Candidate fraud is escalating due to remote work and AI, forcing TA teams to defend against threats from sophisticated fraudsters to state-sponsored attacks.
This guide covers everything you need to know: how candidate fraud works, the red flags to watch for, real examples, and the steps to protect your organization at every stage of hiring.
Candidate fraud is exploding—AI, remote work, and deception are reshaping hiring.
From bots to deepfakes, candidate fraud is evolving fast—learn the risks hiding in plain sight.
Learn how to detect fake candidates with subtle signs across resumes, interviews, and online profiles.
Proactive hiring tips to detect and prevent candidate fraud early.
Fraud is happening, it’s sophisticated, and even vigilant companies can be targeted.
Get the complete training guide to detecting and safeguarding against fake candidates.
Gartner predicts that by 2028, globally 1 in 4 job candidates will be fake. This is largely due to the proliferation of AI-generated profiles and application tactics.
Beyond individual attempts, organized schemes are also generating significant revenue. For instance, the UN estimates that North Korean IT worker scams alone have funneled $250MM – $600MM annually to the regime since 2018, often funding sanctioned activities like weapons programs.
Since 2022, the FBI has warned of increased fraud using deepfakes and stolen personally identifiable information (PII) to apply for remote jobs.
Hiring is a human process, and that’s exactly what makes it vulnerable. Every search moves through a chain of handoffs — recruiter to coordinator to interview panel to hiring manager to onboarding — and identity is rarely re-verified at any of them. Four forces are converging to exploit that:
Hiring a fraudulent candidate goes far beyond the frustration of a bad hire. The consequences can ripple throughout an organization, impacting finances, security, and reputation, and can be magnified particularly for organizations handling highly sensitive data (e.g. healthcare, financial institutions) or critical infrastructure (e.g. utilities, military, etc).
There are a range of ways companies can be held liable for these schemes. There’s no defense to say, ‘we didn’t know,’ or ‘we did our best.’”– Joshua Fattal, Privacy, AI and Data Security Attorney, Morrison Foerster
Claiming credentials, experience, or capabilities a candidate doesn’t have, often at scale: using AI to generate and submit thousands of tailored resumes and cover letters. While often driven by desperation rather than malice, this floods systems, wastes recruiter time, and can obscure genuinely qualified candidates.
Leveraging AI for assessments, coding tests, or real-time answer generation during interviews. This misrepresents a candidate’s true abilities, potentially leading to costly mishires and performance issues.
Having someone else (an impersonator) conduct interviews, known as proxy interviewing OR using sophisticated “deepfake” technology where the person on screen appears to be talking, but their words are generated by AI or spoken by someone else off-camera.
Placing individuals within companies with specific, malicious intent to steal data, intellectual property, or funds, or to install malware. These complex operations are often run by criminal organizations or malicious governments like North Korea.
Developing a “spidey sense” for potential fraud is crucial. While many of these signs could have innocent explanations (beware of false positives!), they warrant further investigation.
Train your team to watch for each of these across the hiring process:
No single red flag proves fraud. The most effective defense is tracking multiple signals together across every touchpoint, from application to screen to live interview, so you can see the full picture.
Many of these red flags can be surfaced automatically. Signals like location mismatches, unusual answer patterns, and video inconsistencies are exactly what BrightHire flags across screening and live interviews, with evidence attached to every signal. Learn more
Awareness is the first step, but proactive measures across the hiring lifecycle are essential. Here’s a step-by-step approach:
These stories underscore the reality: fraud is happening, it’s sophisticated, and even vigilant companies can be targeted.
The U.S. Justice Department uncovered a scheme affecting over 300 companies, including major retail and tech firms, generating nearly $7 million for fake IT workers, likely linked to North Korea.
A company hired a fraudulent North Korean employee who infiltrated systems and downloaded information. After being caught and fired, the individual demanded a ransom payment to prevent the release of the data.
“No longer are they just after a steady pay check, they are looking for higher sums, more quickly, through data theft and extortion, from inside the company defenses.”
A defector described to The Wall Street Journal how the operation runs: IT workers placed at Western companies, wages routed back to the regime, quotas enforced from Pyongyang. On the other side of a suspicious interview is often an organized system, not an opportunist.
Even we at BrightHire encountered a suspicious candidate for a back-end engineer role. The applicant had an unusual name for his accent, gave a lengthy, overly rehearsed background story, but then became stumped and audibly seemed to be searching for an answer when asked a simple follow-up question (“Where were you before Amazon?”). Throughout the interview, pauses, keyboard noises, and increasingly evasive responses raised major red flags.
Hear how hiring teams can defend against fraud. In our recent webinar, talent, legal, and security leaders shared how they’re confronting the rise of candidate fraud, from the tactics they’re seeing to the safeguards they’re putting in place.
Watch the on-demand webinar
Candidate fraud is no longer a niche problem; it’s a significant and growing threat impacting organizations of all sizes, globally. From AI-powered cheating to sophisticated state-sponsored infiltration, the methods are evolving, and the potential damage is substantial.
Talent Acquisition teams are now guardians at the gate, playing a critical role in protecting their organizations. By fostering awareness, training teams to spot red flags, implementing robust verification processes throughout the hiring lifecycle, and leveraging technology thoughtfully, companies can significantly mitigate their risk.
Don’t let your organization become the next victim. Stay informed, stay vigilant, and build strong defenses against the rising tide of candidate fraud.
Report suspicious activity: If you suspect you’ve encountered fraud, especially involving potential North Korean actors, report it to the FBI’s Internet Crime Complaint Center (IC3) at www.IC3.gov.
What's the difference between candidate fraud and a candidate exaggerating their resume?
Exaggeration is stretching the truth, rounding up a job title, padding a date, or overstating a skill. Candidate fraud is deliberate deception about who someone is or what they can do: a stolen or fabricated identity, an impersonator or proxy sitting the interview, or a deepfake. The line is intent and identity: embellishment inflates a real person’s record, while fraud misrepresents the person entirely.
How can you prevent candidate fraud in remote interviews?
Remote hiring removes the in-person cues that once caught impostors, so build the checks back in: require cameras on, ask unscripted follow-up questions a proxy couldn’t anticipate, run a live skills task rather than a take-home, and confirm the same person appears at every stage. Verify identity and location, and treat resistance to any of these as a signal worth investigating.
Can you detect a deepfake in a live interview?
Yes, though it’s difficult to do manually. Trained eyes can sometimes spot rendering artifacts, unnatural lighting, or lip-sync issues, but deepfake quality is improving quickly. Detection technology has started to close the gap: deepfake detection is now available directly inside live interviews on Zoom, analyzing video for signs a human reviewer would miss.
Is it legal to record interviews to detect fraud?
In most jurisdictions, yes, with proper consent. Consent and notification requirements vary by state and country, so work with your legal team to set a compliant policy. Look for consent-first tools, and use NIST’s 2025 digital identity guidance as a reference point when setting your approach.
What should you do if you suspect a candidate is fraudulent?
Don’t reject on a hunch. Document the specific signals you observed, review any interview recordings, ask verifying follow-up questions, and loop in your security team if the role involves system or data access. Consistent human review protects honest candidates while giving your team a defensible record of how the decision was made.