Time Tracking with Screenshots Logo
  • How it works
  • Prices & FAQ
  • Blog
  • Sign Up
  • Log In
  • Contact Us
  • Try SCREENish for free
  1. SCREENish
  2. Blog
  3. Can Your Employer Tell If You Use a Mouse Jiggler? What Time-Tracking Software Actually Sees

Can Your Employer Tell If You Use a Mouse Jiggler? What Time-Tracking Software Actually Sees

If you are wondering whether your company can tell you use a mouse jiggler, the honest answer is: often yes, but rarely the way people imagine. Nobody gets an alert that says "mouse jiggler detected." What a manager actually sees is a pattern in a dashboard, and the uncomfortable part of that is not that jigglers get caught. It is that ordinary, honest work sometimes produces the same pattern.

We build monitoring software, so it would be commercially convenient for us to tell you that detection is total, inevitable, and infallible. It isn't, and pretending otherwise is how this whole category earned its reputation. This article is written for the person being monitored. If you are the employer trying to work out what your tooling can and cannot prove, read our companion piece on what employers can actually detect instead, which covers the same ground from the other side of the desk.

What your employer actually sees

Almost no time-tracking product reports raw mouse coordinates to a manager. What gets stored and surfaced is much coarser, and understanding the difference matters, because most people overestimate the resolution and underestimate the inference.

Here is the realistic picture of what typically reaches a manager's screen:

What people assume is visible What is usually visible
Every keystroke you type Counts of keyboard and mouse events per interval, not their content, in most time trackers
A live view of your screen Periodic screenshots, on an interval the employer configures
An explicit "jiggler" alert An activity percentage, an idle-time entry, or a review flag with a severity label
Proof of what you were doing A shape in the data that someone then interprets, correctly or not

Hubstaff, one of the largest trackers in this market, documents its own activity metric plainly: it divides active seconds by the length of a ten-minute segment, and its support documentation notes that "team members who spend more time in meetings, doing more research, or participating in video chats will tend to have lower scores" and that "people with 75% scores and those with 25% scores can often times both be working productively." That is a vendor telling you, in its own help center, that the number is not a measure of work. Managers still read it as one.

Flags versus inference: two different mechanisms

A software jiggler runs as a program on your machine and synthesizes input events. Operating systems have flagged this for decades. Windows documents an event-injected bit on low-level mouse events: Microsoft's reference for the MSLLHOOKSTRUCT structure states that "testing LLMHF_INJECTED (bit 0) will tell you whether the event was injected," and a second bit indicates injection from a lower-integrity process. macOS exposes a comparable distinction through CGEventSourceStateID, which separates events originating from the HID system from events synthesized in the session. Any monitoring agent that bothers to check these flags can see, unambiguously, that the input was synthesized rather than delivered by a physical device. What the flag does not tell anyone is who or what did the synthesizing, which turns out to matter enormously.

A hardware jiggler is a different story. A USB dongle that presents itself as a mouse produces events that arrive through the same path as a real mouse, and the operating system has no injection bit to set. Detection there is inference, not proof: unusually regular movement, movement with no accompanying keyboard activity across long stretches, cursor motion without the acceleration and hesitation of a human hand. Any vendor claiming deterministic detection of hardware jigglers is overselling. What they have is a probability, and probabilities produce false positives.

None of that adds up to a safe option, and it is worth being precise about why. A weaker evidentiary basis is not the same as not being caught: the pattern inference described above catches hardware jigglers routinely, and it does so without needing a flag. More to the point, the disciplinary cases discussed later in this article did not turn on hardware versus software at all. The regulatory language in the Wells Fargo disclosures describes simulated keyboard activity and names no device; the UK commentary turns on dishonesty toward the employer, which is indifferent to how the movement was produced. The consequence attaches to the act of faking activity, not to the mechanism. Picking the option that is harder to prove does not change the thing being judged.

There is also a case that is neither: some platforms and configurations simply cannot report whether input was injected. That is not an all-clear and it is not a conviction. It means the platform can't tell, and honest tooling should record it that way rather than defaulting to either extreme.

The part vendors bury: why honest people get flagged

Detection vendors mention false positives in one hedged paragraph and move on, because fear sells licenses. It deserves the center of the article, because if you are reading this after being asked an awkward question in a one-on-one, this is probably your situation.

