Advances in AI are making candidate fraud cheaper, easier to scale, and harder to spot. In one recent survey, 41% of IT and security leaders said their company had already hired a fraudulent candidate.
Most hiring processes screen for it at one or two check points. But today, fraud is showing up at every stage: the application and the resume, LinkedIn profiles, pre-screen questions, the recruiter screen, interviews, falsified reference checks, and even onboarding.
“It’s something that’s full spectrum, so we have to be vigilant and have authentication baked into every single step throughout the hiring funnel and after.”
– Stacy Zapar, Founder of Fraud Squad
The stakes have changed too. A fraudulent candidate who gets hired is an insider threat on day one, with real credentials and access to your systems.
That makes this a problem TA and security have to solve together, which is why our recent webinar, The Insider Threat You Just Hired, put both in the same room. BrightHire co-founder and CEO Ben Sesser sat down with Jonathan Ramirez, Senior Intelligence Analyst at Zoom; Stacy Zapar, who founded the TA fraud community Fraud Squad; and Christian Anderson, Insider Risk Analyst at CrowdStrike, to talk about how that partnership can protect companies from candidate fraud. Their advice came down to three practices:
Build a feedback loop between TA and security
Candidates change hands at every stage of the hiring process, which means the small fraud signals that would add up to a pattern are spread across interviewers who never compare notes. And an interviewer who does notice something odd often doesn’t know it’s worth mentioning.
Jonathan’s recommendation is a standing feedback loop between TA, hiring managers, and security. Two things make it work:
- A shared record of every interview. Without them, fraud signals from different rounds never get connected.
- A loop that runs both ways. Security gives TA training on current fraud trends, what counts as a real signal, and what’s likely a false positive. TA gives security the context behind what a recruiter actually saw.
“I have a lot of signals, but the one thing I really don’t have is context, which comes from TA.”
– Christian Anderson, Insider Risk Analyst at CrowdStrike
At CrowdStrike, a recruiter who spots two or three things worth worrying about, like a candidate reading from a prompt during the screen, submits a security review. Security asks what they saw and how the conversation went, then runs the checks TA can’t, starting with the candidate’s IP address.
Christian’s point is that none of this works without rapport. Security has to train recruiters on what to look for, and recruiters have to feel comfortable raising something they aren’t sure about.
Change what recruiters get measured on
Recruiting has spent years optimizing against delay. Time-to-fill, speed to first interview, days in stage. That discourages talent teams from spending valuable time on fraud checks.
“There’s a perception that the security check is that speed bump, so changing that perception and narrative that security is no longer a speed bump, but a very critical element to this process now, because of the evolving threat.”
– Jonathan Ramirez, Senior Intelligence Analyst at Zoom
His proposal is a new success criterion for TA, one that recognizes and incentivizes a recruiter for running fraud checks up front instead of penalizing the slight delay. That might look like two to five minutes per review, which is a small price for catching a potential security threat.
BrightHire built fraud detection into the interview itself, so recruiters get the evidence in the same place they already review interviews.
Stack fraud signals before you escalate a candidate
Not all fraud signals are conclusive on their own. A candidate might look “off” because they’re nervous, looking off-screen, speaking English as a second language, following different cultural norms, and more.
That’s why the panel’s advice is to look for multiple signals before acting on any of them.
“What’s a flag? When does it become a signal? We need to stack multiple signals before we start making decisions.”
– Stacy Zapar, Founder of Fraud Squad
Christian makes the same argument from the detection side, with a warning about complacency. Deepfakes and location obfuscation keep improving, so any single indicator you’re relying on today has a short shelf life. His approach is to take the whole set of signals, apply context, and let that inform the process. The payoff is that a documented pattern is something you can act on and explain to a candidate, a hiring manager, or your legal team.
So what happens when a candidate does trip enough signals? The panel’s answer: hand the case to security, not a rejection. The candidate stays in play while security runs enhanced due diligence. Move ahead with other candidates in the meantime, and if security finds nothing, the candidate picks back up where they left off.
Final thoughts
Defending against candidate fraud means rethinking your hiring process and recruiter skills. Training, a working relationship with security, and a record of what happened in each interview are all key.
“In the age of AI, we can’t just take our 2019 recruiting funnels and processes and pipelines and just throw AI on it and expect it to work in 2026.”
– Stacy Zapar, Founder of Fraud Squad
Watch the full conversation for the panel’s take on background checks, false positives, and where fraud is heading next.





