Both Sides of HiringBoth Sides of Hiring · Report 1 · September 2026

Who's Really Applying?

The trust problem in hiring, from noise to state-sponsored fraud

  • 93% of candidates from job adverts don't fit the role they're applying for
  • 46% of US candidates flagged as a potential risk before anyone spoke to them
  • 67% of candidates from job boards and aggregators identified as a potential risk
  • 1.8× flag rate from job boards vs paid social

What we looked at

175,000 applications from job advert channels across 2026, checked against the role each candidate applied for. And 70,000+ US candidates who went through Archer Approves, our three-layer trust system, in a single month.

What we found

  • 93% of candidates arriving from job adverts don't fit the role they're applying for
  • Nearly half of US candidates were flagged as a potential risk before anyone spoke to them. One in seven was high risk
  • 67% of candidates from job boards and aggregators identified as a potential risk

Chapter 01

A call from the FBI

Late last year one of our customers, a FTSE 100 company, got a call from the FBI. Someone they'd hired was working for the North Korean government. The hire had applied through their career site and went through their normal interview process. Every stage passed. Nobody in that chain had a reason to think the person on the other end of the video call wasn't who they said they were.

That call is why we started looking at this properly.

Another customer told us something smaller and, in a way, worse. Their recruiting team runs more than ten screening calls a week with people who turn out not to be who they claim.

Neither company is careless. Both have structured processes, experienced teams and the usual tooling. What they don't have, and what almost nobody has, is a way of knowing who's on the other side of an application before they've spent time on it.

So the question this report tries to answer is a simple one. Who's really applying?

Chapter 02

Only 7% of applicants are a potential fit

A recruiter opens a role and gets 400 applications in a week. Most are AI-written, and many are for a job the candidate can't do or wouldn't take. They can't read them all, so they buy AI to filter them.

A candidate applies to 100 jobs and hears nothing. Not a rejection, nothing. So they apply to 100 more, and now there's a tool that will do it for them overnight with a resume rewritten for each posting. Why wouldn't they use it?

There are no villains here. Each side is doing the sensible thing inside a system that stopped working. Applying has always been free. What changed is that it takes no effort now either, and silence is the usual answer, so volume is the rational reply.

Across 2026 we checked 175,000 applications from job advert channels against the role each candidate applied for. Only around 7% pass an initial screen from Archer. The other 93% largely missed for basic things that would've been displayed in the job ad.

Why applications don't fit Archer application data, 175,000 applications from job advert channels, Jan-Sep 2026, global
  • Salary 28%
  • Location 23%
  • Skill mismatch 19%
  • Visa 15%
  • Experience 10%
  • Other 5%

Salary, location and the skill mismatch are 70% of the misses. That's the basics, and the ad had all three in it.

One line in that chart matters more than the others for the rest of this report. Location and visa together are 38% of mismatches. Nearly four in ten candidates fail on where they are or where they're allowed to work.

Chapter 03

Fraud is a spectrum

"Candidate fraud" covers a lot of ground, and most of it isn't fraud. It helps to lay the whole range out.

The candidate fraud spectrum
  1. AI-assisted applying
  2. Misrepresentation
  3. Identity fraud
  4. State-sponsored operations

Lower harm Higher harm

AI-assisted applying: Rewritten resumes, tailored cover letters, auto-apply tools. Legal, normal and here to stay. GoodTime's 2026 Hiring Insights Report surveyed more than 500 US talent leaders. For the first time, fake or AI-assisted candidates came out as their top anticipated challenge for the year, at 27%, one point ahead of finding qualified talent.

Misrepresentation: Experience stretched, a location fudged, a right-to-work answer that's hopeful rather than true.

Identity fraud: Someone else on the interview call. A borrowed or invented identity. GetReal Security surveyed 668 IT, security, risk and fraud leaders at organizations with 1,000+ employees. 41% said their organization had already hired and onboarded a fraudulent candidate. Staffing Industry Analysts found 54% of contingent workforce programs reported identity-related fraud this year, up from 37% reporting candidate validation and fraud challenges the year before.

State-sponsored operations: In February 2026 a federal court sentenced the operator of an identity-rental service to five years for placing North Korean IT workers at 40 US companies.

The bands differ in motive, in harm and in what you'd do about them. They share one thing. A resume looks identical at every point on that line, and so does an application form. Hiring has run on those documents for decades. They never captured a person, and once the volume went up, nobody could pretend they did.

