00 · SUMMARY

Homework: Turing, Investigations Analyst

Where fraud and insider risk sit in an AI data vendor with a global contractor network, the typologies that follow, and a working case desk that takes a case from signal to written report.

Talent network
~4M
developers, vetted through an automated funnel
Security seats open
4
2 analysts, Director of Security Investigations, Director of InfoSec
Typologies in the desk
8
each with a benign twin that looks alike
Log sources joined
10
IdP, vetting, HRIS, payouts, EDR, Drive, Git, tasks, admin, DLP
THE READ

Turing sells confidential work done by remote people. Both halves carry the risk: who the person really is, and where the client's data goes.

THE ANGLE

On a human-data contract, fraud includes the data itself. Machine output passed off as human work is a case, and a quality problem for the lab that paid for it. Section ★.

THE PROOF

A case desk on synthetic data: alert queue, cross-source timeline, entity graph, hashed evidence with custody log, generated case report, detection benchmark. Try it ↗

01

Turing in context

Two businesses, one workforce. Each creates a different insider-risk profile.

LayerFactWhat it means for investigations
Frontier lab sideCoding and STEM datasets, RL environments and benchmarks for frontier labs. Largest data provider in software engineeringLab instructions, eval sets and prompts are the crown jewels. Exfiltration and leakage cases start here
Enterprise sideAgentic AI systems built into Fortune 500 workflows across financial services, life sciences, healthcare, retail, auto and CPGEngineers hold access to client production data. Access misuse and privilege cases start here
Workforce~4M developers in the talent cloud. Vetting runs as survey, quiz, coding challenge and AI matchingThe funnel is the attack surface for proxy candidates, synthetic identities and the DPRK IT-worker scheme
Scale and moneySeries E USD 111M, March 2025, led by Khazanah Nasional, USD 2.2B valuation, ~USD 300M run rate and profitableLarge payout volume to a global contractor base. Duplicate payees and payout diversion are live fraud paths
Security orgDirector of Security Investigations, Director of Information Security and two Investigations Analysts, all open September 2026A function being stood up. Playbooks, case templates and detection feedback loops get written by the first hires
02

The threat map

Four public events from the last 16 months set what labs now ask of a data vendor.

EventWhat happenedThe investigation lesson
Scale AI, June 202585+ Google Docs left public, exposing Meta, Google and xAI project material plus contractor records, some editablePublic-link creation on client docs is a detection, with an owner and a time-to-revoke
Scale v Mercor, Sept 2025Trade-secret suit alleging a departing lead moved 100+ customer strategy docs to a personal DriveResignation date plus bulk download plus personal destination is the classic departing-insider pattern. Watch the 30 days before notice
Mercor, March 2026Poisoned LiteLLM release on PyPI, live about 40 minutes, stole credentials. 40k+ contractors' IDs, interview videos and lab methodology taken. Class action filed 1 April 2026Credential theft turns an outsider into an insider. Investigations need a clean line to D&R for session and token review
DPRK IT workers, 2025 to 2026July 2026 State and FBI advisory with 10 allied nations. Laptop farms, KVM devices, deepfaked interviews, facilitators sentenced to 9 years and 200 months combinedIdentity, device and payout evidence have to be read together. Paying one is also a sanctions exposure, so Legal is in from the start

Typologies for an AI data vendor

Each row is planted in the case desk alongside a benign twin. The twin is the reason a single signal never closes a case.

TypologySignals, across sourcesBenign twinFirst move
Laptop farm / DPRK-style workerKVM USB id on EDR, remote-access tool, residential proxy ASN against declared country, payout account shared with other workers, face match drop since vettingDeveloper with a KVM for two machines and a VPN for travelPreserve, Legal first, D&R contains access
Proxy intervieweeVetting face and voice differ from delivery calls, typing cadence changes after onboarding, output quality dropsPoor webcam, new headsetCompare vetting media with recent calls
Account sharing or resaleOverlapping sessions from two countries, throughput doubles, new device fingerprintsTravel with a laptop and phone both signed inSession overlap by minute
Client data exfiltrationBulk download of client instructions, public link created, push to a personal Git remote, resignation within 30 daysLead exporting docs for an approved handoverRevoke link, legal hold, check the ticket
Timesheet inflationLogged hours far above active time, input at fixed intervals, no task output in the windowReading-heavy review tasksOutput per logged hour against peers
Machine output on human-data tasksPaste ratio near 1, detector score high, throughput spike, identical phrasing across tasksFast senior engineer drafting offlineSample with the client QA rubric
Duplicate payeeSeveral contractor accounts paying into one bank fingerprint, bank country unrelated to each profileFamily members sharing a joint account, disclosedHold payouts, verify identity
Staff privilege misuseAdmin grants self access to another client's workspace with no ticket, outside hoursOn-call fix with a late ticketMatch to change record, interview via HR
03

JD duties, my method

Each duty in the posting, the method I would bring, and where it shows on this page or in the desk.