Activity metrics measure input events. A great deal of valuable work produces almost none. The recurring cases:

  • Reading long documents. Forty pages of a contract, a spec, or a case file is an hour of high-value work and a handful of scroll events.
  • Thinking before typing. Debugging, architecture, drafting a difficult email to a client. The output is one paragraph; the work was forty minutes.
  • Long calls. On a customer call with a notepad in hand, or listening on a video call with your camera on, your input rate is near zero for the entire duration.
  • Remote desktop and VDI sessions. When you work through a remote session, thin client, or virtual desktop, input can arrive at the endpoint as synthesized events, because that is architecturally how the remote session delivers it. The injection flag your employer's agent is watching for can be set by the legitimate remote-desktop client itself. Whole teams in banking, healthcare, and government work exclusively this way.
  • Accessibility software. Dictation, switch access, eye tracking, and on-screen keyboards generate synthesized input by design. Flagging that is not a productivity finding, it is a disability-discrimination hazard.
  • Presentations and shared screens. Screen-sharing tools, remote support sessions, and automation you were told to use all inject input.

None of these are exotic. Together they are a large fraction of professional work, which is why an activity score that is treated as a verdict rather than a question generates a steady stream of wrong conclusions. The mechanics of how these signals are gathered are covered in more depth in our writeup on how fake keyboard and mouse activity is detected.

What a well-designed system should do with that

The design question is not "how do we catch more people." It is "what happens to a signal after it is generated." A system that automatically docks pay, marks the hours unpaid, or emails your manager an accusation is a system that has decided your reading hour was fraud without asking anyone.

In SCREENish, faked-activity signals are graded into severity bands and routed into an Activity Review queue for a human to look at. The system never automatically penalizes anyone on the strength of a flag, and remote-desktop context is assessed and recorded alongside the signal rather than silently deciding the outcome. That is a design stance, not a magic detector, and any vendor in this space can adopt it. If yours has not, that is worth raising.

If you have been flagged, here is how to raise it

This article is not going to tell you how to avoid detection, and you should be suspicious of the ones that do. The useful move when a flag lands on your name is to make the conversation about evidence rather than vibes.

  • Ask what the flag actually says. "Low activity" and "injected input detected" are different claims with different explanations. You cannot answer a claim you have not been shown.
  • Name your context immediately. If you were on a Citrix session, using dictation software, or in a two-hour call, say so at the start. These are the exact explanations that make an inference collapse.
  • Bring the corroborating record. Calendar entries, the call log, the pull request, the document version history, the ticket you closed. Output beats input rate in any reasonable discussion.
  • Ask for the monitoring policy in writing. In many jurisdictions your employer is already required to have given it to you.
  • If you are in the UK or EU, you can request your data. Article 15 of the GDPR gives you the right to obtain a copy of your personal data plus the purposes of processing, the recipients, the retention period, and, where automated decision-making is involved, "meaningful information about the logic involved, as well as the significance and the envisaged consequences." A monitoring score used to make decisions about you is personal data.

Is using a mouse jiggler illegal?

In the United States and the United Kingdom, buying, owning, or using a mouse jiggler is not itself a crime. They are sold openly on mainstream retail sites for under twenty dollars. No US or UK statute we are aware of names them specifically. Pages that imply criminal exposure are wrong, and pages that say "it's fine" are also wrong, because the actual risk is not criminal at all. It is employment risk, and it is real.

What follows is general information rather than legal advice. Outcomes in this area are heavily fact- and jurisdiction-specific, which is a point the employment lawyers cited below make themselves. If your job is on the line, get advice on your actual circumstances.

The United States: contract, not statute

The controlling case is not a prosecution, it is a firing. In 2024, Wells Fargo terminated more than a dozen employees in its wealth and investment management division. As CBS News reported, filings with the Financial Industry Regulatory Authority described them as discharged after review of allegations "involving simulation of keyboard activity creating impression of active work." One detail matters and is usually dropped: CBS noted that it was unclear whether those specific employees used mouse movers at all. The regulatory language describes simulated keyboard activity, not a device. Forbes coverage similarly noted the disclosures did not state the total number of staff disciplined. The "mouse jiggler" framing came from the press, not the filing.

The exposure in a US context typically runs along three lines. It can breach an acceptable-use or code-of-conduct policy, which in at-will employment is sufficient grounds on its own. If you are hourly and non-exempt, misrepresenting hours worked can be characterized as time or wage fraud, which is a materially more serious allegation than a policy breach. And in regulated industries, the reason for a termination may end up in a regulatory filing rather than staying inside the company, as it did here.

The United Kingdom: gross misconduct, but not automatically fair

UK commentary is more developed and more nuanced than the US coverage. Employment lawyers quoted by Raconteur take the view that deliberately faking activity amounts to dishonesty and can breach the implied duty of trust and confidence, potentially making it gross misconduct. But the same article records the crucial counterweight, from Trevor Bettany of Charles Russell Speechlys: "an employee using such a device to mislead the employer may nevertheless have been working very hard – perhaps thinking rather than typing, or working different or additional hours." Raconteur also notes that whether dismissal falls within the range of reasonable responses "has yet to be determined in an employment tribunal." There is no binding UK authority on this. Anyone who tells you the law is settled is guessing.