Chapter 04

Some channels are riskier than others

We ran 70,000+ US candidates through the signals layer of Archer Approves. It runs at sign-up, before a candidate can be matched to any role, and it checks the things a resume can't tell you: whether the email is new or unverified, whether there's any online footprint, whether the connection is coming through a proxy, a VPN or a virtual machine, whether the phone number is VoIP, and whether the IP location matches the one the candidate gave. The signals technology is built with Tofu. Each candidate lands in one of three bands: low risk, medium risk or suspicious.

Nearly half were flagged as a potential risk. 46% landed in the medium or suspicious bands. One in seven, 14.5%, was suspicious.

70,000+ US candidates, by risk band Archer Approves signals layer
  • Low risk 54%
  • Medium 31.5%
  • Suspicious 14.5%

A potential risk means the signals didn't add up and the candidate has to verify their identity with a government ID before they can go live. It doesn't necessarily mean they're a fake candidate. Some of these people are exactly who they say they are, working from a coffee shop on a VPN with a new email address. The additional identity verification layer verifies this.

We were interested to find out if potential risk candidates are more likely to come from some channels than others.

Share of candidates flagged, by channel type Archer Approves signals layer, 70,000+ US candidates
  • Job boards and aggregators 67%
  • Direct, origin unknown 51%
  • Professional network 45%
  • Paid social 43%
  • Organic search 43%
  • Paid search 38%

Candidates arriving from job boards and aggregators were flagged as a potential risk at 67%, with a third of them suspicious. Candidates from paid social were flagged at 43%, and under 3% were suspicious. That's roughly a 1.8x gap and was consistent in every way we analyzed the data.

The AI apply tools

A small % of applications had a referrer showing they'd been submitted by an AI job-application agent, a tool that applies on the candidate's behalf. 100% of these applications were flagged as a potential risk, which is not surprising given the way our signal layer works.

It's a good example of a candidate AI tool fighting our trust layer. It's highly unlikely all of these candidates were a potential risk and shows why a multi-layer approach is critical to identify truly bad actors.

Chapter 05

What to do about it

By 2028, one in four candidate profiles worldwide will be fake.

Gartner, July 2025

Gartner projects that by 2028, one in four candidate profiles worldwide will be fake. The more useful number sits underneath it: in Gartner's 2Q25 survey of 3,000 candidates, 6% admitted to interview fraud outright, either posing as someone else or having someone else pose as them.

Five things a talent leader can do this quarter, none of which need our product.

  1. Check identity and location at sign-up, before an interview slot is booked: Most teams verify at background screening, which is after the decision has effectively been made.
  2. Publish an AI use policy and say that you check: Write down what's acceptable and what happens if someone's caught.
  3. Separate identity fraud from AI-assisted misrepresentation: One is "this isn't the person they claim to be." The other is "this is a real person whose claims were written by a tool." Different checks, different owners.
  4. Stop using the resume as a first filter, and change the questions instead: It's a self-authored document in an age of free authorship. Instead focus on targeted, relevant screening questions.
  5. Measure flag rate and verification drop-off by source, next to cost per hire: If you don't know which channels bring you candidates who fit and are real, you're buying risk blind.

Chapter 06

How Archer approaches it

Trust is a relationship problem, and you can't solve a relationship problem without building an actual relationship.

Archer is the agent for both sides of hiring. It ensures that candidates only have one profile, decides which roles they see, talks to them over months and verifies them before any employer does. That's what first-party data means in hiring, and it's the vantage point from which the trust problem is solvable.

Archer Approves is how we protect employers with our three-layer system:

  1. Layer 1

    Structure: A candidate has one profile with Archer, and Archer assesses them against it. They can't browse jobs and they can't submit 100 different resumes for 100 different roles. They see the roles Archer thinks fit, and nothing else.

  2. Layer 2

    Signals: At sign-up, Archer looks at online presence, location and behavior and puts each candidate into one of three risk bands. Medium and suspicious candidates can't go live until they've ID verified.

  3. Layer 3

    Verification: Government ID through Veriff, with a human review for the edge cases. Candidates who pass get the Archer Approves badge. If they tripped signals on the way in, the employer sees that too.

So far, Archer Approves has blocked 30,000+ candidates from being matched to our customers. Every live US remote candidate on Archer today is Archer Approved, which means they signed up, were checked, and verified if the checks required it. Speak to our team if you'd like to learn how Archer Approves can help your company here.

The manifesto we published this month asks for two things. Nobody should have to apply to 200 jobs to be seen once. And nobody should have to read 400 applications to find the one. Both problems come from the same place. Fixing them starts with an agent that knows who it's representing.

Only get qualified candidates applying to your roles