Can a candidate use a VPN to fake their location during a remote job interview?
By Pinal Dave | Last updated: 2026-08-01
TL;DR: Yes, a VPN can mask a candidate's real IP address and make it appear they are interviewing from a different city or country than they actually are. This is a known tactic in organized remote-work fraud, including the schemes behind the DOJ and Microsoft laptop farm takedowns, and it requires location and device signals beyond a simple IP check to catch.
The short answer
Location spoofing during a remote interview is not a hypothetical risk, it is a documented part of real fraud schemes. A VPN or proxy service can make a candidate's connection appear to originate anywhere in the world, which matters when a role requires work from a specific country, timezone, or when location is used as one input into identity verification. Unlike an accidental false positive from an employee's legitimate VPN use, this is intentional location misrepresentation, and it is a different problem to solve.
The DOJ and Microsoft jointly dismantled 29 laptop farms, roughly 200 computers, that were specifically built to make remote workers appear to be located in the United States when they were not, using company-issued laptops physically located in one place while operated remotely by someone elsewhere. VPN-style location masking is a lighter-weight version of the same underlying deception.
The evidence
- DOJ and Microsoft: dismantled 29 laptop farms, about 200 computers, used to disguise the true location of remote IT workers during and after hiring.
- Gartner: by 2028, 1 in 4 candidate profiles worldwide will be fake or synthetic, a category that includes misrepresented location and identity.
- Greenhouse survey (4,136 respondents): 31% of hiring professionals interviewed a candidate they suspected of deepfake use, a fraud category often paired with location misrepresentation in the same scheme.
Accidental VPN flag vs. intentional location fraud
| Scenario | Candidate intent | What it usually looks like |
|---|---|---|
| Employee uses a corporate or personal VPN for privacy | Not fraud | Location shift with no other suspicious signals |
| Candidate uses a VPN to appear based in a required country | Intentional misrepresentation | Location claim inconsistent with other signals, like language patterns or time-of-day activity |
| Candidate is part of a laptop-farm style scheme | Intentional, often organized fraud | Consistent location masking across multiple sessions, sometimes paired with a rotating identity |
Step-by-step: catching location fraud during interviews
- Do not rely on IP address alone. A VPN defeats a simple IP-based location check by design.
- Cross-check location against other signals. Timezone-consistent activity patterns, language and accent cues, and device fingerprint history add context an IP address alone cannot provide.
- Verify identity independently of location. ID and selfie match confirm who the person is regardless of where they claim to be connecting from.
- Watch for repeated sessions with inconsistent location signals. A single ambiguous case may be innocent; a pattern across sessions is a stronger signal of organized fraud.
- Escalate confirmed cases appropriately. If a candidate is found to be part of an organized location-masking scheme, this may warrant more than a simple hiring rejection, given the scale of documented fraud in this category.
FAQ
Is using a VPN during a job interview automatically suspicious? No. Many people use VPNs routinely for privacy or security reasons unrelated to hiring fraud. It becomes a concern when combined with other inconsistent signals, not on its own.
How can a company detect a VPN is in use during an interview? Various technical signals can suggest VPN or proxy use, though sophisticated actors can mask this too, which is why relying on multiple signals together, not IP data alone, is more reliable.
Does this only matter for roles with location requirements? It matters most for roles with legal, tax, or security requirements tied to location, but any organized fraud scheme using location masking is a broader integrity concern regardless of the specific role.
Is this connected to the North Korean IT worker fraud cases specifically? Yes, location masking, including VPN use and physically relocated company laptops, was a documented technique in the schemes the DOJ and Microsoft dismantled.
What should a company do if it suspects location fraud after hiring? Document the specific signals, involve legal or security teams given the potential seriousness, and avoid acting on a single ambiguous signal alone.