Jul 22

Deepfake Job Candidates and AI Interview Fraud: The People You’re Interviewing Aren’t Who They Seem

Ever gotten tired of scouring through resume after resume because nothing’s standing out? You just about had had enough. Then, one stopped you on your tracks and caught your eye.

This is it. This is the hire.

Resume? Perfect. Pre-interview questions were answered just as perfectly. One of the four candidates to go through the final interview.

The person sounded great over their short 3-5 minute video call. Contracts are agreed upon. Onboarding gets done. They’re in. Weeks after the hire, something feels off. This new hire you’ve been speaking to suddenly looks and sounds different in your next video meeting.

How to spot deepfake interviews or deepfake job candidates?

Experian’s 2026 Future of Fraud Forecast named deepfake job candidates one of the top five fraud threats of the year.

If 4 out of 10 candidates are likely gaming the recruitment process, how do you know the people you’re about to hire really are who they said they were?

How to spot a deepfake interview? (Why are there fake job applicants?)

Key Takeaway / Quick Answer

Watch for subtle signs such as lip-sync delays, unnatural facial movements, inconsistent lighting, or answers that sound overly polished yet fall apart under follow-up questions. Fake job applicants typically use deepfakes, proxy interviewers, or AI tools to secure jobs they aren’t qualified for, steal sensitive company data, bypass hiring requirements, or conceal their real identity. Because a single red flag isn’t proof of fraud, combine visual observations with identity verification, technical checks, and unscripted interview questions before making a hiring decision.

Deepfake Interviews and Fake Candidates: What Is a Deepfake Job Candidate?

A deepfake job candidate is a person who uses AI-manipulated video, cloned or synthetic audio, a stand-in/proxy interviewer, or a stolen/fabricated identity to get through your hiring process as someone they’re not.

Exaggerating one’s skills, apparently, is too old school. This also isn’t merely about identity theft. Here are the 3 main ways deepfake candidates manipulate fake AI interviews (after their AI-generated resumes get a pass):

Fake identity (Identity fraud)

Here, candidate fraud takes place when the applicant uses a stolen or fabricated identity; they impersonate someone else, and may use AI-generated video or voice, or generative AI tools, to change their appearance or the way they sound over the length of the video call.

Synthetic Identities are among the fraudulent methods as well. This is where identities are a blend of real and fake information or customer data. Though this is more prevalent in financial fraud.

Proxy interview

A more qualified person (a real human) completes the online interview on the applicant’s behalf. But once the job offer’s accepted, a different individual performs the work.

It can also happen in reverse. The applicant acts as the front person, while someone else does the work. They share the earnings. Or the first is actually with a hiring agency “helping” qualified persons get through interviews, and asks for a placement fee once candidates are accepted.

AI-assisted deception (job applicants using AI)

The applicant attends the interview themselves but uses AI tools, such as answer generators, voice enhancement, or deepfake technology, to appear more qualified, more knowledgeable than they really are.

By 2028, 1 in 4 job candidate profiles could be fake. Globally. By the end of 2026, about 30% of enterprises will find their identity verification tools unreliable against deepfakes.

— Gartner

Illustration: Derek runs his own Denver-based software company. He has 9 people on his team. Quite the significant increase when he only had 2 when he started. He hires a backend developer after three virtual interview rounds. No red flags.

Two weeks in, and the new developer is inconsistent with submissions and deadlines. After month two or three, IT flags a login from a different country (than what Derek was told during the interview/or was in the new hire’s resume).

operational excellence

Don’t Wait Around for an Attack. Hire a Cybersecurity Specialist Today.

Hire a Remote Staff specialist to support operations while you take care of your business vision.

Trusted by 3,000+ businesses to scale remotely since 2007.

Most hiring managers, recruiters and hiring specialists rely on instinct to catch whether an interviewee is telling the truth or is embellishing away, to give their resumes a more flattering, albeit unreal, upgrade. Instinct hasn’t always been a fool-proof approach to rule out who’s lying and who isn’t, but it’s worked so far for the most part.

That’s no longer true today. Especially when it comes to roles built around remote hiring and remote work.

Human reviewers / hiring specialists identify deepfake videos only 55% of the time. Half of the candidates screened online are put through because the interviewer couldn’t tell deepfake interviews apart from the real ones.

In a separate study, 82% of people mistook AI-generated images of deepfake job applicants for authentic ones. A staggering number, when hiring managers tend to note their first impressions of a candidate through a resume with a resume photo or a LinkedIn profile.

