Fake Job Candidates: How to Spot a Deepfake Applicant Before You Hire One (2026)

The interview went well. Clear answers, good energy, a polished resume. Three weeks later the person who logs into your systems on day one looks a little different, sounds a little different, and can't explain the project they described so fluently. That scenario used to belong in cybersecurity training decks. It has now shown up in real hiring pipelines, from startups to security companies. Most hiring processes were built to judge whether a candidate is good. Almost none were built to check whether the candidate is real.
Quick answer
Quick answer: Gartner predicts that by 2028, one in four candidate profiles worldwide could be fake, and in its survey of 3,000 candidates, about 6% admitted to interview fraud. "Fake" covers three different problems: AI-polished paperwork (common, mostly harmless), skills the candidate doesn't have, and outright identity fraud. Don't try to spot deepfakes by eye. Verify at three checkpoints: the application, the live interview, and before day one, and apply the same checks to every finalist.

What "one in four candidates will be fake" actually means
The headline number comes from Gartner, which said in mid-2025 that by 2028 one in four candidate profiles worldwide could be fake. It is a forecast, not a measurement of today, and it is worth reading precisely. Alongside it, Gartner surveyed 3,000 job candidates and found that about 6% admitted to interview fraud: either posing as someone else or having someone else pose as them. The same survey found that roughly 40% of candidates use AI somewhere in the application process, and that a majority of candidates say they would be more likely to apply if a role required an in-person interview.
Two things follow. First, the risk is real enough that a leading research firm is planning for it. Second, "fake" is doing a lot of work in that sentence, because it lumps together behaviors that call for completely different reactions. A hiring team that treats them all the same will either wave through a fraudster or reject an honest candidate who used a grammar tool.
The three kinds of fake candidate
Think of candidate fakery as a spectrum from cosmetic to criminal. Where a person sits on it determines what you should do.

- Cosmetic: AI-polished paperwork. A real person with real experience whose resume and cover letter were smoothed by a tool. This is widespread, and it is not fraud. Penalizing it mostly filters out candidates who were transparent about using modern tools. If it worries you, our guide to using ChatGPT to tailor a resume shows what a legitimate version looks like.
- Capability inflation: skills they don't have.The resume claims proficiency the person lacks, and a tool feeds them plausible answers during the interview. It looks like great answers followed by shallow follow-ups. The cost is a hire who can't do the job.
- Identity fraud: a different person entirely. A proxy interviewer, a stolen identity, or a face and voice swapped in real time. This is the rare, severe end, and it is the one that puts data, money, and systems at risk.
The cases that made hiring teams pay attention
The most cited example is KnowBe4, a security awareness company that disclosed in 2024 that it had hired a remote engineer who passed background checks, reference checks, and four video interviews. The person turned out to be a North Korean operative using a stolen US identity and an AI-enhanced photo. The company's security tooling flagged suspicious activity soon after a laptop was shipped. The uncomfortable point is that a firm whose entire business is teaching people to spot deception was fooled by a process that looked thorough.
It is part of a bigger pattern. US prosecutors have described schemes in which overseas IT workers obtained remote jobs at hundreds of American companies using stolen or fabricated identities, sometimes with US-based accomplices running "laptop farms" so the hardware appeared to sit at a local address. In mid-2025 the Department of Justice announced coordinated actions that included searches at 29 suspected laptop farms across 16 states. You do not have to be a government contractor or a security firm to be a target. Any employer that hires remotely, pays well, and grants system access qualifies.
One reason this works is speed and cost. Reporting on the topic, including coverage in HR Dive, has described how a workable deepfake candidate can be assembled in about an hour with consumer-grade tools. The same reporting notes how poorly people detect synthetic video: one meta-analysis found human accuracy of only about 56%, barely better than a coin flip. If your entire defense is "our recruiters will notice," it is not a defense.
A three-checkpoint verification process
Instead of trying to become a deepfake detective, build verification into the process itself. The idea is simple: the person who applied, the person who interviewed, and the person who starts must be the same person, and you check that at three points rather than one.

