TL;DR: Automated and malicious job applications are increasingly overwhelming applicant tracking systems, with application volume nearly doubling since 2021 while recruiting teams have shrunk, according to Fingerprint. The governance gap is that ATS controls still evaluate isolated sessions, leaving automation, replayed browser signals, and repeated submissions to blend into normal hiring traffic.
NHIMG editorial — based on content published by Fingerprint: LLMjacking? no, automated job application fraud and ATS abuse
By the numbers:
- Since 2021, application volume has nearly doubled even as recruiting teams have gotten smaller.
- Gartner projects that by 2028, one in four job applications will be fake.
Questions worth separating out
Q: How should teams stop automated job applications without blocking real candidates?
A: Use layered controls that combine device intelligence, velocity checks, and selective friction.
Q: Why do applicant tracking systems struggle with bot-driven application fraud?
A: Most ATS controls assess each submission on its own, so they miss the pattern of repeated activity across sessions.
Q: What signals indicate that an application flow is being automated?
A: Look for sudden volume spikes, very fast form completion, highly similar resumes or answer patterns, and repeated browser or device characteristics.
Practitioner guidance
- Implement cross-session correlation at application intake Link submissions by visitor ID, browser traits, and network context so repeated automation is visible before recruiters review the queue.
- Step up friction only on suspicious application flows Apply additional checks when signals such as proxy use, browser tampering, or unnatural submission speed appear, while leaving low-risk candidates uninterrupted.
- Measure funnel distortion as a fraud indicator Track sudden spikes, identical application structures, and falling interview conversion together so automation is detected as a pipeline integrity issue, not a staffing issue.
What's in the full article
Fingerprint's full article covers the operational detail this post intentionally leaves for the source:
- How the vendor uses browser and device signals to link repeated submissions back to the same visitor.
- Examples of Smart Signals such as bot detection, proxy detection, and browser tampering in application flows.
- The practical flow for applying selective friction at the point of submission without disrupting genuine candidates.
- Why visitor ID helps distinguish repeated automation from separate human applicants.
👉 Read Fingerprint's analysis of automated job application fraud and ATS abuse →
Job application bots: what recruiting and fraud teams need to know?
Explore further
Application fraud is now an identity assurance problem, not just a recruiting nuisance. The moment an application pipeline accepts repeated submissions without durable session linkage, it stops being a simple intake workflow and becomes an adversarial trust boundary. That boundary matters to IAM and identity verification teams because the issue is not whether an applicant can complete a form, but whether the same automated source can repeatedly present as distinct people. Practitioners should treat this as a governed identity surface.
A question worth separating out:
Q: Who is accountable when automated applications distort hiring decisions?
A: Accountability usually spans recruiting, fraud, and security leadership because the problem crosses workflow, identity, and risk management. If a regulated process depends on application data, teams should document who owns detection, who owns escalation, and who approves control changes when fraud signals rise.
👉 Read our full editorial: Automated job application fraud is overwhelming ATS pipelines