Recruiters themselves are reporting the same pattern:

  • 91% of US hiring managers say they’ve encountered or suspected candidates of using AI-generated interview answers (Greenhouse, 2026)

  • 59% suspect candidates of using AI to misrepresent themselves during the hiring process

  • One in three hiring managers says they’ve personally uncovered a fake identity or a proxy candidate during an interview

  • 62% believe job seekers are now better at using AI to game interviews than recruiters are at catching it

Tracking data backs this up, too. There’s been an increase in deepfake fraud attempts in hiring and people using AI in interviews; a 1,300% increase from 2023 to 2024. And 2026’s numbers aren’t looking so great either:

38.5% of nearly 19,400 interviews were flagged for AI-cheating behavior, a threefold increase in just 3 months.

— The Interview Guys

As always, large enterprises are the first, and quickest, to respond to the threat. 72% of recruiting leaders are required to conduct in-person interviews, particularly when it comes to roles that are high-access, high-trust (roles with access to sensitive systems and data; senior-level, executive).

Even bigger players are mandating the change now: Google, McKinsey, and Cisco. After years of remote interviewing and hiring.

But this isn’t the best recourse for small to medium-sized businesses. In fact, it’s far from recommended. Many US SMBs have hybrid teams. Many more have transitioned to putting together workforces that are fully remote, especially for work that’s done inside tools and platforms.

When your employees are overseas, in-person interviews and on-location background checks are beyond impractical; it’s just not possible.

How then do you address the threat of fake job candidates?

Free Consult. No Pressure.

Free Consult. No Pressure.

We’ll answer any question on how to hire world-class, high performing, vetted virtual staff to cut your labour costs by 60-70%.

By submitting this form, you agree to receive SMS or phone communications from Remote Staff, Inc. Message & data rates may apply. Reply STOP to opt out.

Two Different Attack Types in Candidate Fraud: How the Scam Works

Earlier, we showed you the 3 kinds of deception happening. Identify fraud. Proxy interviews. AI-assisted deception. This section explains how the fake video or identity is presented during the interview.

Presentation Attacks

The older, much more crude version. A candidate holds up a phone or tablet displaying a fake or AI-generated video (a.k.a. Manipulated video) in front of the webcam. They wear a mask or use a face-swap filter that replaces their face with someone else’s during the video call.

Common signs to watch for:

  • Lip movement that either doesn’t always match the audio or lags behind the same audio every now and then

  • Eye blinking that looks too rhythmic or happens only a handful of times during the duration of the call (in other cases, not at all)

  • “Visible seams” of either a thin line of light or a blur around the hairline and jawline

  • Lighting on the face that doesn’t match the lighting/brightness in the rest of the room/room background

The last two bullets need close scrutiny. They’re also common in perfectly legitimate video calls, especially when candidates use virtual backgrounds, poor lighting, or low-quality webcams.

What’s important to note is that you (or your recruiters and hiring managers) are the first layer of defense. These attacks can be detected by careful human eyes. A reason why this tactic’s becoming less common.

Video Injection Attacks

A live camera doesn’t play a part in this attack. No webcam or mobile device camera. This method’s done by using virtual camera software or a browser plugin, where malicious actors send a fake live video directly into the video call.

There’s technically no live video manipulation going on, and the platform receives what appears to be a normal live feed. So, standard checks like the ones mentioned in the bullets above are bypassed. The person’s blinking and speech patterns can be made to sound as close to human as possible. The background and lighting don’t raise alarm bells.

How do you test for this before each interview? See the table below.

Deepfake Interview Attacks: Presentation Attacks vs. Video Injection Comparison

Attack Type
Presentation Attack
Video Injection Attack
Method
Fake video/mask held up to a real camera
Synthetic video fed in through virtual camera software, bypassing the camera
Detectable by basic liveness checks (blink, turn head)?
Often, yes
No, these can be pre-built into the injected feed
Human reviewer can usually spot it?
Sometimes
Rarely
What actually catches it
Visual inspection, unscripted requests
Detection at the device/signal level, checking whether a virtual camera driver is running

Worth Noting: Identity verification providers such as Innovatrics, GBG, and Jumio identify video injection as one of the fastest-growing forms of interview fraud because it bypasses the camera itself, making it much harder for standard identity checks to detect.

What Started All This: How Did Deepfake and AI Candidate Fraud Become a Thing? (Real Cases)

What Started All This How Did Deepfake and AI Candidate Fraud Become a Thing

Deepfake interviews or deepfake job candidates have been documented even by the FBI and the Department of Justice. This isn’t some distant possibility that’s affecting only those in tech or cybersecurity. It’s happening to businesses of all kinds and in all industries.

