sxsphinxstack

Skills / Advanced / Respond to resume identity theft

Advanced Resume skill

Respond to resume identity theft

Respond to resume identity theft and employment impersonation through victim protection, evidence preservation, account containment, corrections, and monitored recovery.

Protect the real person and anyone targeted by the impersonator before trying to restore reputation.

When to use

  • Use for fake resumes, recruiter profiles, portfolios, references, email domains, job applications, interview scams, credential misuse, or compromised career accounts.
  • Use normal profile correction when there is no unauthorized actor, account compromise, fraud, or continuing victim risk.

Preconditions

  • Confirm a safe contact route independent of possibly compromised email, phone, social, or device accounts.
  • Identify authorized security, platform, employer, credential issuer, domain, legal, privacy, law-enforcement, financial, and victim-support contacts.
  • Do not ask the victim to send additional identity documents through the same suspicious channel.

Procedure

  1. Establish victim protection and authentication through a trusted route, immediate account safety, credential and financial risk screen, and a support contact.
  2. Record the first report, known artifacts, affected identity elements, impersonator requests, targets, dates, and urgent risks.
  3. Conduct evidence preservation and containment by saving full messages, headers, files, URLs, profile IDs, domain records, logs, application records, payment routes, and screenshots before takedown where safe.
  4. Build an impersonation scope across email, phone, domains, social profiles, job boards, recruiter systems, portfolios, code repositories, credential verifiers, references, employers, and search results.
  5. Determine whether accounts, devices, mail forwarding, recovery methods, API tokens, password managers, identity documents, or payment information are compromised.
  6. Secure legitimate accounts, revoke sessions and tokens, remove malicious factors and forwarding, protect domains, and preserve necessary logs.
  7. Report impersonation through platform, domain, employer, issuer, and authorized fraud channels using minimal verified evidence.
  8. Warn known targets with factual indicators and a safe verification route without exposing the victim's sensitive documents broadly.
  9. When active harvesting continues and targets are unknown, require communications, privacy, legal, and victim approval for any broader warning, define notification thresholds, use anti-amplification wording, and distinguish employer breach duties from third-party impersonation.
  10. Correct false application and profile records, request preservation plus takedown, and distinguish impersonator activity from the victim's legitimate history.
  11. Perform correction and recovery for career profiles, credentials, references, search results, financial or identity records, and affected relationships.
  12. Monitor new accounts, domains, applications, searches, credential checks, account access, and victim impact for a defined period.
  13. Review root access path, data exposure, platform response, residual risk, and longer-term controls before closeout.

Failure plan

  • If the registered email or phone may be controlled by the attacker, do not use it for recovery or warning.
  • If the impersonator is actively collecting money, identity documents, or interview recordings, prioritize target warnings and platform containment.
  • If takedown could destroy essential evidence, coordinate preservation and capture before removal where safe.
  • If a false record affects employment, licensing, immigration, credit, or criminal matters, use qualified legal and official correction routes.
  • Never publicly accuse an unverified individual, publish the victim's identity documents, pay the impersonator, or impersonate them in return.

Worked example

An employer contacts a professional after receiving a resume with their name, photo, and certifications from a lookalike email domain. Fake interviews have collected identity documents, and the professional's career profile shows a new recovery method. The response authenticates the victim through a clean route, preserves the resume and headers, secures accounts and domain variants, scopes recruiter and issuer records, warns known candidates and employers, requests evidence-preserving takedowns, corrects false applications, and monitors new domains and credential checks.