Learn why enterprise teams use identity verification against GenAI-powered fraud.
Published February 18, 2025
Last updated July 07, 2026

Workforce identity verification use cases: improve your organization's security posture across high-risk moments

Attackers are bypassing traditional controls by calling the help desk pretending to be an employee and by getting hired as one. Here are five moments in the employee life cycle where identity verification can stop them.
Joshua Rodriguez
Joshua Rodriguez
Jenna Kim
Jenna Kim
12 min
Illustration of various good users (clear with green checkmarks) and bad users (blurry with red x's)
Key takeaways
Over the past decade, security teams worldwide have seen a dramatic upswing in attacks targeting the workforce and help desk.
Workforce-related attacks are growing for two main reasons: more companies have adopted remote hiring and remote work policies while more threat actors use GenAI tools to power their attacks.
Security teams can limit these attacks by deploying digital identity verification at critical moments in the employee life cycle — for example, during candidate screening and interviewing, onboarding, device enrollment, account recovery, and other high-risk moments.

All over the world, cybersecurity attacks targeting the workforce and help desks are growing in frequency, and they’re costing companies more than before. A recent IBM report found that the global average cost of a data breach is $4.4 million. In the US, that cost is as high as $10.22 million per breach, considered an all-time high for any region. 

Attacks targeting the workforce are also becoming more sophisticated. Threat actors are no longer just targeting help desks or account recovery flows. Instead, they’re infiltrating organizations by impersonating legitimate employees and candidates, using AI-generated personas, fictitious identities, and social engineering to bypass traditional defenses.

That’s why more organizations are deploying workforce identity verification (IDV), or the process of ensuring employees and candidates are who they claim to be. By implementing identity proofing at critical junctures throughout the workforce life cycle such as during key hiring stages, onboarding, or account recovery, security teams can reduce the volume of threats levied against their organizations.

Below, we take a closer look at why workforce-related cybersecurity and employee impersonation incidents are increasing and why traditional solutions have become less effective at combating these threats. We’ll also define workforce IDV and explain when it’s helpful to deploy. Finally, we’ll discuss five common use cases for workforce IDV and how they work.

Why are threats targeting the workforce and help desk increasing?

Organizations are seeing an increase in threats targeting the workforce for two reasons. One is that businesses today rely on a more distributed workforce compared with even five years ago. Another is that threat actors now have access to powerful AI tools to carry out attacks. We explore both of these factors in greater detail below.

Factor #1: A more distributed workforce

A decade ago, the vast majority of a company’s employees worked on site in physical offices and logged into their accounts using company-issued devices on a company network. Businesses had a relatively simpler perimeter to monitor for both cybersecurity policy compliance as well as identity threats.

But over the years, workforces became increasingly distributed — thanks, in part, to widespread adoption of cloud-based technologies that enabled workers to access a company’s systems off site.

Remote work has made it possible for businesses to attract and retain employees from a wider talent pool. It can also lead to significant savings by reducing or even eliminating the need for office space. But by its very nature, it requires businesses to give up some of the security and control offered by a centralized workforce.

That’s because remote workers often access company systems on multiple devices (like personal smartphones) and across various networks (from home routers to mobile hotspots to coffee shop WiFi). This dramatically expands the attack surface area, offering attackers and threat actors multiple avenues to try and skirt your business’s defenses. It’s more difficult to defend multiple fronts than it is to defend just one.

When personal devices and networks are added to the mix, it’s much harder for an information security team to enforce cybersecurity policies, especially around things like password hygiene and credential sharing. For many businesses, that means an increased threat of account takeover (ATO) attacks.

Factor #2: Threat actors have more tools at their disposal

Just as the way we work has changed in recent years, so too has the way that threat actors carry out their attacks. That’s because today’s threat actors have access to powerful new tools that simply didn’t exist in the past — namely in the form of generative AI (GenAI).

Thanks to GenAI,  threat actors can easily generate a variety of assets to support their attacks. With large language models (LLMs), for example, threat actors can quickly draft emails, phone scripts, website copy, social media posts, and other text they need to engage in social engineering and phishing attempts. Likewise, they can use video and image generators to create realistic selfies, documents, and deepfakes to impersonate someone else or evade identity verification.

These same tools have also transformed the hiring process into a new attack surface. Today's recruiters are barraged with AI-generated resumes that are nearly impossible to tell apart from legitimate candidates. When fake candidates make it to interviews, the tactics escalate: they may use deepfakes to impersonate real people and proxy stand-ins to complete technical assessments on the fake candidate's behalf.

In the past, creating these assets took time, skill, and a high degree of technical know-how. Today, they can be created in seconds by nearly anyone, enabling attackers to carry out larger and more complex attacks faster than before. 