Documented Case Studies on Fake AI Interviews:

North Korean IT worker schemes

US authorities have uncovered groups of North Korean operatives posing as legitimate job candidates to secure remote tech jobs. Using stolen identities, fabricated profiles, and deepfake technology, they were able to get hired by US companies, with the salaries ultimately flowing back to the regime.

The interview wasn’t the end of it.

The FBI has also warned employers about “laptop mules.” These are US-based individuals who receive company laptops on behalf of overseas workers. They keep those devices within the borders of the US (“laptop farms”), making it appear as though employees are logging in locally when they’re actually working from abroad.

KnowBe4

Here’s a company built around security awareness training. The irony is that they unknowingly hired a North Korean IT worker using a stolen American identity. And in doing so, caught a deepfake user. Almost as soon as the company laptop arrived, the new hire began installing malware on the device.

Amazon

Stephen Schmidt, Chief Security Officer of Amazon, disclosed that Amazon has blocked more than 1,800 suspected North Korean operatives from being hired.

The number continued to climb throughout 2025, jumping 27% quarter over quarter.

Beyond nation-state actors

Government-backed groups aren’t the only ones behind these schemes.

One infamous incident involved a “candidate” who, in reality, was a professional actor running an elaborate scheme involving fake business deals and fake medical diagnoses.

They would’ve gotten away with it had not a separate company reported being deceived by the same actor.

Voice Fraud: AI Voice Cloning or Vishing

The FBI also reported a growing number of employment scams involving AI. Voice spoofing and possible voice cloning during interviews. Two more types of AI interview scams to add to the list.

Victims lost $13 million (on average) to these scams in 2025.

These scams don’t just target large corporations. Small businesses are often the easier option because there are simply fewer checks in place to verify who a candidate really is before they’re hired.

Get Matched AI Recruiter Banner

How to Expose Fake Job Candidates (How to Stop Deepfake Hiring Fraud)

You don’t need identity verification software or a security team to catch most of this. The same signals that flag fraud for Amazon and the FBI are visible in a standard interview process, if you know where to look.

Quick Reference Table: How to Spot Fake Candidates Through Practical Verification Steps

Red Flag
What It Usually Signals
Phone number formatted as “+1” rather than standard US format
Common pattern flagged by Amazon’s internal fraud screening
Email or LinkedIn account under ~2 months old
Matches Socure’s data on confirmed fraudulent applicants (avg. 48 days vs. 1,646 for genuine candidates)
Shipping address changes near delivery date
Documented “laptop farm” mechanism named directly in FBI guidance
Refusal or resistance to small camera adjustments
Consistent with injected or pre-recorded video feeds
Degree or school claims and work histories that don’t match program offerings or calendars
Documented pattern in Amazon’s applicant review process
Scripted-sounding answers that don’t survive follow-up
Common indicator across FBI, KnowBe4, and Amazon reporting

None of these signals is conclusive when taken separately against impostor or deepfake detection. But continue with your observations, while proactively restricting new employee access to sensitive data. Two or more of these taking place, and on more than one occasion? That’s your cue to pause.

Verify the details independently, and privately inform the person responsible for your hiring, payroll, or business operations before taking the next step.

Already Made the Hire and You’re Noticing These Things

Here’s what you can do if the wolf’s already inside the fence:

  • Don’t confront the individual or drop hints that you’re aware of the fraud (not yet) – preserve records (communication logs, resume files, interview recordings) and loop in whoever handles IT/security before deciding on your next step

  • Restrict system access immediately

Cybersecurity experts recommend giving every new hire only the system access they need at first. If the hire isn’t who they claimed to be, you’ve reduced how much damage they can do.

If system access, payroll, or sensitive data was already involved, this becomes more than an HR matter, but a legal and compliance one.

Related Read: Here’s something about the Cybersecurity Skills Shortage US and Cybersecurity Legal Guide— how these are related to an increase in attacks among SMBs.

Why This Is Harder When You’re Hiring Without an HR or Security Team

Most US SMBs have owners conducting the interview, onboarding, and HR processes themselves. But when interview deepfakes are becoming more alarmingly prevalent, you can’t afford NOT to hire specialists to safeguard your operations anymore.

Many of those SMBs? They’re turning to managed providers like Remote Staff. We’ve been at it for over 18 years, making sure businesses don’t just get a pool of candidates. We match them with the best ones for their specific business needs.

