In June 2026, a 43-year-old part-time tutor from Liverpool was sentenced to three years in prison after investigators found more than £2.4 million spread across his bank and trading accounts. He had no elaborate technology and no insider access. What he had was a service: he completed coursework and sat online assessments on behalf of more than 100 students across UK universities. One customer paid him £14,000 for a single qualification. Prosecutors described it as the most lucrative scheme of its kind uncovered in the country.
What makes the case significant is not the size of the fraud. It is what the size of the fraud proves. A single individual, working from a laptop, accumulated millions because the demand was steady, the price was known, and nothing in the delivery of online training was capable of noticing that the person doing the work was not the person enrolled.
This Is a Market, Not an Anomaly
It would be comfortable to read the Liverpool case as an outlier — one unusually organised individual who got greedy and got caught. The evidence points the other way.
In June 2026, the Florida Attorney General announced the arrest of a woman accused of running a large-scale proxy-testing operation, impersonating multiple candidates to sit teacher certification assessments. Separately, industry researchers who have gone looking for these services report finding certification proxy rings openly advertising completion of cloud, security, and project management credentials for around $200 each — on pay-after-pass terms.
Pay-after-pass is the detail that should worry every training organization. A refund guarantee is not something a nervous amateur offers. It is something a supplier offers when they have run the process enough times to price the risk. That is not cheating. That is a service business with a conversion rate.
Why Online Delivery Is the Target
Proxy completion concentrates where delivery is remote and identity is assumed. The reason is structural rather than moral.
In most online training, identity is established once — at enrollment, often with nothing more than an email address and a password — and then never checked again. Every module completion, every progress marker, and every final assessment after that point is attributed to whoever holds the login. The platform is not lying when it records a completion. It genuinely does not know, and was never built to know, who was at the keyboard.
That is why a proxy service scales so cleanly. The supplier does not need to defeat a control. There is no control to defeat. They log in as the customer, do the work, and the record is generated exactly as designed.
The Certificate Looks Identical Either Way
The uncomfortable part for compliance teams is that fraudulent completions are visually indistinguishable from legitimate ones. Same certificate template, same completion timestamp, same audit trail entry, same line in the training matrix.
When the fraud eventually surfaces — through a conviction, a regulator's inspection, or an incident investigation — the organization holding those records has no way to sort the valid from the invalid retrospectively. The question an auditor asks is not "do you have a certificate?" It is "how do you know this person earned it?" A completion log answers the first question and is silent on the second.
That silence is what turns one supplier's arrest into hundreds of unusable records.
Detection After the Fact Is the Wrong Control
The instinctive response to proxy completion is surveillance: proctor the assessment, monitor the session, flag the anomalies. Proctoring has real value at the assessment stage, and organizations that use it are better off than those that do not.
But proctoring is a detection control applied at a single moment. It watches the final assessment and not the weeks of coursework preceding it, and in most implementations it cannot establish that the person being watched is the same person who enrolled. A proxy who completes the course and also sits the proctored assessment passes both checks, because both checks confirm that *someone* was present — not *who*.
Detection also creates a second problem. Flagging and failing learners after the fact pushes the cost onto the training organization: appeals, re-sits, disputed results, and a compliance record that is now contested rather than clean.
Identity Continuity Is What Actually Breaks the Model
The control that undermines proxy completion is continuous learner verification tied back to a verified enrollment identity.
It works because it attacks the supplier's economics rather than their behaviour. If the learner is verified against a government ID at enrollment, and then re-verified as the same human at each subsequent training event and at the final assessment, the proxy cannot deliver the product. They cannot sell a completion they are unable to produce, and they cannot offer pay-after-pass terms on a process they will fail. The $200 credential stops being a viable listing.
This is the approach Asgard Authenticate is built around: verify the learner at enrollment, confirm the same learner is present throughout the course and at the assessment that follows it, and keep the whole sequence bound to one identity. Because verification carries across courses, the learner does not repeat an ID check for every refresher — and the organization gets a record where every step is attributable to a named, verified person.
Keeping Learners Compliant Rather Than Failing Them
There is a practical reason organizations resist adding identity controls: they expect a wave of flagged sessions, failed learners, and administrative cleanup.
That expectation comes from the proctoring model, where the system's job is to catch and penalise. Asgard's model is different by design. When something drifts — the learner steps away, someone else appears, the session conditions change — the learner is guided back into compliance during the session rather than failed after it. Most issues in legitimate training are not fraud; they are ordinary human interruptions, and treating them as fraud generates work for everyone.
The result is that genuine learners finish with a clean, defensible record, and the proxy supplier finds there is nothing left to sell.
The Path Forward
A three-year sentence and £2.4 million in seized accounts make headlines, but the enforcement is not the lesson. The lesson is that proxy completion had a price list, a guarantee, and more than a hundred customers — because online training, as most organizations deliver it, cannot tell who is doing the work. Until identity is verified at enrollment and carried through every course and assessment that follows, the certificate is a document about an account, not a person. Regulators, auditors, and courts have started asking for the difference.
Authoritative Sources & Further Reading
Writing on training integrity, learner verification and compliance record-keeping for Asgard Authenticate.
Ready to Issue Credentials You Can Defend?
Join organizations worldwide that trust Asgard for online training credential integrity. Start your free trial today—no credit card required.
Start Free Trial