Skip to content

Deepfake Candidates, in Plain Terms

Understand how deepfake candidates can enter hiring processes, what warning signs recruiters should watch for, and where identity verification can fail.

Deepfake Candidates, in Plain Terms

Fake applicants and deepfaked interviews have moved from novelty story to documented fraud vector inside a single hiring cycle. Here is what is actually happening, and what verification now requires.


A recruiter runs a routine video interview. The candidate answers well, the connection is a little glitchy, and the recruiter puts it down to a weak home network. Nothing about the call feels wrong. Nothing about it needs to feel wrong, because the technology involved was built specifically not to.

That's the version of this problem HR systems now have to plan for, and it's worth being precise about what it is and isn't, because the coverage has run ahead of most recruiting teams' actual exposure.

Three distinct problems wearing one headline

"Deepfake candidate" gets used loosely to describe at least three different things, and they call for different responses.

Visual 1 — Three forms of hiring identity fraud, and why each is hard to catch

Form

What it looks like

Why standard screening misses it

Proxy interviewing

A different, more qualified person sits the technical interview on the candidate's behalf

No synthetic media involved at all — just a mismatch between who interviews and who shows up on day one

Deepfaked video/audio

Real-time face or voice manipulation during a live remote interview

Built specifically to survive casual scrutiny; glitches read as bad Wi-Fi, not manipulation

Synthetic or stolen identity

A fabricated or borrowed identity used to pass background and reference checks entirely

Documentation-based checks verify that a document is well-formed, not that the person presenting it is who they claim

How to read it: The third row is the one linked to organised, state-backed operations rather than opportunistic fraud, and it's the one with the highest downstream cost — because it doesn't end at the offer letter, it continues into system access.

The numbers, and where they're heading

Six per cent of job candidates now admit to some form of interview fraud, including impersonation or proxy interviewing, when asked directly. Gartner's forecast is more pointed: by 2028, as many as one in four candidate profiles globally could be fake in some respect. The volume of deepfake material in circulation is the clearest leading indicator — the Citi Institute projects roughly 8 million deepfakes shared online by the end of 2025, up from around 500,000 in 2023, a sixteen-fold increase in two years.

Financial exposure is following the same curve. Deloitte estimates generative-AI-enabled fraud losses in the United States could reach $40 billion by 2027, up from $12.3 billion in 2023 — and puts the generative-AI share of email-based fraud losses specifically at up to $11.5 billion by that point. Hiring fraud is a smaller slice of that total, but it's the slice with the most direct route into a company's own systems.

Why this is now a systems problem, not a vigilance problem

The reason this belongs in an HR technology conversation rather than a security-awareness memo is that the highest-profile documented cases aren't opportunistic individuals. US Department of Justice actions through 2025 targeted coordinated, nationwide North Korean remote IT worker schemes — indictments, arrests, searches of so-called "laptop farms," and seizures of financial accounts tied to synthetic identities used to obtain legitimate remote access at real companies.

That's an operation with infrastructure behind it, running against recruiting processes designed for a much smaller threat: the occasional candidate who exaggerates a skill. Standard applicant tracking and background-check workflows were never built to catch a coordinated identity, and most haven't been redesigned since the threat changed.

What verification now requires, in five steps

  1. Build interview unpredictability in deliberately. Follow-up questions that require lived context and on-the-spot reasoning are still the simplest tool against both proxy interviewing and scripted deepfakes.

  2. Add liveness checks to remote interviews. Asking a candidate to adjust their camera angle, show the room, or read a randomly generated phrase aloud is low-friction and currently harder for real-time deepfake tools to handle convincingly.

  3. Move identity friction earlier. Government-issued ID validation before significant process investment, plus at least one in-person or verified-live confirmation before onboarding, closes the gap fully remote processes have opened.

  4. Treat resume claims as claims, not records. Live reference conversations catch what automated verification workflows are built to wave through.

  5. Extend zero-trust principles into the first 30–90 days. Monitoring access patterns and privilege requests in the early tenure window catches the cases that made it all the way through hiring.

What this changes

None of this argues for slower hiring across the board — most candidates are exactly who they say they are, and treating every applicant as a suspect is its own cost, in both candidate experience and recruiter time. It argues for moving verification decisions out of individual recruiter judgement calls and into the systems layer, so that liveness checks, identity verification timing and early-tenure monitoring are configured once, consistently, rather than depending on whether a particular recruiter happened to notice a glitchy video call.

The organisations that get ahead of this aren't the ones that trust less. They're the ones that moved the trust decision to a point in the process — and a system — built to actually test it.


Sources and method. A HRHubsMedia original. Interview fraud admission rate (6 percent), Gartner's forecast that up to one in four candidate profiles could be fake by 2028, deepfake volume growth (approximately 500,000 in 2023 to approximately 8 million by end of 2025, per Citi Institute), Deloitte's fraud-loss projections ($12.3 billion in 2023 rising to a projected $40 billion by 2027, with generative-AI-enabled email fraud specifically projected at up to $11.5 billion), 2025 US Department of Justice actions against North Korean remote IT worker schemes, and the five detection recommendations, per The Hacker News, January 2026. Journalism, not procurement advice, and not legal advice — verification and monitoring obligations vary by jurisdiction. Corrections will be made openly on this article.

The briefing

Keep reading the desk.

One email a week on HR technology and the systems of work.