When we vet, we go into each profile, each resume, doing checks over checks around the applicant’s identity, their skills, and previous work experiences. We adapt to tech trends (and problems) like deepfake interviews; we know how to watch out for genuine professionals from those who just want to game the system.

As you shore up on cybersecurity and grow your remote team, we’ll support you in other areas of your business, too. Here’s what you need to know about How to Avoid Manager Burnout and how to support Mental Health for Remote Workers.

FAQs About Deepfake Job Candidates

How to spot AI and deepfake candidates in video interviews? (How to detect deepfake job candidates?)

Be on the lookout for lip-sync lag, unnatural blinking, lighting or shadow inconsistencies, unnatural facial movements, lighting mismatch over the face of the person and their background/surroundings, and responses that sound scripted or too polished.

Ask the candidate to make a small unscripted movement, like turning their head or adjusting their lighting. An injected or pre-recorded video often can’t respond to that convincingly in real time (or without taking longer than normal before reacting to your instruction).

What is video injection in a job interview scam? (What is camera injection, or what are video injection attacks?)

Video injection is when a fraudster or scammer feeds a pre-recorded or real-time deepfake video into a video call through virtual camera software. Doing so means they don’t need to use a webcam or mobile phone camera.

Your platform receives what looks like a live feed, making it more difficult to do verification checks like blinking or head movement since these can be edited or perfected long before the video feed is linked.

How common is deepfake and AI fraud in hiring right now? (Are fake job seekers flooding U.S. companies now? Is AI and deepfake fraud in hiring increasing?)

It’s definitely no longer on the rarer end. One 2026 tracking report found 38.5% of candidates flagged for AI-cheating behavior across nearly 19,400 live interviews. According to Experian’s research, deepfake candidates are now one of the top five fraud threats of 2026.

Nearly two-thirds of hiring managers believe candidates have become better at using AI to fool interviewers than recruiters have become at spotting it.

Have you been interviewing a deepfake yet?

Don’t confront the person, and avoid dropping hints that you’re onto their scheme. Preserve interview recordings, resumes, communication records, and track their work logs. Restrict their system access immediately, and involve whoever handles your IT or legal matters (payroll or financial as well) before taking further action.

Extra Read: Beware of Shadow AI Data Leak and find out how to spot the most vulnerable parts of your business operations.

One Video Glitch Can Turn Into a Deepfake Pattern

There’s always something to catch up on in tech. Today, business opportunities aren’t the only thing to watch out for and get ahead of. Deepfake job interviews or fake AI interviews are rapidly gaining a foothold. Big companies are already respponding with replacing remote interviews with in-person ones.

But for SMBs who have remote or hybrid teams, this isn’t the option. You (and your hiring specialists) need to step up to the plate and be familiarized with how these scam interviews are conducted. And what their tells are.

Don’t get caught in the numbers where almost half of businesses can’t tell a real candidate from a fake one. Better yet, hire the offshore specialists who are already experts at spotting deepfakes, and let them deal with the issue so you don’t have to.

Want to learn more about what these roles look like? Call us or Request a Callback today.

+ posts

Vaune Everis Cura has always been a writer in the truest sense, drawn to the art both as a personal creative pursuit and as a profession. Her experience penning content across digital marketing spaces and collaborating with business owners and market shapers has broadened her craft to include strategic direction and SEO insight. Having spent years with the InterContinental Hotels Group before stepping boldly into freelancing, she understands that at the centre of it all are genuine, meaningful brand–customer relationships built on purposeful, human content.

Get FREE EXPERT Guidance

We’ll answer all your burning questions when it comes to building and setting up your remote team.

Our Featured Talent

Get instant and
FREE Access to
our more than
1,000 talent pool
database.

Pick and choose to your liking.

About The Author

Vaune Everis Cura has always been a writer in the truest sense, drawn to the art both as a personal creative pursuit and as a profession. Her experience penning content across digital marketing spaces and collaborating with business owners and market shapers has broadened her craft to include strategic direction and SEO insight. Having spent years with the InterContinental Hotels Group before stepping boldly into freelancing, she understands that at the centre of it all are genuine, meaningful brand–customer relationships built on purposeful, human content.

Leave a reply

Your email address will not be published. Required fields are marked *

Get Your Free Virtual Staff Toolkit

Step by Step Guide on how to effectively and efficiently build, manage your virtual staff.

Ready to Build and Retain your
Ideal Remote Workforce?