We recently launched candidate fraud detection in BrightHire, surfacing fraud signals from inside the interviews themselves to help talent and security teams protect their companies from the rise in fraudulent candidates.
To walk through how it works, we hosted a webinar, Inside BrightHire’s New Candidate Fraud Detection. Below is a quick overview of the feature, along with answers to the questions that came up in the webinar.
Candidate fraud detection overview
Application screening, identity verification, and background checks are all important steps in preventing candidate fraud during the hiring process, but none of them are foolproof. Fraudulent candidates clear background checks and go on to be hired.
The interview is the richest source of fraud signals, but until now it’s been the point in the hiring process where fraud easily slips by – from AI-assisted answers to proxy interviews and even deepfakes. BrightHire’s candidate fraud detection is built to spot those signals. It runs across three categories:
- Deepfake detection. Is the person on the call who they claim to be, or is AI being used to manipulate their appearance or voice?
- Network risk. Is the candidate connecting through a VPN, proxy, or Tor, or from an unexpected location?
- Interview behavior. Are there signs of AI tools or third-party assistance during the interview?
Signals accumulate at the candidate level, not just per interview, so a pattern across a hiring process is visible, with every flag carrying a severity rating and the evidence behind it.
It runs inside BrightHire Screen and live interviews, so there’s no separate tool and no new step in your workflow.
Candidate fraud detection FAQs
Below are the questions that came up in the webinar:
Can BrightHire tell whether a candidate’s responses are AI-generated in live interviews?
Two signals speak to this. LLM Answer Match compares a candidate’s answer against the characteristics of AI-generated responses and returns a confidence score. Alongside it, BrightHire flags delivery patterns that tend to accompany AI assistance, like a flat, monotone reading that sounds scripted rather than spoken. Each flagged moment links back to the point in the interview that triggered it.
Does BrightHire catch proxy interviewing?
Today, BrightHire provides multiple ways to detect potential proxy interviewing. IP, device, and session metadata help surface inconsistencies that may call a candidate’s identity into question. Recruiters can also review interview recordings and thumbnail snapshots across the interview journey to quickly identify identity anomalies over time—not just within a single interview. Looking ahead, facial geometry and voice fingerprinting will enable even stronger identity verification and candidate consistency capabilities.
If a candidate uses a VPN, will it show?
Yes, though not as a location. Location obfuscation is common in interview processes, and BrightHire can’t definitively pinpoint where someone is when a tool is masking it. What it can do is flag that anonymity services are in use, whether that’s a VPN, a proxy, or Tor, so a reviewer knows the location on file isn’t reliable.
Are you tracking IP and location across a candidate’s interviews to see whether the location changes from one to the next?
Yes. The candidate view lists every interview completed in BrightHire in timeline order, with the integrity signals detected in each alongside session context like location, IP address, and device. That makes shifts visible across the full process.
Does candidate fraud detection make automated decisions, like auto-rejecting or filtering candidates?
No. BrightHire surfaces each signal with the underlying detail, along with an overall risk profile that accumulates across a candidate’s interviews, and leaves the decision to your team. There is no auto-rejection or auto-filtering today. Customers build their own review process around what gets surfaced.
If an interviewer suspects a deepfake, does the tool start an escalation process or guide them through next steps?
Not today, and that’s intentional. The models still produce false positives, and a false signal shouldn’t cost you a strong candidate or degrade the candidate experience. Signals are provided post-call rather than in real time, and Interview Integrity access is available via API, so customers can build their own custom workflows when certain signals are detected. Real-time capabilities are something BrightHire is exploring.
Do fraud detection features require consent from the candidate?
Deepfake detection does. It’s the only capability that requires explicit opt-in consent, because it uses biometric information: facial geometry and voice fingerprint. That requirement follows the most stringent biometric privacy standards in the US, including BIPA. BrightHire helps customers set up the consent flow as part of onboarding.
If a candidate opts out of being recorded, are they opting out of fraud detection too?
It depends on the signal, since each one draws on something different from the interview. Deepfake detection requires the video recording, since the analysis runs frame by frame. LLM Answer Match requires the transcript. Scripted-response detection requires the audio. IP and network signals don’t depend on any of them and remain available.
Does fraud signal coverage differ across Zoom, Microsoft Teams, and Google Meet?
Coverage varies by platform, largely because each signal depends on what session data that platform makes available.
- BrightHire Screen, the AI interviewer that runs first-round screening interviews, has a robust signal set. BrightHire powers the session itself so the signals are captured directly.
- Zoom: the fullest coverage, with a proprietary deepfake model and unique session metadata available only to Zoom customers with a BrightHire subscription.
- Microsoft Teams: deepfake detection, plus IP-derived signals covering geolocation and VPN use.
- Google Meet: deepfake detection only today, with BrightHire adding more as Google exposes more session data.
Who can see candidate fraud signals?
Your organization decides. Role-based access controls determine which interviewers, recruiters, and hiring admins can view integrity signals, and access can also be gated by team. Both are set the same way as any other BrightHire permission.
Do signals show up in the Chrome extension, or only in the main BrightHire app?
Both. A Signals tab appears alongside the transcript in the extension when you’re working in your ATS, showing the same fraud detection signals available in the app.
Can this data be pulled into our own dashboards through the API?
Yes. Candidate fraud signal details are available programmatically through BrightHire’s Interview Access API, so you can pull them into your own dashboards and build custom workflows around them. Enterprise teams with threat detection functions often combine these signals with what they’re already monitoring.
Is there an alert if fraud risk crosses a threshold?
There are no built-in notifications today. Teams that want alerting build it on the API, pulling the signals and triggering on whatever thresholds fit their process.
When will candidate fraud detection be available?
Candidate fraud detection becomes generally available in August. Until then it’s in early access rather than rolled out to all customers, which is why it may not yet appear in your settings.
How do you turn on candidate fraud detection?
Once the feature is available to your organization, it’s a settings change in your account. Administrators enable candidate fraud detection in the settings and choose which categories to run: deepfake detection, network risk, and interview behaviors. Each category toggles independently, so you can match your own policies and risk tolerance. BrightHire works with you on compliance requirements for the states and countries you operate in, and enablement typically takes 24 to 48 hours.
If your question isn’t answered here, or you want to talk through what this looks like for your organization, reach out to your CSM or request a product demo.
Watch the full webinar recording for the complete walkthrough.





