To detect a fake candidate, get them into a live conversation and confirm that the person on the call is who they claim to be and that the work history is theirs. Ask unplanned follow-up questions a real candidate would answer easily, check identity against an ID or earlier photo, and compare the person across every round.
For most hiring teams, catching a fake candidate was a recruiter’s job. Nowadays it pulls in Security, IT, and Legal, because a fake candidate who gets hired becomes not only a bad hire but also an access problem.
The four types of candidate fraud
Candidate fraud surfaces in different ways, and a check that catches one type can easily miss another. The main candidate-fraud guide sorts these types by how much damage they do, from a padded résumé to a state-sponsored operation.
For detection, sort them by the method that actually catches each type.
| Fraud type | What it looks like | What catches it |
|---|---|---|
| Qualification misrepresentation | An AI-written résumé, cover letter, or writing sample, or an inflated work history. | Checking claims against sources the candidate did not supply, plus a live conversation that probes the experience. |
| AI-assisted cheating | An AI generating or coaching answers in real time during an assessment or interview. | Unplanned follow-ups and back-and-forth a script cannot cover. |
| Identity misrepresentation: proxy or impersonation | Someone other than the applicant on the call, or a facilitator standing in and coaching. In a 2025 Gartner survey, 6% of candidates admitted to interview fraud of this kind. | A camera-on identity check against an ID or earlier image, and comparing the person across touchpoints. |
| Identity misrepresentation: deepfake or synthetic identity | Real-time face or voice synthesis, now buildable in about 70 minutes on cheap, off-the-shelf hardware. | Challenge-response inside a live interview, and deepfake-artifact detection. |
| Organized or state-sponsored fraud | Trained operatives who use real but stolen identities to clear every check, then steal data or install malware once hired. | A layered defense that pairs identity verification with post-hire device, location, and access controls owned by IT and Security. |
Qualification misrepresentation
The most common type, and the least dramatic. Someone inflates a title, stretches a date, or claims a project they only watched happen. Generative AI has made the written layer of this cheap and polished, so a résumé, cover letter, and writing sample can all read well without the candidate having done any of the work behind them. A conversation catches this one almost by itself, because asking for the detail behind a claim either produces it or doesn’t.
AI-assisted cheating
AI-assisted cheating is harder to spot than impersonation. The candidate is real, but the answers aren’t theirs. A model can draft a response, feed it through an earpiece, or coach a coding round as it happens.
Identity misrepresentation
Two versions of the same problem, and they break differently. In the simpler one, a stronger candidate sits the interview for someone else, or a facilitator joins and coaches from off camera. Comparing the person across rounds is what catches it, since the substitution usually happens once and then has to keep holding.
Real-time deepfakes are the harder version, and they’ve gone from novelty to something anyone with basic technical skills can assemble cheaply. Whether a human interviewer can reliably catch a deepfake in a live conversation is still an open question: current published research measures prerecorded clips, not live hiring interviews, so nobody yet knows how a trained recruiter performs against a real-time fake.
How to Detect Deepfake Candidates in Video Interviews covers the specific signals and the challenge-response checks that force a fake to break.
Organized or state-sponsored fraud
Organized fraud is the reason security teams now join hiring conversations at all. The US Department of Justice has documented North Korean IT-worker schemes that placed operatives at more than 300 companies using stolen identities, earning wages that funded North Korea’s government and, in some cases, enabling data theft and extortion.
How to detect a fake candidate
The same five steps work whether you’re running screening interviews at volume or sitting in a final round.
1. Treat the records as claims, and pick the ones you’ll test. Everything you gather before the conversation describes a claimed identity. A résumé, a LinkedIn profile, references, even a completed background check all sit on top of a name, and a name can be borrowed.
So before the interview, pull two or three specifics off the résumé that only the real candidate could speak to, like a project they led or a call they made, and plan to ask about those live.
In 2024 the security-training firm KnowBe4 hired an engineer who cleared résumé review, four video interviews, and background and reference checks, then loaded malware the day the company laptop arrived. The person had used a real but stolen US identity. Records can describe a real, verifiable person and still not prove that person showed up.
2. Force a live, two-way exchange. Fraud is easiest wherever you’re reviewing what a candidate sent over instead of talking to them. A résumé cannot be cross-examined, a one-way recorded video answers only the questions you set in advance, and a take-home test can be handed to someone else.
Fraud can and does survive a live conversation, and KnowBe4’s hire passed four of them. What a live conversation gives you is the first chance to probe, follow up, and watch someone think, which is more than anything earlier in the process offers.