Why aren’t multi-factor authentication and employee training enough to stop workforce identity fraud?

Many businesses have spent years investing in two-factor and multi-factor authentication (MFA) to safeguard employees’ credentials from becoming compromised. While this is better than simply relying on passwords to secure employee accounts, there are limitations. 

Sending a one-time passcode to a verified device upon login only tells you that the person trying to log in has access to a trusted device. But it can’t stop lost or stolen devices falling into the hands of a threat actor. It also doesn’t fully protect against SIM swapping and other methods of cloning a trusted device. 

To combat social engineering and phishing/vishing attempts, many businesses have invested in employee training — for example, instructing workers not to open emails from unknown senders or click on suspicious links. While training is necessary, it can only go so far. Threat actors need only one employee to make a mistake to find a way in. 

What is workforce IDV?

Workforce identity verification (IDV) is the process of ensuring every member of your workforce is who they say they are. By requiring an employee to prove who they are — for example, by submitting a selfie or uploading a photo of their ID — identity verification can offer additional assurance during high-risk moments like enrolling a device or resetting passwords. 

To implement workforce IDV, most organizations use a combination of government ID verification, document verification, database verification, and selfie verification. Workforce IDV is especially important during two moments in the candidate and employee life cycles:

  • During hiring and onboarding: workforce IDV reduces the risk of hiring someone with falsified information, be it their identification documents or liveness/personhood, especially for a remote role. 

  • After onboarding: When leveraged elsewhere in the employee life cycle, workforce IDV helps you maintain organizational security by more securely controlling access to accounts and sensitive data vs. relying solely on MFA. 

Five use cases for IDV in the employee life cycle

While every company deploys workforce IDV differently, most focus on certain high-risk moments. Let’s take a look at what IDV looks like in each of those scenarios. 

1. IDV for candidates

Security teams are increasingly wary about whether you can trust that the people interviewing for their highest-access roles are who they claim to be. North Korean threat actors such as Famous Chollima have reportedly infiltrated companies by applying for remote IT worker positions, using tactics like synthetic identities, AI-generated profiles, and deepfakes to mask their identities. Some reportedly even performed their job responsibilities for months before they were detected. 

Just one fake candidate can introduce serious security risks, from unauthorized access to system disruption. Candidate verification brings identity proofing into existing hiring workflows  to help teams confirm that the person applying and interviewing is real, present, and who they claim to be. Rather than treating hiring as a one-time background check step, identity verification can be deployed across key moments in the hiring cycle:

  • At application or screening: Candidates complete identity verification using a government ID and selfie, helping establish a trusted identity early in the process.

  • Before key interviews: For final rounds or technical interviews, teams can reverify candidates to confirm the person interviewing is the same person who applied.

  • At the offer stage: A final identity check helps ensure the person being hired is the same person who progressed through the interviews.

2. IDV for employee onboarding

How sure are you that the person you interviewed and hired for a role is the same person who shows up on Day 1? With the rise of GenAI tools, it’s becoming more difficult to tell, especially for remote roles. 

The reasons that a threat actor would pretend to be someone they aren’t while applying for a job are numerous. For example, they might want to:

  • Gain access to trade secrets or valuable, sensitive information

  • Skirt international sanctions that prevent the hiring (as was recently seen when a US cybersecurity firm hired a North Korean threat actor)

  • Divert funds to the North Korean regime

Robust workforce IDV during hiring can help you reduce these risks — especially in remote hiring scenarios where you may never meet the applicant face to face. 

3. IDV for device enrollment

Any time an employee attempts to log into a work account (like email) from an unrecognized device, there’s a certain level of risk that the login attempt was actually completed by a threat actor trying to engage in an account takeover. 

That’s why most businesses trigger MFA when they detect an unrecognized device during log in. But MFA isn’t a silver bullet to protect against account takeovers, especially if a trusted device has been compromised.

One way to reduce this risk is to require employees to reverify themselves when they’re enrolling new devices. For example, you could require employees attempting to log into a work account on an unrecognized device to capture a selfie. This image would then be compared against an image on file — such as the portrait of a government ID or a previously-captured selfie. Even if a threat actor has compromised a trusted device, they will be denied access upon failing reverification.

4. IDV during account recovery

Account recovery is now one of most vulnerable security moments that attackers exploit. When an employee is locked out and can't complete MFA, they call the help desk. Your help desk agent must decide, in real-time, if this is the user they expect.

Requiring reverification at this moment means the agent no longer has to make that judgment call at all. By deploying automatic reverification during account recovery, you also empower legitimate employees to regain access to their account without tying up your help desk unnecessarily.

5. IDV during high-risk actions

Employees often need to perform actions that carry a high degree of risk for the business — for example, initiating a large transaction, accessing sensitive information, or downloading data. Requiring an employee to reverify themselves at these high-risk moments can help protect against inappropriate access or account takeover. 

