Coalition · Call for partners

A coordinated defense against a coordinated threat.

We are convening (and committing to draft) a cross-industry schema for hiring-risk signal sharing. We want partners to help us govern it.

The case for shared signals

The second target is paying for the first to learn.

The same threat actors target many victims. Public prosecution exhibits show foreign IT-worker operatives applying to dozens of companies with the same identity package; the laptop-farm IP ranges identified in 2025 federal raids served operatives placed at multiple Fortune 500 firms simultaneously. Today, when one organization detects and rejects a fraudulent applicant, that signal does not reach the next organization the same applicant approaches.

This is the same coordination problem that threat-intelligence sharing solved for malware fifteen years ago. It has the same solution shape, and Census Networks is committing to draft it, convene the partners, and contribute to it.

What we are proposing

A hiring-risk extension to STIX 2.1 / TAXII 2.1.

The extension reuses existing patterns where the analogy holds and adds new object types where it does not. The first-pass indicator types we are proposing:

v0 · STIX 2.1 extension 6 indicator types
01
ip-indicator

Laptop-farm and high-risk IP indicators

IP and CIDR ranges, ASN observations, residential-proxy exit-node fingerprints, with provenance and decay metadata.

02
synthetic-identity

Synthetic-identity tokens

Privacy-preserving hashes of identity tuples observed in confirmed fraud, designed so two members can independently observe a hash collision without either disclosing the underlying identity.

03
deepfake-artifact

Deepfake artifact signatures

Model-detected anomaly fingerprints associated with specific face-swap toolchains, as opposed to raw biometric data.

04
resume-fabrication

Resume-fabrication patterns

Institutions and employer entities observed in confirmed fraudulent claims, with confidence and decay metadata, gated on a quorum of independent member observations.

05
behavioral-drift

Behavioral drift fingerprints

Irreversible aggregate features describing the shape of behavioral mismatches observed in confirmed fraud, with differential-privacy noise added at aggregation.

06
ttp-narrative

TTPs and procedures

Known facilitator playbooks, interview-rehearsal artifacts, intermediary-network topologies, in shared narrative form.

Privacy-preserving by construction

The schema must not enable cross-member tracking of innocent candidates.

Three primitives anchor that commitment.

  1. 01

    Hashed identifiers with k-anonymity awareness.

    No raw PII crosses tenant boundaries.

  2. 02

    Bloom-filter membership tests.

    For the question "is this token in any other member's confirmed-fraud set?": answered probabilistically, with bounded false-positive rate, without revealing who reported it.

  3. 03

    Multi-party computation for aggregate statistics.

    Members compute joint distributions without any one member observing the others' raw counts.

Governance

A working schema needs a working governance model.

Membership

Open to security vendors, enterprise employers, and trusted industry associations who maintain a designated security and legal point of contact. New members admitted by quorum of existing members.

Curation

Indicators submitted with provenance, confidence, and decay; promotion from "reported" to "confirmed" requires a member's own confirmed-fraud incident or a quorum of members independently observing the same indicator.

Arbitration

A standing review panel, rotating across member companies, handles disputes about indicator validity and removal requests from candidates who believe they have been incorrectly listed.

Legal posture

Sharing under the cybersecurity-information-sharing safe-harbor analogues established by CISA 2015 and equivalent provisions, with member counsel jointly drafting the operational agreement.

Census Networks's commitments

Contingent on industry interest, Census commits to:

  1. 01

    Publish a draft schema (v0) by Q4 2026

    Open under a permissive license, with a reference data model and example STIX/TAXII bindings.

  2. 02

    Convene a working group

    Security vendors, enterprise employers, and policy bodies. Quarterly meetings, rotating chair, public minutes.

  3. 03

    Open-source the privacy-preserving primitives

    Hashed-identifier construction, Bloom-filter membership API, and MPC aggregation, all under an OSI-approved license.

  4. 04

    Contribute confirmed-fraud signals from the Census platform

    Subject to customer consent and the curation rules above.

Who we want at the table

How to engage.

Sign on to the working group, or read the full proposal in the whitepaper (Section 6).