JD dutyMethodShown inStatus
Investigate fraud and insider threat cases, reconstruct eventsOne timeline per subject across all sources, coloured by source, so gaps and overlaps are visible before any conclusion§04built
Triage alerts and reports, escalate appropriatelySeverity sets the path. Sanctions or active exfiltration go to D&R and Legal at once. Behavioural alerts are worked in score order with a stated SLA§05built
Analyse logs, transactions and behavioural signalsJoin on stable keys: device id, payout fingerprint, ASN, vetting id. Shared keys between people are the strongest lead§04built
Document objectively, keep chain of custodyEvidence hashed at collection with collector and UTC time. Report separates fact from inference and states confidence with a reason§05built
Partner with D&R, Legal and HRLegal before any contact with a subject or any OSINT. HR owns the interview. D&R owns containment. The analyst owns the file§05designed
Contribute to playbooks, feed new detectionsEvery closed case ends with a detection note: what would have caught it earlier, and what it would have cost in false positives§04built
Nice to have: SIEM, DLP, UEBA, SQL, PythonSQL and Python daily. SIEM query languages (SPL, KQL) are syntax over the same joinsresumepartial
04

The case desk

Built for this application on a synthetic workforce: 400 contractors, 60 staff, 30 days, about 30,750 events, 22 rules. At the default threshold it catches 11 of 11 planted subjects with no alerts on the 9 benign twins. No Turing systems or data. Open the desk ↗

QUEUE

Alerts with severity, source and SLA age. Dismissal needs a reason. Escalation names the partner team.

CASE

Unified timeline, the signals that fired and why, and a graph of shared devices, IPs and payout accounts.

QUERY

Filter the raw logs directly, with saved hunts for each typology.

EVIDENCE

Pinning a row hashes it (SHA-256) and appends a custody entry. Re-verify at any time.

REPORT

Generated write-up: scope, sources, timeline, findings with evidence ids, benign hypotheses tested, confidence, actions.

DETECTIONS

Rules run over labelled subjects with a threshold slider, so each change shows what it catches and what it costs.

05

Working a case

The same seven steps on every case. Cheap, reversible steps first.

1 Signal
alert or report
2 Preserve
snapshot, hash
3 Benign first
write it, test it
4 Corroborate
two independent sources
5 Escalate
Legal, D&R, HR
6 Write
facts, inference, confidence
7 Feed back
detection note
Evidence rulePractice
Hash at collectionSHA-256 of the canonical export, recorded with collector, source system and UTC time
Work on copiesOriginals stay in the evidence store. Analysis runs on a copy with its own hash
Log every transferEach hand-off to Legal, HR or an outside party is a custody entry
Legal hold earlyMailbox, Drive and Git retention frozen before the subject can know
Need to knowCase access limited to named people. No case detail in shared channels
Proportionate collectionOnly what the allegation needs, on a documented basis. Stricter where GDPR applies
06

First 90 days

DAYS 1 TO 30
  • Learn every source: fields, retention, join keys
  • Shadow senior investigators on live cases
  • Read closed cases, list what each one needed and lacked
DAYS 31 TO 60
  • Work cases end to end with review
  • Draft a case report template and evidence checklist
  • Saved queries for the top three typologies
DAYS 61 TO 90
  • Independent caseload
  • Two detection proposals from closed cases, each priced in false positives
  • Playbook drafts for workforce identity fraud and data exfiltration
07

Method & sources

Public job posting (2026), public reporting and court records. The case desk uses synthetic data only.

ClaimSource
Series E USD 111M led by Khazanah, USD 2.2B, ~USD 300M run rateSiliconANGLE, TechCrunch via Yahoo
~4M developers in the networkFortune
Automated vetting funnelTecla review
Director of Security Investigations openingjob listing
Scale AI public Google Docs, June 2025TechRepublic
Scale v Mercor trade-secret suitAxios
Mercor breach via LiteLLM, March 2026TechCrunch, BankInfoSecurity, Hausfeld
DPRK IT-worker advisory, laptop farms, sentencesSkadden, Holland & Knight, DOJ, The Hacker News

Independent work by Edward Tay for a job application. Not affiliated with Turing. The case desk is a prototype built for this application and is not Turing software.