3. Ask an unplanned follow-up question. The single most useful thing an interviewer can do is go off-script. Rehearsed proxies, answers fed by an AI in real time, and borrowed work histories all hold up against prepared interview questions, but they can break on unexpected follow-ups.
Pick something the real candidate would know cold, like a decision they say they made or a tradeoff on a project they’ve listed. Ask them to go a level deeper on it. Someone reading from a script or waiting on a generated answer tends to stall, speak in generalities, or contradict what they said a minute earlier.
4. Verify identity for every hire, then scale to the role. Hiring someone means handing over credentials, systems, and often customer data, so how much you verify should match the sensitivity of that role.
Every hire gets credentials and system access, so every hire clears the same baseline, a camera-on conversation where the person matches their ID or an earlier photo. Roles carrying production access, customer data, or financial authority justify more on top of it. What doesn’t work is treating every applicant like a suspect, which drives good people away without catching anyone.
Whatever level you choose, the aim is to confirm identity, not to interrogate, because the method has to protect honest candidates as much as it catches the rare fraud. If something looks off, look closer. Don’t auto-reject over it.
5. Compare across various touchpoints, and keep a record. Fraud that survives one conversation tends to break across several, because the same face, the same story, and the same location all have to hold up every time. Is the person in the final round the person from the screening interview? Do the answers, the background noise, and the claimed location hold steady from one session to the next?
Recruiters most often catch fraud by comparing recordings, which is only possible if the conversations were captured in the first place. A reviewable record turns a vague suspicion into something a hiring team can actually check.
If you suspect a candidate is fraudulent
When something looks wrong, document what you see, preserve the recording, and bring in whoever owns the decision before you act on it (including Security or Legal if the role touches sensitive systems).
How BrightHire detects candidate fraud
Most detection work happens inside the interview itself, which is where BrightHire operates. Recording the conversation means someone else can review what was said, and you can compare the candidate from one round to the next.
BrightHire Screen runs the AI screening interviews, and Interview Intelligence records the live interviews your team runs. Across both, BrightHire has captured over 5 million interviews and 2 million candidates.
BrightHire surfaces fraud signals from both AI screening interviews and live interviews, including deepfake detection, location mismatches, unusual answer patterns, and video inconsistencies. Every flag arrives with the evidence attached, so a person can check it rather than take it on faith. On Zoom, deepfake detection runs directly inside the live interview.
Those signals land in one place next to the recording and the transcript, so whoever owns the decision can see what was flagged, why, and what the candidate actually said. BrightHire never auto-rejects a candidate or makes the hiring decision. Your team gets the signals, the evidence, and the recording, and your team decides.
Protect your company from candidate fraud covers the Zoom-native detection, the risk dashboard, and the audit trail behind every flag.
Frequently asked questions (FAQs)
How do you detect a fake candidate?
Confirm the person is who they claim to be and that the work history is theirs. Treat every record as a claim until the live conversation confirms it belongs to the candidate you’re interviewing. Hold a two-way conversation, not a one-way recording. Ask unplanned follow-up questions the real candidate would answer easily. Match your identity checks to the sensitivity of the role, and compare the candidate across every round.
Does a background check prove someone is who they say they are?
No. A background check confirms records, and a real but stolen identity produces clean records. It also runs late, after you’ve already spent your most expensive interview time. A clean check tells you the identity exists, not that the person you interviewed is the one who owns it.
How do I know the same person shows up for every interview?
Compare recordings across rounds. Identity is usually checked once, at the start, then assumed for every session after, which is exactly the gap a proxy or a swapped candidate uses. Line up the person, the answers, and the claimed location from the screening interview against the later rounds, and re-verify identity between them rather than only at intake.
How do I detect candidate fraud during an interview without special tools?
Keep cameras on and ask unplanned follow-up questions. Rehearsed impersonators and real-time AI both break when you go a level deeper than their prepared answers or change direction unexpectedly. Record the conversation with consent so you can compare it later. Tools help at scale, but the interview itself is where most fraud first becomes visible.
Can you spot an AI-generated or deepfake candidate on your own?
Sometimes, but don’t count on it. Real-time deepfakes are cheap to build and getting harder to catch by eye, and the current research only tests prerecorded clips, not live hiring interviews, so there’s no reliable figure for how often a person catches a deepfake live. Treat the conversation, cross-round comparison, and identity checks as your primary defense, and use detection tools as a second layer. How to Detect Deepfake Candidates in Video Interviews covers the specific signals.