At the application: catch the cheap fakes early
In the live interview: test the person, not the script
Before day one: the strongest gate, before any access
One more low-cost lever: for sensitive roles, add an in-person or at least a live, unscripted final round. Gartner's survey found that a majority of candidates say they are more likely to apply when a role involves an in-person interview, so it doesn't necessarily hurt your funnel, and it removes an entire category of fraud.
In the live interview: signals to notice, and what to say instead
Some signals are worth a second look. The trap is treating them as proof. They are prompts to verify, not verdicts.

The scripts matter as much as the signals. Never ask "are you a deepfake?" You put an honest person in a humiliating position and tip off a dishonest one. Instead, make a small, natural request that a real person can meet without effort: "Could you turn your head side to side, or wave a hand in front of your face? Quick lighting check." If video is glitching, offer to switch to a phone call or a short in-person round. And keep probing the substance: "You mentioned the migration. What broke first, and what would you do differently the second time?" A person who did the work answers easily. A script eventually runs out.
The rule that keeps you fair
Put your live-verification time where it counts
Rankid doesn't verify identity, but it does score every resume against your job description on a consistent 0-100 scale and shows exactly which requirements match and which don't, so you spend live-interview and verification effort on the finalists who genuinely fit. First 5 resumes free, no signup.
Try bulk screening freeStaying fair, legal, and unbiased while you verify
Fraud prevention is not a license to profile. A few principles keep the process on solid ground:
- Apply the same checks to every finalist.Verifying only the candidates who seem "off" invites bias. A uniform step at the offer stage is both fairer and more effective.
- Treat detection tools as one input, not a verdict. Biometric and liveness tools can produce false positives, and accuracy can differ across demographic groups, which can create disparate-impact risk. Keep a human in the loop, and see our guide to adverse impact for how to monitor selection outcomes.
- Mind biometric and privacy rules. Some jurisdictions regulate collecting facial or other biometric data. If you scan faces or IDs, get legal review, disclose what you collect, and store it securely for only as long as you need it.
- Document your process. Keep a record of the checks you run and why, so you can show a consistent, job-related procedure. If you rely on automated tools, our overview of AI resume screening covers the compliance questions to ask.
- Write a clear AI-use policy.With around 40% of candidates using AI somewhere in the application process, tell people what is acceptable (polishing wording) and what isn't (impersonation, or feeding live answers during an assessment). Clear rules make violations easy to act on.
For candidates: how to look real when everyone is suspicious
If you are an honest applicant, expect more verification than a few years ago, especially for remote roles. You can make it painless. Keep your camera on with a plain, well-lit background. Make sure your resume, professional profile, and portfolio tell the same story. Be ready to share a screen and talk through real work in detail, since specifics are the best proof of experience. If asked to confirm your identity, check that the request comes from the company's official recruiter, ask how the copy of your ID will be stored and for how long, and be cautious about sending images through unofficial channels. Fake recruiters exist too, and the same caution applies in the other direction. Our guide to ghost jobs covers how to tell whether a posting is real in the first place.
The bigger picture: verification is now part of hiring
Hiring used to assume that the person in the interview was who they said they were, and focused all its effort on whether they were good. That assumption is what is breaking. The fix is not paranoia. It is a process with a few well-placed checks, applied evenly, that makes honest candidates' lives easy and dishonest ones' lives hard. If you already run a structured hiring process, adding these three checkpoints is a small change with an outsized payoff. If you don't, this is a good reason to start.
Applying for remote roles? Make your resume tell one consistent story
Paste your resume and the job posting into Rankid for a free 0-100 match score and the exact requirements you meet and miss. A resume that maps clearly to the role is easier to verify, and easier to trust.
Check your match score freeFrequently asked questions
What does it mean when analysts say one in four candidates will be fake by 2028?
It is a prediction from the research firm Gartner, reported in mid-2025, that by 2028 one in four candidate profiles worldwide could be fake. The important word is profiles, and the important caveat is that it is a forecast rather than a measured rate today. It also covers a wide spectrum of behavior, from AI-polished wording on a real person's resume all the way to a completely invented or stolen identity, so it should not be read as one in four applicants being criminals.
What is the difference between an AI-polished resume and a fake candidate?
