As professional services are now being sold on online marketplaces, a new form of professional fraud is emerging. Licensed engineers are discovering that their names, license numbers, and professional identities are being used without their knowledge to produce and stamp design documents. While digital signatures and electronic authentication laws exist, inconsistent adoption and enforcement have left significant gaps in the system. This article explores a real-world case of engineering impersonation, examines why current safeguards are falling short, and argues that protecting the public and the industry will require more than technology alone.

Last year, someone at my firm brought a website to my attention. It was a gig-economy website specifically for professional services. Unlike platforms like TaskRabbit, which connects people with gig contractors willing to assemble furniture or mount a TV to a wall, this service aims to connect people and companies with professionals willing to do “white-collar” freelance work like programming, graphic design, digital marketing, or architecture and engineering services.

The Problem

The colleague who brought this to my attention had discovered that his license was being fraudulently used to sign and seal structural drawing and calculation packages. He found this out when he received a call from a contractor trying to get a question answered about project documents. For a project that my colleague knew nothing about.

This wasn’t a case where they had lifted my colleague’s signature and seal from a set of drawings. The scammer simply obtained his name and license number from the state board’s website, made their own digital stamp, and added a messy signature that had no resemblance to my colleague’s.

When the contractor attempted to get a hold of the individual he thought he hired, and could not reach anyone through the website he had originally used, he went to Google and found the name he was looking for on our company website and found the real engineer instead. After the initial confusion and concern, they reached out to the local authority having jurisdiction and the state board to report the issue.

The Verdict

After the board’s investigation, it was determined that the homeowner, the contractor, and my colleague were all victims of fraud (i.e. it was not determined that the contractor was complicit or had reason to know that he was procuring illegitimate engineering services). By the time the investigation started, the scammer no longer had an account or persona on the platform. My colleague eventually found out that this scammer had fraudulently used his license number for a couple of other projects before disappearing. It is possible that the actual number of projects completed with his license number could be much more than what was discovered.

Unfortunately, this is not a unique story, and it’s something that states are being watchful of and are putting out communication about. Code officials that I work with in Ohio reported similar stories. The Alabama State Board for Licensure for Professional Engineers and Land Surveyors has a Fraud Alert notification on their home page. The notification highlights the rise in online scams where individuals impersonate licensed engineers and provides tips for identifying warning signs of fraudulent practices. The Oregon State Board of Examiners for Engineering and Land Surveying’s latest newsletter includes a “Protect the Public & Be Aware” notification describing this issue, and providing recommendations for engineers.

The Solution

A technology solution already exists: Require the use of digital signatures by designers to confirm documents are valid and require the use of a trusted certificate authority to confirm the person signing and sealing the documents are who they say they are. In fact, almost all states already have laws like the following in the Ohio Administrative Code:

Rule 4733-23-01 Paragraph D

Plans, specifications, plats, reports and all other engineering of surveying work product bearing a computer generated seal and electronic signature and date shall have an electronic authentication process attached to or logically associated with the electronic document. The electronic signature must be unique to the person using it; capable of verification; under the sole control of the person using it; linked to a document in such a manner that the electronic signature is invalidated if any data in the document is changed.

Some states are more explicit regarding digital signature requirements, and some are more vague, but in general, states require that electronic or digital signatures meet some combination of the following requirements.

  • Unique to the individual.
  • Capable of verification.
  • Under the sole control of the person using it.
  • Is removed, invalidated, or modified if the documents are modified after the digital signature is applied.

The Problem With the Solution

Digital signature technology is not new, and the Ohio law referenced above requiring the use of digital signatures is nearly 20 years old. However, except for a few states, this technology is still not universally adopted in practice, nor is the law universally enforced by building departments.
Any individual can self-sign their own certificate to create a digital signature, but this alone wouldn’t prevent someone from using someone else’s identity to digitally sign a document. You still need to ensure that the person signing the document is actually who they say they are.

Read the full article at STRUCTURE magazine beginning on page 58.

AUTHORS

RELATED POSTS

Leave a Reply

Your email address will not be published. Required fields are marked *