The New Hire Wasn't in the Country: How a Laptop Farm Beat Every Security Check
A client's new senior engineer signed in from more than 50 networks before lunch on his first day. The laptop we shipped was in Texas. He wasn't in the country. Here is how remote-hire fraud gets past every geographic security check most companies run, and the checklist that stops it.

All my ex's live in Texas… or so we thought. A cautionary tale for anyone hiring remote.
Last Monday a client's new senior engineer started work. By 3 PM we had suspended every account he had, locked the laptop we'd shipped him, and handed the client a record of everything the account had touched. He had been inside their systems for three hours.
This is a cybersecurity story, not an HR story, and I want to walk through it carefully, because it's the cleanest example I've seen of an attack most small and mid-size companies don't know they're exposed to. The pattern is what matters.
The hire looked normal
Remote role. Solid resume. Interviewed well. References answered. Offer accepted, onboarding form filled out, laptop shipped to the address on the form, delivered by UPS three days before the start date. The identity provider created his accounts, HR sent the welcome pack, his manager put a welcome meeting on his calendar.
On the onboarding call, our technician had a feeling something was off. So we looked.
What the logs showed
We pulled every sign-in on the account since it was created, from the identity provider and from Microsoft.
On his first day the account connected from more than 50 distinct IP addresses. Not 50 over a week. Fifty between 7 AM and 2 PM. Comcast in Chicago, then AT&T, then T-Mobile, then Comcast in Rockford, then Verizon, then a cable ISP in Iowa, then one in Kentucky, then Arizona. A login that was issued to one carrier and completed from a different carrier three seconds later, four times in one morning. One Microsoft session that had been used from fifteen different networks.
That's a rotating residential proxy. It's a commercial service. You pay for it, and your traffic exits from real household internet connections all over the country so every "is this a normal US login" check passes.
Then the rest:
- His first-ever login, three days before his start date, came through a VPN exit in a data center in Los Angeles.
- His MFA phone only ever approved pushes from VPN exits. Never from a carrier, never from the same network as the laptop.
- The laptop was delivered to an address in Texas. Every sign-in said Chicago, Los Angeles or Phoenix.
- The phone number on his onboarding form was from a third state.
- None of his devices were ours. The company laptop had never been used, or if it had, it wasn't where it was supposed to be.
The people who do this have a name for the setup. A laptop farm is someone in the US who takes delivery of company laptops, plugs each one into a KVM-over-IP box, and lets a worker anywhere in the world drive it remotely. The laptop is physically in the country. The employee isn't. Add a VPN on the phone and a residential proxy on the worker's own PC, and you have a remote employee who passes every geographic check a normal security stack runs.
The FBI has published warnings about this pattern, and about who is behind a lot of it. I'm not going to attribute our case, because I can't prove it, and that's honestly the point. You won't be able to prove it either. What you can prove is that the person is not where they say they are, and that's enough to act.
What he actually did
The client's next question was the right one: what did he get?
We pulled the audit log for every action on the account. He read his own onboarding email. He joined Slack and Zoom. He opened Teams on the Mac and looked at the staff directory several times. He clicked through from the app dashboard to the payroll system's login page. That was it. Zero emails sent. Zero files opened, downloaded or shared. Zero Teams messages. Nothing changed, nothing forwarded, no rules, no consents, no admin rights.
Three hours, and the worst he got was a look at the org chart and the benefits PDF. Day one is the best possible day to catch this.
A peer MSP told me about the other version. Their client's remote hires worked for months. Nobody noticed. The story ended when the workers themselves contacted the client to say they were overseas, weren't being paid, and might not be able to leave. Months of access to email, files and customer data, and the paychecks going somewhere else entirely.
Why the security tools didn't catch it
This is the uncomfortable part. We built and run a tool called Warden for our clients. It monitors user activity across their Microsoft and Google environments, scores sign-ins and mailbox changes against the account-takeover patterns we see most, and locks accounts down on the high-confidence ones. It had every one of these sign-ins in front of it and said nothing. Microsoft's risk engine said nothing. The identity provider scored the first login "high risk" and then let it through, because the policy's only response to risk is to ask for MFA, and he passed MFA from his own phone.
Every check was geographic. Every address was in the US. Residential proxies are built to beat exactly that.
So we taught Warden the pattern itself: any sign-in through a VPN or proxy that isn't our own, any session that hops carriers, any login that finishes on a different provider seconds after it started, any MFA approval from a data center. Replayed against this case it flags the account in the first hour of his day, and it can now block it. It runs across every client we manage.
The remote hire security checklist
Here is what I now think onboarding a remote employee has to include. Some of this is policy, some is tooling, and the tooling part is what your IT provider should be doing for you.
Before you hire
- Every interview on camera, no virtual backgrounds. Ask for a slow head turn and a hand across the face once. Real people don't mind; live face-swap tools break.
- Call references at numbers you find yourself, not the ones on the resume.
- Run a background check that includes address history, and make sure the home address on the paperwork is on it.
- Check whether the phone number is a real carrier line or an internet number.
Before day one
- Ship the laptop only to the address on the I-9. No changes without a phone call back to the number on file.
- Put your management tools on it before it ships. Block remote-control software. Cap each employee at one enrolled computer.
- New hires get the basics on day one and nothing sensitive until they're verified.
Day one
- An onboarding video call, camera on both sides. ID next to the face. Laptop on camera, serial number read out loud and matched to what you shipped.
- Watch the first login land. Your IT team can see the address it came from. It should be the person's home internet, in their city, not a VPN or a proxy.
- Set up MFA on the call with the phone on camera. Set up direct deposit on a separate call with HR, and require a callback for any banking change in the first 90 days.
After that
- Monitor every account, not just new ones, for VPN and proxy connections and for logins that hop between carriers. Alert the same day. Lock first, ask questions second.
- Allow logins only from your own company network path. A commercial VPN should never get in.
- Tie sign-ins to the company laptop so a personal computer can't log in at all.
- Manager does a surprise camera check-in once a week for two months. "Share your screen, show me the room."
- For the roles that matter most, a hardware security key with a fingerprint reader, like a YubiKey Bio. Once it's enrolled, only that finger opens the account. It isn't flawless. It is a lot harder to farm.
If you see any of these, stop and verify today
- Camera always off, hard to reach, working odd hours for the time zone they gave you.
- Logins from several cities or carriers in one day.
- MFA approvals coming from a different network than the laptop.
- A request to change the shipping address or bank account right after hire.
- The company laptop never checks in, or checks in from a different city than you shipped it to.
The part I keep coming back to
None of this is expensive. Most of it is a decision. This one was caught because one technician trusted a bad feeling and looked. The peer's client didn't have anyone look for months.
If you have remote employees and you can't say right now what network they're connecting from, that's the gap. Run our free security scan to see what's visible from the outside, or talk to us and we'll show you exactly what we look at on day one.
Keith Parker is the founder of Methodology IT, a Los Angeles managed service provider that has looked after regulated businesses since 1997.
Ready to make IT work?
No pressure, no sales pitch. A senior tech will walk your environment with you and leave you with a report — whether you hire us or not.