countries or anonymized networks (such as VPNs), and flag activity inconsistent with the employee’s stated location. When multiple red flags appear, such as identity discrepancies combined with overseas logins, companies should have a clear, rapid escalation process in place so HR, IT, and legal can immediately suspend system access and investigate before restoring it.

This topic will be explored further in our June 30, 2026, Ice Miller/In-House Connect CLE program addressing emerging risks at the intersection of remote work, cybersecurity, and employer compliance.

If you have questions, please contact Jennifer Jackman or another member of the Ice Miller Workplace Solutions Group.

This publication is intended for general information purposes only and does not and is not intended to constitute legal advice. The reader should consult with legal counsel to determine how laws or decisions discussed herein apply to the reader's specific circumstances.

Related People

Related Categories

<p>Sign up now to receive periodic updates from Ice Miller&rsquo;s legal professionals.</p>

Sign up now to receive periodic updates from Ice Miller’s legal professionals.

Subscribe

Firm Highlights