DEV Community

Cover image for I Put a Canary Token in My Resume and Caught a Company Stalking Me
v. Splicer
v. Splicer

Posted on • Originally published at Medium

I Put a Canary Token in My Resume and Caught a Company Stalking Me

The job market is broken. So I decided to break it back.

The interview that felt like an interrogation

You know that moment in a job interview when it stops feeling like a conversation and starts feeling like deposition?

That was Tuesday.

I was interviewing for a "Senior Operations" role at a mid-size tech company that I won't name, because their lawyers have more free time than I do. Let's call them PanoptiCorp.

The HM was nice enough. Then he said it:

"So, I saw you were really into the whole... rationalist scene in 2021? And you did that crypto project that didn't really go anywhere?"

My resume says none of that. My LinkedIn says none of that. My portfolio site says none of that.

My resume says: 5 years experience. Python, ops, systems design. Links to GitHub. Clean. Boring. Corporate-friendly.

It does NOT say anything about LessWrong. It does NOT mention a failed DAO I contributed to three wallets ago under a pseudonym I thought was dead.

So I smiled and said, "Where did you see that?"

He backpedaled so fast he left skid marks. "Oh, you know, just... did a little research. We like to be thorough."

Thorough.

Right.

Most candidates hear that and feel flattered. Wow, they really looked into me.

I felt my stomach drop. Because I knew what "thorough" meant. It meant someone had run me through a full OSINT sweep. Not just Googled me. Investigated me.

And I had prepared for exactly that.

Why I started booby-trapping my own resume

Let's be honest about what hiring is in 2026.

You are not being evaluated. You are being investigated.

Every company now has either an internal "Trust & Safety" guy who used to do military intel, or a $199/month subscription to some people-search aggregator that promises to show your "risk signals," your old addresses, your relatives, your leaked passwords, your deleted tweets from when you were 19.

You apply for a marketing job and they know your ex-girlfriend's dog's name.

The advice we're given is insane: "Clean up your digital footprint!" As if you can. As if you should have to scrub your entire personality to be worthy of health insurance.

I got tired of being paranoid. So I got proactive.

If you can't stop them from watching, you can at least make them trip a wire.

Enter: Canary Tokens.

If you don't know what they are, Canary Tokens are free, tiny digital tripwires made by Thinkst. You create a file, a link, a DNS token, an image — and when someone opens it, it pings you. IP address, user agent, timestamp. Proof someone touched something they shouldn't have.

Security teams use them to catch hackers. I started using them to catch employers.

How to put a honeypot in a PDF without being a psycho about it

This is the part where I have to be careful, because I don't want every recruiter on LinkedIn thinking I'm trying to hack the Pentagon.

I'm not. I'm just done pretending this is normal.

Here's what I did, and it's so simple it should be illegal that more people don't do it:

1. The Invisible Image.

I generated a Canary Token for an image. Thinkst gives you a URL that looks like any random tracking pixel.

I embedded it in my resume PDF. White 1x1 pixel in the footer. You will never see it. Your ATS will never see it. But if a human opens that PDF in a previewer that loads remote images — which Gmail, Apple Mail, and most corporate Outlook setups do — ping.

I get an email: "Your Canarytoken has been triggered."

It includes the IP, the time, and often the organization that owns the IP.

2. The Portfolio Link.

I didn't just link to voidrane.xyz/portfolio. I linked to voidrane.xyz/portfolio?src=resume_q3 and that page had a Canary link embedded as a "Download full case study (PDF)" button. Different token for every company I applied to.

So if PanoptiCorp's token fires, I know it's PanoptiCorp.

3. The Boring Doc.

My actual portfolio site is clean. But I have a /old directory that is not linked anywhere. If you find it, you found it via scraping or OSINT tools that brute-force subdirectories. I put another token in there.

If that one fires, I know they didn't just read my resume. They ran a recon tool on me.

Is this paranoid? Maybe. Is it effective?

Let me tell you what happened after Tuesday.

The stalking timeline

I got home after that weird interview and checked my Canary dashboard.

Trigger 1: Resume image token - Opened 3 times. First open from a San Francisco IP owned by PanoptiCorp. Expected. Second open from same IP, 4 hours later. They forwarded my resume around. Normal.

Third open: Different IP. Ashburn, Virginia. Owned by a data broker aggregator. The kind of IP that belongs to SocialLinks / Maltego / People Data Labs style infrastructure.

That was 9:42 PM on a Sunday. Two days before they even emailed me to schedule the interview.

So before a human ever decided I was worth talking to, my resume was already fed into an automated background check system.

Trigger 2: Portfolio link token for PanoptiCorp - Fired at 10:15 PM Sunday. Then again at 8:04 AM Monday from a different user agent, this time a headless browser. That's not a hiring manager clicking a link. That's a scraper.

Trigger 3: The /old directory token - Fired at 10:17 PM Sunday. Two minutes after the portfolio link. That means whatever tool they used automatically enumerated my site.

So by the time I got the cheerful "We'd love to chat!" email on Monday morning, they had already:

  1. Run my email through a people-search API
  2. Scraped my entire personal website structure
  3. Associated my current name with a pseudonym from 2021

That's not "doing a little research." That's a full-spectrum dossier.

And in the interview, they acted like they just happened to stumble on it.

