--- name: respond-to-resume-identity-theft category: resume description: Respond to resume identity theft and employment impersonation through victim protection, evidence preservation, account containment, corrections, and monitored recovery. Use when someone uses another person's career identity, credentials, profile, or application materials. --- # respond-to-resume-identity-theft Protect the real person and anyone targeted by the impersonator before trying to restore reputation. ## When to use - Use for fake resumes, recruiter profiles, portfolios, references, email domains, job applications, interview scams, credential misuse, or compromised career accounts. - Use normal profile correction when there is no unauthorized actor, account compromise, fraud, or continuing victim risk. ## Preconditions - Confirm a safe contact route independent of possibly compromised email, phone, social, or device accounts. - Identify authorized security, platform, employer, credential issuer, domain, legal, privacy, law-enforcement, financial, and victim-support contacts. - Do not ask the victim to send additional identity documents through the same suspicious channel. ## Procedure 1. Establish **victim protection and authentication** through a trusted route, immediate account safety, credential and financial risk screen, and a support contact. 2. Record the first report, known artifacts, affected identity elements, impersonator requests, targets, dates, and urgent risks. 3. Conduct **evidence preservation and containment** by saving full messages, headers, files, URLs, profile IDs, domain records, logs, application records, payment routes, and screenshots before takedown where safe. 4. Build an **impersonation scope** across email, phone, domains, social profiles, job boards, recruiter systems, portfolios, code repositories, credential verifiers, references, employers, and search results. 5. Determine whether accounts, devices, mail forwarding, recovery methods, API tokens, password managers, identity documents, or payment information are compromised. 6. Secure legitimate accounts, revoke sessions and tokens, remove malicious factors and forwarding, protect domains, and preserve necessary logs. 7. Report impersonation through platform, domain, employer, issuer, and authorized fraud channels using minimal verified evidence. 8. Warn known targets with factual indicators and a safe verification route without exposing the victim's sensitive documents broadly. 9. When active harvesting continues and targets are unknown, require communications, privacy, legal, and victim approval for any broader warning, define notification thresholds, use anti-amplification wording, and distinguish employer breach duties from third-party impersonation. 10. Correct false application and profile records, request preservation plus takedown, and distinguish impersonator activity from the victim's legitimate history. 11. Perform **correction and recovery** for career profiles, credentials, references, search results, financial or identity records, and affected relationships. 12. Monitor new accounts, domains, applications, searches, credential checks, account access, and victim impact for a defined period. 13. Review root access path, data exposure, platform response, residual risk, and longer-term controls before closeout. ## Failure plan - If the registered email or phone may be controlled by the attacker, do not use it for recovery or warning. - If the impersonator is actively collecting money, identity documents, or interview recordings, prioritize target warnings and platform containment. - If takedown could destroy essential evidence, coordinate preservation and capture before removal where safe. - If a false record affects employment, licensing, immigration, credit, or criminal matters, use qualified legal and official correction routes. - Never publicly accuse an unverified individual, publish the victim's identity documents, pay the impersonator, or impersonate them in return. ## Worked example An employer contacts a professional after receiving a resume with their name, photo, and certifications from a lookalike email domain. Fake interviews have collected identity documents, and the professional's career profile shows a new recovery method. The response authenticates the victim through a clean route, preserves the resume and headers, secures accounts and domain variants, scopes recruiter and issuer records, warns known candidates and employers, requests evidence-preserving takedowns, corrects false applications, and monitors new domains and credential checks. ## Done - An impersonation exposure timeline records victim protection and authentication, identity elements, accounts, domains, targets, fraud actions, evidence custody, and scope - A containment and notification log proves evidence preservation and containment, session and factor revocation, platform and issuer reports, target warnings, takedowns, and record corrections - An identity recovery and monitoring report verifies correction and recovery, legitimate profiles, credentials, search results, financial or official referrals, recurrence checks, residual exposure, and owner