Catch Unauthorized Employment‑Verification Pings (The Work Number and Peers) Using Safe Requests

Surprise employment and income checks can be early clues that someone is using your identity to open accounts, rent housing, or take out loans. Services such as The Work Number, Experian Verify, Equifax’s employer services, and similar payroll-link systems can be queried by lenders, landlords, background screeners, and even fraudsters who obtained partial personal data. This guide shows you how to recognize unauthorized verification activity and respond with safe, low‑risk requests that confirm what happened without giving away new details or escalating the situation.

Why Employment‑Verification Pings Matter

Employment and income verification (VOE/VOI) is a common step in underwriting credit, leases, and certain services. When your identity is being misused, a fraudster or an automated screening vendor may ping verification databases to confirm your job status or salary. These pings can precede a fraudulent application by hours or days—and they can happen even if your credit is frozen. Catching them early helps you lock down records, alert your employer’s payroll provider, and prevent larger losses.

How Verifications Typically Work

Understanding the workflow helps you spot anomalies without overreacting:

  • Requester: A lender, landlord, background screener, or benefits administrator initiates a VOE/VOI check.
  • Gateway: They query a service like The Work Number or another payroll-backed database.
  • Source: The gateway pulls data from your employer’s payroll provider if your employer is enrolled.
  • Disclosure & Consent: Legitimate checks should be tied to a signed authorization. However, consent can be forged or mishandled.
  • Outcome: The requester receives a “hit” (employment/income found) or “no record,” often with timestamps and limited details.

Early Clues You Were Pinged

You may not get a direct alert from the verification service. Instead, watch for these indirect signals:

  • Out‑of‑the‑blue “we couldn’t verify your income” emails or calls: Especially when you did not apply for anything.
  • Employer HR notifications: Some HR teams receive audit logs or alerts about verification attempts.
  • Stream of pre‑approval mailers: A sudden spike can indicate recent eligibility checks tied to your profile.
  • Credit report soft inquiries from background or screening firms: While VOE/VOI checks may not always hit your credit, related screening can show up.
  • Tenant screening or insurance quotes you didn’t request: Unexpected communications can signal an application elsewhere using your details.

Safety First: Use “Safe Requests” to Confirm Activity

When you suspect an unauthorized employment‑verification attempt, the goal is to confirm facts without revealing new sensitive information, and to leave a clean paper trail for HR, payroll, and any dispute process.

Principles of a Safe Request

  • Write, don’t call random numbers: Use official, publicly listed contact points on your employer’s HR or payroll portal, or the published security email of the verification service.
  • Identify yourself minimally: Name, last four of SSN only if your employer requires it via secure channel, employee ID (if standard), and your work email if safe.
  • Ask for logs, not data: Request a yes/no on whether a verification was attempted, the date/time (UTC), the requesting entity’s name, and the authorization document reference, if any.
  • Do not share full SSN, full pay stubs, or copies of IDs: Those increase exposure and are rarely needed just to find an access log.
  • Keep the scope tight: You are asking for access audit details, not your full payroll file.

Template: HR/Payroll Log Check

Use this structure, adapted to your employer’s process:

  • Subject: Employment/Income Verification Access Check for [Your Name]
  • Message: “I did not initiate any applications requiring verification. Please confirm whether any third‑party employment or income verification requests were made for my record in the last 60 days. If yes, please provide the date/time (UTC), the requester’s name/company, the verification channel (e.g., The Work Number), and whether a signed authorization was on file. Please do not send pay or SSN data. I’m concerned about potential identity misuse and will document this for security.”

Template: Verification Service Audit Request

If your employer uses a service like The Work Number, you can also send a safe, concise request to the service’s published consumer support channel:

  • Subject: Consumer Access/Audit Inquiry – Possible Unauthorized Verification
  • Message: “I’m requesting an audit check for potential unauthorized employment/income verification attempts tied to my record in the last 60 days. Please confirm whether any verifications were requested and, if so, the date/time (UTC), requester identity, and authorization indicator. I am not requesting payroll details. I will verify identity through your official secure process only.”

Always use contact information from the company’s public site, not links in emails or texts.

What The Work Number and Peer Services Can Show

Consumer support typically won’t release your payroll details over email, but they can often confirm:

  • Whether your employer participates: If your employer is not in the database, a “hit” elsewhere is suspicious.
  • Recent verification timestamps: Helps you align with suspicious emails or soft inquiries.
  • Requesting organization name or code: Useful for disputes and law enforcement reports.
  • Authorization status: Whether a consent document was recorded or presented.

These audit points let you escalate accurately without exposing more of your data.

Locking Down Exposure Without Over‑Sharing

After you confirm or strongly suspect an unauthorized ping, take controlled actions that reduce risk:

  • Ask HR to enable tighter verification controls: Some payroll systems allow “release by code,” manual review, or opt‑out for non‑essential verifiers.
  • Opt out of income sharing where available: If your payroll or benefits portal offers data‑sharing preferences, choose the most restrictive setting compatible with your job needs.
  • Review your employer’s authorized verifiers list: Make sure only legitimate partners (e.g., mortgage lender you’re actively using) are allowed during a defined window.
  • Request a flag on your profile: Ask HR/payroll to note “verify authorization signature on file” or “manual confirmation required” before releasing details.