The law firm Collyer Bristow's analysis of mouse-jiggling dismissals adds the point that matters most if you are on the receiving end: an employer must investigate why the employee did it, and if the answer is that they were circumventing monitoring, then the lawfulness and proportionality of that monitoring under the UK GDPR and the Data Protection Act 2018 becomes central to whether the dismissal was fair. A disproportionate surveillance regime does not become defensible because someone reacted badly to it. The firm also stresses the ordinary procedural requirements: investigation, hearing, decision, appeal, and assessment on the specific facts.

Your employer's own obligations

Monitoring is not a free action. In New York, Civil Rights Law § 52-c requires employers who monitor telephone, email, or internet usage to give prior written notice on hiring, obtain the employee's written or electronic acknowledgment, and post the notice conspicuously, with civil penalties escalating from $500 to $3,000 for repeat violations. Connecticut's General Statutes § 31-48d requires prior written notice of the types of monitoring in use, with a narrow exception where the employer has reasonable grounds to suspect unlawful conduct, and the same penalty ladder.

There is also a wage-and-hour point that cuts in your favor and that monitoring vendors rarely volunteer. If you are non-exempt in the US, the time you actually worked is compensable, and an activity percentage is not the legal test for whether you worked. The Department of Labor's fact sheet on hours worked under the FLSA is built on the statutory definition of "employ" as "to suffer or permit to work," and it is explicit that work an employer knows about but did not request is still work time that must be paid for. An hour spent reading a contract is hours worked whether or not it moved the mouse. An employer who docks pay or refuses to approve hours purely because a score came in low is not making a productivity decision, it is making a wage-and-hour decision, and it should be prepared to defend it as one. That is a separate question from whether you are meeting expectations, which your employer is entitled to raise through ordinary performance management.

In the UK, the Information Commissioner's Office published final guidance on monitoring workers in October 2023 requiring employers to identify a lawful basis before monitoring, to be transparent about it, to keep it proportionate, and to recognize that home-based workers have heightened privacy expectations. Separately, and importantly if your employer told you that you agreed to this when you signed your contract, consent is rarely a workable lawful basis in an employment relationship at all. The European Data Protection Board's Guidelines 05/2020 on consent state that it is "problematic for employers to process personal data of current or future employees on the basis of consent as it is unlikely to be freely given," and use activating workplace monitoring systems as the worked example. If you want to know what a defensible setup looks like before you challenge yours, our GDPR-compliant employee monitoring checklist lays out what your employer should already have in place.

The uncomfortable summary

Software jigglers announce themselves to any agent that checks the operating system's injection flags, and that check is neither exotic nor new — though the flag proves only that input was synthesized, not that a person was faking, which is why the same flag lands on dictation users and Citrix sessions. Hardware jigglers are usually caught, if at all, by inference from patterns, which means sometimes they are not caught and sometimes the wrong person is. Either way, the thing landing on your manager's screen is a signal that needs interpreting, not a confession.

Which is why the argument worth having at your company is not about jigglers at all. It is about whether an activity number is being used as a proxy for work, and what happens to a person when the number is low. If you want to see how the flagging side is designed when it is designed to be reviewed rather than enforced, our mouse jiggler detection overview describes the mechanisms and, more importantly, the limits. A monitoring system that produces a flag and a human conversation is defensible. One that produces a flag and a punishment is going to be wrong about somebody, and eventually about you.

Track time the transparent way

SCREENish is free to try — no credit card required.

Start free

← All posts

  • How it works
  • Prices & FAQ
  • Blog
  • Sign Up
  • Log In
  • Contact Us
  • Try SCREENish for free

Solutions

  • Mouse Jiggler Detection Software
  • Overemployment Detection for Remote Teams
  • Remote Employee Identity Verification
  • Face Recognition Time Tracking
  • Compare Alternatives
  • Feature Guides
  • Blog Articles
  • Pricing & Plans

Random Blog Posts

  • Verification Is The Ultimate Form Of Trust
  • A Guide To Teamwork Between Outsourced Professionals
  • Key Principles Of Risk Management For Future And Ongoing Projects
  • Key Principles To Creating Project Strategies
  • Be the one in control of your tasks
  • Most commonly hired type of outsourced professionals
  • How to increase the productivity at the workplace
  • Key principles to effective management of outsourced projects
  • Few tips on how to decrease the costs of your office
  • Project and process time management
© SCREENish 2026 All right reserved. By SCREENish.com | Terms of Service | Privacy Policy & Cookies