Insider Threats & Organizational Risk

When an Iranian past disappears from a CV: a risk pattern Israeli companies should know

When an Iranian past disappears from a CV: a risk pattern Israeli companies should know

During background checks we carried out for an Israeli company of strategic importance, we encountered in more than one case a pattern that forced us to stop and take the check deeper.

On the face of it, the candidates looked excellent.

They lived in Western countries, had gained experience at well-known international companies and were applying for senior positions. A review of their social media turned up no extremist, anti-Israeli or suspicious activity. A search of open sources and additional databases also found no clear indication of hostile activity.

On the surface, a completely clean profile.

But when we reconstructed their professional timeline in depth, one detail appeared that changed the risk picture: their past included a significant period of employment at an Iranian company identified with the Islamic Revolutionary Guard Corps (IRGC) and subject to sanctions.

After that period, the candidates left Iran, moved to Western countries and worked for several years at legitimate local companies. Only after that geographic and professional distance from Iran had been created did they apply to the Israeli company.

Why the timeline is what matters

A standard background check could end here with the conclusion that there are no negative findings.

That is exactly the problem.

When examining the risk of activity on behalf of a foreign state, one must not look only for "negative information". One must also look for patterns.

The question is not only what appears online about the candidate today. The entire life path has to be examined: where they worked, for whom, in what roles, when they left, where they moved, which professional stops appeared along the way, and when they began to take an interest in Israeli companies or in positions that grant access to sensitive assets.

In the cases we examined, the years of work at Western companies after leaving Iran created, on the face of it, a new and clean professional profile.

This can be seen as an entirely natural career progression. And indeed, that has to be one of the hypotheses examined.

But from the perspective of counterintelligence and insider threat risk management, there is another hypothesis that must not be ignored: those intermediate stops may serve as a layer of separation between a sensitive past and the target organization.

This is the fundamental difference between a "negative information" check and a risk check.

Not everyone who left Iran is a risk

This needs to be said unambiguously.

Iranian origin, past Iranian citizenship, emigration to the West or previous work in Iran are not in themselves an indication of hostile activity.

Millions of Iranians live outside the country, and many of them oppose the Iranian regime.

Origin should therefore not be grounds for disqualifying a candidate.

The significant finding is different: a substantive professional connection to an entity owned by, controlled by or significantly affiliated with the IRGC, especially when it involves a prolonged period of employment or a role that may have required a high level of trust.

Even such a finding does not prove that the person is an Iranian agent.

But it certainly changes the level of risk and justifies an entirely different kind of check.

A "clean profile" is not necessarily an answer

One of the important insights from these cases is that the absence of negative findings online is not necessarily a sufficient indication of the absence of risk.

In the cases we examined, we found no suspicious statements on social media. We found no support for the Iranian regime. No clear unusual activity was found, and no public information appeared linking the candidates to intelligence activity.

Precisely for that reason, the most important finding was easy to miss.

It was not in a Facebook post or an old tweet. It was hidden inside the employment history.

And that is a point Israeli companies operating around the world need to internalize.

Why would an Israeli company be a target?

Certain Israeli companies have intelligence and strategic value that goes far beyond their business activity.

Companies in infrastructure, energy, transportation, technology, cyber, communications, defense, finance, logistics and industry hold information, systems, relationships and access that may be of interest to foreign intelligence actors.

Placing a person in a suitable role may, theoretically, allow access over time to commercial and technological information, to infrastructure and systems, to customers and suppliers, to internal processes, to executives and to people in sensitive positions.

And the goal does not have to be immediate.

A person can be integrated into an organization for years without carrying out a single unusual action. Their value may lie in the very access they accumulate and in the option of using it in the future.

So the question "did we find something they did?" is not always the right question.

Sometimes the question should be: "what is the risk arising from who they were connected to, from the path they took, and from the access they are now asking to receive?"

The broader pattern is a known one

The use of intermediate layers to obscure connections is not a new theory.

In recent years, U.S. authorities have documented time and again the use by IRGC-linked actors of front companies, companies in third countries, intermediaries and commercial identities designed to hide the real Iranian connection. The U.S. Department of Justice has described, for example, the use of companies and intermediaries outside Iran to disguise the role of the IRGC and the origin of certain activities.

In another case, published by the U.S. Department of Justice, a person charged with acting on behalf of the Iranian government obtained a job with a contractor of the U.S. Federal Aviation Administration. According to the indictment, the position gave him access to sensitive information and he passed documents to Iranian actors.

In March 2026, a person who admitted to acting for the IRGC was convicted in the United States. In the course of the proceedings it emerged that he had also been sent to the United States to look for potential recruitment candidates who could remain in the country.

These cases do not prove that any particular candidate for an Israeli company is an agent. They do show that running people, using civilian cover and creating distance between the IRGC and the target of the activity are scenarios organizations need to take into account.

What Israeli companies need to check

When recruiting employees around the world, and especially for senior or sensitive positions, a sanctions check alone is not enough.

The candidate's full professional timeline has to be reconstructed, and the employers themselves have to be checked as well.

Who owns each company they worked for? Who controlled it during the relevant period? Do the company, its parent companies, related companies, shareholders or executives appear on sanctions lists? Is there an affiliation with the IRGC, with the Iranian security establishment or with other government bodies? Are there gaps in the CV? Are there periods that were left out? Does the movement between countries and companies form a natural sequence, or a pattern that calls for further inquiry?

And above all, it is not enough to check the person.

The organizations that shaped their career have to be checked as well.

We are publishing this for one reason

The identifying details in the cases on which this article is based were deliberately changed or omitted to protect the client and the candidates.

The purpose is not to determine that the people who were checked were Iranian agents. We have no evidence that would allow us to determine that.

The purpose is to share a risk pattern that, in our view, Israeli companies employing people around the world must know.

If you are a global Israeli organization, especially one that holds infrastructure, technology, sensitive information or assets of strategic significance, it is worth examining not only the candidates you are recruiting today.

It may be worth looking back as well.

Examining employees who have already been recruited to sensitive positions, re-checking their employment history and asking a question that was not always asked at the time of hiring:

Is there, anywhere along the way, a significant affiliation with an entity controlled by the IRGC or with a sanctioned Iranian entity, even when everything that came after it looks Western, legitimate and completely clean?

Sometimes the most important finding in a background check is not what the candidate did.

It is where they worked, the people they worked for, and the path they took from there to you.

Get these breakdowns in your inbox, plus the six steps for closing the offboarding window as a one-page brief.Get the one-pager

Stay sharp

Get our insights in your inbox.

New cases, red flags and reliability lessons - a short email when something worth reading goes up. No spam, unsubscribe anytime.