Cross‑Check for Related Fraud

Employment verification rarely happens in isolation when fraud is underway. Run through these checks:

  • Credit files: Review your reports for new inquiries or accounts you don’t recognize. If you don’t already have monitoring, consider enrolling in a reputable credit and identity‑monitoring service to catch new activity early. A practical option that combines credit changes with identity‑related alerts is available here: SmartCredit for privacy, credit monitoring, and identity protection.
  • Freezes and fraud alerts: Maintain credit freezes at Equifax, Experian, and TransUnion. If you see attempts clustering in time, place a 1‑year fraud alert.
  • Tenant/background portals: Create accounts (if safe) on major screening portals tied to your email to prevent accounts being created behind your back, and check for past applications under your name.
  • Bank and card alerts: Enable transaction notifications and new‑payee alerts; fraudsters may test small transactions after verification attempts.

Red Flags vs. Routine Activity

Not every ping is malicious. Differentiate normal from risky:

  • Routine: You are actively applying for a mortgage, loan, or apartment and signed an authorization recently; you recognize the company name on the request.
  • Risky: No current applications; the requester name is unfamiliar; multiple attempts within days; demands for extra SSN/pay data via phone or email; pressure to act quickly.

What to Say (and Not Say) on the Phone

If someone calls claiming they need to “complete verification”:

  • Do say: “Please send your request on company letterhead from your official domain to my employer’s HR address listed on our website. I won’t provide SSN or pay details over the phone.”
  • Don’t say: Full SSN, detailed salary, past employers, or answers to “knowledge‑based” questions not already public. Decline to “confirm” data you didn’t supply.
  • Do take: Caller name, company, callback number, case/reference ID, and the reason for verification—all without confirming sensitive items.

Build a Minimal Evidence Pack

Documenting early creates leverage if you need to dispute or escalate:

  • Timeline: Log dates/times of suspicious emails, calls, and your safe requests.
  • Screenshots: Capture headers of emails and any portal messages (with sensitive data redacted).
  • Names and IDs: Requester names, ticket numbers, and any authorization references.
  • HR confirmations: Keep written responses from HR/payroll and verification services.

If You Confirm an Unauthorized Verification

Move from investigation to containment:

  • Increase controls with HR: Switch to manual release only, require signed authorization checks, and limit verifier scope to known entities.
  • Notify the requester’s compliance team: If provided, send a brief notice that authorization is disputed and any further checks require direct employer confirmation.
  • File reports as needed: Consider an FTC Identity Theft Report and, where money loss is likely, a police report to establish a record.
  • Watch for linked attempts: Monitor for new‑account inquiries, payday loans, or tenant applications that often follow VOE/VOI hits.

Preventive Steps That Lower Future Risk

Think of verification controls as part of your broader privacy hygiene:

  • Reduce data breadcrumbs: Remove home address, phone, and employer details from people‑search sites to make identity assembly harder.
  • Use segmented contact info: Create a dedicated email and virtual phone number for applications you initiate, so unknown verifier contacts are easier to flag.
  • Audit your resume and profiles: Limit public employer details and exact salary ranges on job sites and social profiles.
  • Secure your mailbox: Physical mail can carry verification letters and pre‑approvals that tip you off—ensure you can see them promptly with mail hold notifications or informed delivery services where available.

Frequently Asked Questions

Can I stop The Work Number from sharing my data?

Employers decide whether to participate and what data is available. You can ask HR to tighten release policies, require manual review, or opt out where policy allows. Even when full opt‑out isn’t available, manual confirmation and authorization checks can reduce risk.

Will credit freezes block employment verification?

Not necessarily. VOE/VOI tools may run outside of credit bureaus, though related screening can still show up on your credit file. Keep freezes in place and monitor both credit and identity signals.

What if the requester insists I must confirm SSN digits?

Decline and route them to your employer’s official HR verification process. A legitimate verifier can work through established channels without you handing over sensitive data directly.

How long should I keep my audit trail?

Keep your notes and confirmations for at least one year, or longer if you experience related fraud attempts. Patterns over time are valuable for disputes.

A Simple Action Plan

  1. Document the signal: Note the date/time and any requester details from calls, emails, or mailers.
  2. Send safe requests: Contact HR/payroll and, if applicable, the verification service to confirm whether a check occurred and by whom.
  3. Tighten release settings: Ask for manual review or restricted verifiers on your payroll profile.
  4. Monitor broader activity: Keep credit frozen and watch for new inquiries, accounts, or tenant screenings. Consider a reputable monitoring tool for faster alerts.
  5. Escalate if confirmed: Dispute unauthorized checks, notify compliance, and file identity theft reports as needed.

Conclusion

Employment‑verification pings are more than administrative noise—they can be the first visible step in a fraud chain. By using safe, written requests through official HR and verification‑service channels, you can confirm what happened without exposing fresh data. From there, enable stricter release controls, keep credit protections in place, and monitor for related activity. A calm, methodical approach preserves your privacy, gives you clear evidence if escalation is needed, and sharply reduces the chance that a silent verification turns into a costly identity event.

Good to Know

A legitimate verifier should already know data you won’t provide; if a caller or email demands SSN digits or pay details to “look you up,” stop and switch to a written, company-domain request to your employer’s HR or payroll portal.