case file 11job stackingJuly 2025Silicon Valley, remote
the engineer with four jobs
A software engineer was hired by a string of venture-backed startups at the same time, without telling any of them. It only unravelled when one founder posted a warning and other founders recognised the name.
~$200k
base salary offered, per role
several
concurrent employers
one post
is how it came apart
what happened
An engineer interviewed extremely well and was hired by multiple venture-backed startups concurrently, without disclosing any of the other roles. Founders described the same pattern each time: he was impressive in interviews, then hard to reach once the work started, with a rotation of explanations for late or thin output.
Nothing here required deepfakes or a stolen identity. He was who he said he was. What was false was the exclusivity every one of those employers believed they had bought.
It ended when one founder posted publicly about firing him. The post travelled, other founders recognised the name, and the shape of it became visible only because they compared notes.
how it was caught
By founders talking to each other on social media. There was no system that caught this. There is no shared registry of who is employed where, and there should not be one.
Each individual hiring process worked correctly by its own standards. He passed real interviews on his own merits. The failure was that no single employer could see the pattern, because the pattern only exists across employers.
what it cost
Several companies paid senior engineering salaries, reported at up to about $200,000 in base compensation each, for a fraction of the attention they thought they were buying.
The deeper cost is to remote hiring generally. Every story like this becomes an argument inside some company for returning to the office, and the people who pay for that argument are the honest remote candidates.
the tells
signals that were visible, in hindsight, before anyone was hired.
- Consistently unavailable during the working hours agreed for their stated time zone.
- Strong interview performance followed by output that does not match it.
- A pattern of overlapping short tenures on the resume, with vague reasons for leaving.
- Reluctance to join unscheduled calls or turn a camera on during the working day.
what would have stopped it
the checks aperture runs on every session, mapped to this case. nothing here is hindsight-only. each one runs before a hiring team spends an hour on the candidate.
Repeat applicants under different framings, and the same person appearing across a pipeline more than once, both show up as repetition when the whole pool is being read rather than one application at a time.
This candidate genuinely interviewed well, which is exactly why polish is a poor predictor. λ-CORE scores specific evidence with a confidence interval on it, which narrows the gap between how someone interviews and how they work.
sources
- [1]Who is Soham Parekh, the serial moonlighter Silicon Valley startups can't stop hiring?
TechCrunch · press · July 3, 2025
- [2]Engineer caught secretly working for multiple Silicon Valley startups at once
Fortune · press · July 4, 2025
Founders describe a candidate who aced early interviews, then underdelivered once hired. Base salaries offered reached about $200,000.
- [3]CrowdStrike: 320+ Famous Chollima incidents in 12 months, up 220 percent
CrowdStrike, via CyberScoop · security research · August 4, 2025
Nearly one newly detected fraudulent hire per day in the twelve months to June 30, 2025.
more case files
north korean it scam · July 2025
the laptop farm in a suburban house
For three years, a woman in Litchfield Park, Arizona kept dozens of company laptops running in her home so North Korean IT workers could appear to be logging in from America. 309 U.S. companies paid them.
north korean it scam · July 2024
the security company that hired one
KnowBe4 trains other companies to spot social engineering. It interviewed a principal software engineer four times on video, ran a background check, checked references, hired him, and shipped him a Mac. Malware started loading 25 minutes after it arrived.
deepfake · March 2025
put your hand in front of your face
Hiring for one backend role out of about 500 applicants, security startup Vidoc got two AI-deepfaked candidates deep into its pipeline. One was exposed by a request that took three seconds: cover part of your face with your hand.