What Is Candidate Fraud, and How Do You Spot a Deepfake Interview?

From invented resumes to proxy interviews and real time deepfakes, candidate fraud is rising. Here are the main types, how to spot a deepfake on a video call, and how to build checks into hiring.

AI Recruiting Academy › Module 3: Screening and interviewing with AI

Module 3Lesson 5 of 510 minute read

The short answer

Candidate fraud is any attempt to get hired by pretending to be someone you are not. It ranges from an AI written resume that invents experience, to someone else sitting the interview, to a real time deepfake that swaps one face for another on a video call. The most serious cases are organized schemes, such as North Korean IT workers who use stolen identities to get remote jobs.

Gartner predicts that by 2028 one in four candidate profiles worldwide will be fake. The defense is layered: verify identity early, make interviews hard to fake, check history directly, and give new hires no system access until checks are done.

How common is candidate fraud?

More common than most recruiters assume. In Gartner’s 2025 candidate surveys, 6% of job candidates admitted to interview fraud, either posing as someone else or having someone pose as them. Gartner also found 39% of candidates used AI in their applications, and it predicts that by 2028 one in four candidate profiles worldwide will be fake.

Using AI is not fraud in itself. Polishing a resume with AI is normal now. Fraud is when the person, the experience or the answers are not real.

What are the main types of candidate fraud?

TypeWhat happensWhere you catch it
Invented experienceAI writes a resume full of jobs, projects or skills the person does not haveSpecific questions about past work, reference checks
Hidden AI helpCandidate reads answers from an AI tool during a live interviewFollow up questions, long pauses, eyes moving to read
Proxy interviewA different, stronger person sits the interviewIdentity check, comparing faces across rounds
Bait and switchOne person interviews, another turns up to do the jobPhoto comparison at onboarding, in person day one
DeepfakeSoftware swaps the face or voice on a live video callMovement tests, liveness checks, ID verification
Stolen or synthetic identityReal or invented identity used to pass background checksDocument checks, direct verification of history

What is a deepfake interview?

A deepfake interview uses software that maps a different face, and sometimes a different voice, onto the person on camera in real time. It used to take skill and expensive hardware. It no longer does.

Palo Alto Networks’ Unit 42 team built a working deepfake as a test. A researcher with no image editing experience and a five year old computer created a synthetic identity good enough for a job interview in 70 minutes, using free tools and an AI generated face. A change of clothes and background was enough to return as a new candidate.

How do you spot a deepfake on a video call?

Real time deepfakes still struggle when the face moves quickly, is partly covered, or the lighting changes. Unit 42 and the FBI suggest simple tests any interviewer can ask for politely:

Ask the candidate toWhat a deepfake may do
Pass a hand slowly in front of their faceThe face flickers, blurs or shows through the hand
Turn their head to show a full profileEdges of the face warp or slip
Move closer to a light or change the lightingSkin tone and face edges stop matching the room
Point the camera out of a windowTests whether they are where they say they are
Keep their real background visibleVirtual backgrounds can hide a second person or setup

Also watch for lips that do not match the words, a voice that sounds flat or delayed, and the same virtual background showing up across different candidates. Ask every candidate the same checks, so no one is singled out.

What are North Korean IT worker schemes?

The FBI has warned repeatedly that North Korean workers use stolen or borrowed US identities to land remote IT jobs and send the pay back to the regime. Its July 2025 alert describes US based helpers who receive company laptops and set up remote access, create job site accounts, and even attend virtual interviews on the worker’s behalf. Contract roles filled through third parties are a common route in.

The FBI’s advice for employers includes:

StepWhat it means for recruiters
Scrutinize ID documentsCheck for errors and compare photos and contact details with the person’s online profiles
Verify history directlyContact past employers and schools yourself, not through details the candidate supplies
Meet in person where possibleEven one in person step, such as fingerprinting or a drug test, confirms identity and location
Capture imagesCompare faces between interview rounds and the first day of work
Ship equipment only to the ID addressA request to send a laptop somewhere else is a red flag
No access before checksDo not grant system access until the background check is complete

How do you build fraud checks into your process?

At application. Watch for duplicate resumes, phone numbers or email patterns across applicants, and profiles created very recently. Some applicant tracking systems now flag these automatically.

At the first interview. Cameras on, real background, and questions that need specific answers about past work. Ask a follow up on every claim that matters.

Before the offer. Identity verification with a liveness check, and references you find yourself rather than ones the candidate hands you.

At onboarding. Confirm the person who starts is the person you interviewed, and limit access until checks clear.

Set expectations. Gartner advises telling candidates what AI use you accept and that you check for fraud. It also found 62% of candidates are more likely to apply when a job includes an in person interview, so an in person step need not scare good people away.

How do you stay fair while checking for fraud?

Fraud checks can slide into discrimination if they target accents, nationalities or names. Apply the same checks to every candidate at the same stage, base concerns on specific evidence, and document what you saw. A candidate who is nervous or has a poor connection is not a fraud. Check anti discrimination rules and, where you record interviews, the consent rules from Lesson 3.

Quick answers

Is using ChatGPT to write a resume fraud?

No. Using AI to write or polish a resume is common and acceptable. It becomes fraud when the resume claims experience, qualifications or employers that are not real.

Which roles are most at risk?

Fully remote technical roles, especially IT, software and contract positions, are the main targets of organized schemes. Any remote role can attract proxy interviews.

Can AI detect deepfakes for me?

Detection and identity verification tools help, and the directory lists them. They work best alongside trained interviewers and an in person step, not instead of them.

What should I do if I suspect a fake candidate?

Pause the process, write down what you observed, involve your security or legal team, and do not grant any access. Report suspected North Korean IT worker activity to the FBI.

Module 3: Screening and interviewing with AI

  1. What is AI resume screening?
  2. What is an AI interviewer?
  3. What does an AI note taker do in an interview?
  4. How does AI interview scheduling work?
  5. What is candidate fraud, and how do you spot a deepfake?

You have finished Module 3. Next up is Module 4, Risk, law and fairness.