Ideally, you would tailor the amount of verification an employee encounters in these moments to the degree of risk associated with each action. Employees seeking to engage in lower-risk actions would encounter fewer verification requests, while employees seeking to engage in higher-risk actions would encounter more. 

Resource
Workforce IDV checklist: 7 must-have features to secure your organization
Learn more

Get workforce IDV right with Persona

Workforce attacks have become more sophisticated and continue to evolve. And every organization has different risk thresholds, hiring processes, and workforce access requirements. The workforce security strategy that’s right for you will be the one that’s tailored to the realities of your business, your industry, and what your workforce looks like.

Our company, Persona, helps organizations verify employees at the moments attackers target most. At Persona, we understand that a one-size-fits-all approach to identity verification doesn’t work. That’s why we've integrated with ATS and IAM systems, such as Workday Recruiting, Ashby, Okta, Cisco Duo, and Microsoft Entra, to help businesses incorporate identity verification into their cybersecurity strategy.

By leveraging Persona, you gain access to:

  • An automated IDV solution that increases security and is compatible with your IT recovery workflows.

  • A range of verification methods — including government ID verification, selfie verification, and database verification — to gain higher confidence that your candidate or employee is who they say they are and that their identity has remained consistent from the start.

  • A wide breadth of risk signals, including active and passive signals like IP address, device telemetry data fingerprints, and geolocation inconsistency to detect sophisticated threat vectors.

  • Global coverage in over 200 countries and territories and 40 languages to help verify employees across your distributed workforce.

  • Granular access controls and role-based permissions so you can fine-tune who should have access to which systems and accounts.

Ready to learn more about how Persona can help you get workplace identity proofing right? Explore our enterprise workforce security guide or request a demo today to get started.

Guide
The business leader’s starter kit for candidate fraud prevention
Read more

The information provided is not intended to constitute legal advice; all information provided is for general informational purposes only and may not constitute the most up-to-date information. Any links to other third-party websites are only for the convenience of the reader.

FAQs

What's the difference between authentication and identity verification?

Toggle description visibility

Authentication focuses on whether the user can prove they have the required credentials or authentication factors. It confirms that the user knows the password or possesses a trusted device or security key.

Identity verification, on the other hand, confirms whether the user is who they claim to be. It ties or reestablishes a digital identity to a real-world person, typically using a government ID, selfie, or liveness detection.

Put another way, IDV is about anchoring trust to the individual user, not just their access keys. If a threat actor steals or compromises credentials and can pass authentication checks, identity verification provides an additional layer of assurance before granting or restoring access.

Why isn’t MFA enough to protect the account recovery moment?

Toggle description visibility

While MFA can tell you that someone has a trusted device at login, it can't verify identity when the user no longer has access to their authentication factors. For example, if an employee has lost their phone, needs to re-enroll an authenticator app, or is fully locked out, they simply can't complete MFA.

Many organizations rely on manual verification during account recovery, which makes it a prime target for attackers. Threat actors may use social engineering, deepfakes, and AI-generated voice clones to impersonate employees and persuade help desk staff to reset credentials or restore account access.

When should security teams trigger identity verification for employees?

Toggle description visibility

Security teams should trigger identity verification for employees during:

  • Onboarding and new device enrollment: Before granting system access, confirm the person being onboarded is the same person who was hired.

  • Account recovery and credential resets: Require reverification before any password reset or MFA re-enrollment to block social engineering attacks.

  • High-risk actions: Step up verification for large transactions, sensitive data access, or admin changes.

Security teams should deploy identity verification at high-risk moments and calibrate the level of assurance to the sensitivity of the action taken.

How should security teams navigate data retention, vendor risk, and compliance for workforce verification?

Toggle description visibility

When you apply identity proofing to the workforce, you may also introduce serious privacy considerations. To navigate them:

  • Follow Zero Trust principles and least-privilege access. Ensure that only those who need to review employee identity data can do so.

  • Restrict access to employee personal information. Most privacy frameworks require it, and it's a core security practice regardless.

  • Apply data minimization. Establish a clear retention policy, decide how long you'll keep data and why, and set your data residency requirements accordingly.

For a deeper look at privacy best practices and reducing data exposure, see our guide.

Joshua Rodriguez
Joshua Rodriguez
Joshua Rodriguez is a product marketing manager at Persona covering fraud and workforce identity. You'll find him around the Bay Area exploring parks and museums with his wife and two kids.
Jenna Kim
Jenna Kim
Jenna Kim is a product manager building Persona's third-party integrations marketplace. Outside of work, she can usually be found at the driving range, tennis courts, or park with a book in hand.
Continue reading