Why this should enrage you (even if you have nothing to hide)

The standard cope is: "If you have nothing to hide, why do you care?"

Because privacy is not about hiding. It's about consent and context.

I consented to you evaluating my ability to do the job described in the JD. I did not consent to you feeding my personal domain into a crawler at 10pm on a Sunday to find a project I did under a different name when I was 24, to use as a weird power move in an interview.

And here's the sinister part: They will never tell you they did it. They will just make vague references to "culture fit" or "we found some inconsistencies." You will never know why you didn't get the job.

I only know because I set a trap.

Once you see it, you can't unsee it. The job application process is the only place in modern life where we are expected to hand over our home address, our work history, our references, our social security number — and then also smile while a stranger in HR runs a background investigation that would be illegal for a cop to do without a warrant.

We talk a lot about companies ghosting candidates. We don't talk enough about companies stalking candidates.

The power asymmetry is absurd. They have tools, budgets, and third-party vendors whose entire business model is violating your privacy at scale. You have... a cover letter.

So I decided to level it a little.

How to know you're being investigated (without becoming a full-time paranoid)

Look, I didn't invent this mindset. There's a whole discipline around it. In the intel world it's called Counter-OSINT — learning the tells that someone is building a file on you.

I got deep down that rabbit hole after the PanoptiCorp incident, and if this story made your neck hairs stand up, you should too. I wish I could put everything I learned in this post, but Medium would flag me for being too unhinged.

The best, latest, and most practical guide I've made that actually explains the technical breadcrumbs — the DNS tells, the aggregator IPs, the fake recruiter accounts — is called THE WATCHER'S WATCHER: Counter-OSINT How to Know You're Being Investigated. It's on Gumroad.

I'm not affiliated with them. I just think if you're going to play this game, you should know the rules.

Because once you know what to look for, the signs are everywhere:

  • The LinkedIn view from someone with no photo, 500+ connections, title "Talent Intelligence" or "People Researcher". That's not a recruiter. That's an OSINT contractor.
  • The weirdly specific question about something you deleted. If they mention a tweet you deleted in 2019, they didn't "find it." They bought it from a data broker who archived it.
  • The follow-up email that comes from a different domain. Your resume gets uploaded to Greenhouse, which shares data with 47 integrations. One of them pings you.
  • The sudden friend request from a stranger in your industry right after you apply. Classic pretexting account to view your private posts.

So what did I do with PanoptiCorp?

I withdrew.

I sent a polite email: "Thank you for your time, but I've decided to move forward with other opportunities."

Then I sent a different email from a burner, with a PDF report of every token trigger, every IP, every timestamp.

Their Head of People responded within 20 minutes asking to "hop on a call to clarify any misunderstandings."

I did not hop.

The point was never to get revenge. The point was to prove to myself that I wasn't crazy. That feeling you get when an interviewer knows too much? That's real. That's data. And now I have logs.

Since then, I've put unique tokens in every single resume I send out. Out of 31 applications in the last 2 months:

  • 19 triggered only the resume image token once or twice. Normal behavior.
  • 8 triggered the image AND the portfolio link. Thorough, but human.
  • 4 triggered all three, including the hidden directory enumeration, from data broker IPs, before any human contacted me. That's the stalking tier.

That's 13% of companies doing full passive recon before they even say hello.

Let that sink in.

Your resume is not a document. It's a beacon.

We are told to optimize our resumes for ATS keywords. We should be optimizing them for counter-surveillance.

I'm not telling you to become a privacy extremist and live in a cabin. I'm telling you to stop playing defense.

Put a Canary Token in your resume. It's free. It takes 30 seconds. Go to canarytokens.org, generate a DNS token or an image token, and embed it.

Not because you want to catch a company and write a snarky Medium post like me.

But because the first time you get that email that says "Your Canarytoken has been triggered" at 2 AM from an IP in Virginia that belongs to a company you've never heard of, that is charging another company to investigate you without your consent — you will finally understand the game you're playing.

And you will never send a naked resume again.


If you try this, tell me what you find. I have a feeling my inbox is about to get very interesting.

And if you work at PanoptiCorp and you're reading this: hi. I know you saw the /old folder. We both know what was in there wasn't work-appropriate. That's why I put it there.

Top comments (1)

Collapse
 
circuit profile image
Rahul S

The clever part is real, but the dashboard is quietly lying to you about attribution — a fired token conflates "a human at PanoptiCorp opened this" with "an automated pipeline prefetched it," and in corporate mail flow the second one fires constantly. Proofpoint/Mimecast/Defender for O365 detonate attachments and follow links on ingest, in a sandbox, before anyone sees the message — link detonation will literally click your "Download case study" button for you. Gmail and Apple Mail proxy-fetch remote images server-side too, so a chunk of those pixel "opens" are GoogleImageProxy, not a recruiter.

The tell isn't the timestamp, it's the user-agent and the reverse-DNS on the firing IP plus how fast it fired: sub-second-after-delivery from a scanner UA that loads no sub-resources is the security stack doing its job, not someone snooping. Where your setup actually holds up is the /old token — an unlinked subdir can't be reached by a scanner just following links in the email, so that one firing really does mean someone brute-forced paths or ran recon, which is a much cleaner signal than the resume pixel. If you keep doing this, log the UA and separate "pipeline touched it" from "human touched it" before you read intent into it.