An AI-polished resume belongs to a real person with real experience whose wording was smoothed by a tool, which is now common and largely harmless. A capability-inflated candidate claims skills they don't have and may use AI to generate convincing answers live. An identity-fraud candidate is a different person entirely, using a proxy interviewer, a stolen identity, or real-time face and voice swapping. Each needs a different response, and treating the first like the third is how good candidates get rejected.
How common is interview fraud right now?
In a Gartner survey of 3,000 job candidates, about 6 percent admitted to interview fraud, meaning they either posed as someone else or had someone else pose as them. That is a self-reported figure from people willing to admit it, so the true rate may differ, but it shows the behavior is no longer a rounding error. Fraud is most attractive in fully remote roles, where no one on the hiring team ever meets the person in the same room.
Can you really tell a deepfake on a video call?
Sometimes, but not reliably by eye. One meta-analysis of studies on human deepfake detection found people identify them only slightly better than chance, around 56 percent. That is why the strongest defenses do not depend on spotting a glitch. They depend on verifying identity at the offer stage, testing real ability with unscripted follow-ups, and confirming that the person who interviewed is the person who starts.
What are the most common red flags of a fake candidate in a video interview?
The signals worth a second look include lip movement that lags behind the audio, blur or warping around the edge of the face when the person turns, lighting on the face that does not match the room, the same long pause before every answer, eyes fixed off-screen as if reading, and repeated refusals to share a screen, show ID, or move a hand near the face. None of these proves fraud on its own. A weak connection or a cheap webcam can cause several of them, so look for patterns and verify rather than accuse.
What should I say if I suspect the person on camera is not real?
Do not ask whether they are a deepfake. Ask for something small that is hard to fake in real time and easy for a real person to do: turn your head side to side, wave a hand in front of your face, or share your screen and walk me through a task. If video quality is the issue, offer to switch to a phone call or an in-person final round. Real candidates comply without offense. If someone repeatedly refuses every reasonable check, pause the process and escalate to security or HR rather than confronting them yourself.
What was the KnowBe4 case, and why does it matter?
In 2024 the security awareness company KnowBe4 disclosed that it had hired a remote software engineer who passed background checks, reference checks, and four video interviews. The person turned out to be a North Korean operative using a stolen US identity and an AI-enhanced photo, and the company's security tools flagged suspicious activity soon after a laptop was shipped. It matters because the company that was fooled sells security training for a living, which shows that standard hiring steps, on their own, do not verify who someone actually is.
What are laptop farms and why do they matter for hiring?
A laptop farm is a location, often a private home in the United States, where company-issued laptops are received and kept running so that a remote worker located somewhere else appears to be working from a local address. The US Department of Justice has prosecuted operators tied to North Korean IT worker schemes, including coordinated actions in mid-2025 that involved searches at 29 suspected laptop farms across 16 states. For employers, the lesson is to verify where hardware is shipped and to be cautious about last-minute shipping-address changes.
Is it legal to ask a candidate to show ID on camera?
In general, verifying identity for a candidate you are about to hire is legal and standard, since you already have to verify identity and work authorization for every new employee in the United States. The care needed is in how you do it: apply the same check to every finalist for the role, do not single out people by accent, appearance, or name, store any copies securely, and be aware that some states regulate biometric data if you use facial recognition or liveness scans. Have counsel review your process before you roll it out.
Do AI liveness or deepfake-detection tools solve the problem?
They can help as one layer, but they are not a complete answer. Detection tools produce false positives and false negatives, and biometric systems have documented accuracy differences across demographic groups, which can create disparate-impact risk. A defensible process keeps a human in the loop for any consequential decision, documents how the tool performs, and combines it with non-technical checks such as verified references and an ID match at the offer stage.
How do I avoid rejecting real candidates while screening for fraud?
Separate the three kinds of fakeness and respond proportionally. Do not penalize AI-polished wording, because that describes a large share of honest applicants. Test real ability with specific, unscripted follow-ups. Save identity verification for finalists and apply it identically to everyone. And never treat a poor webcam, a stutter, an accent, or a thoughtful pause as evidence of fraud. The goal is to verify, not to profile.
I'm a real candidate and was asked to verify my identity. Should I be worried?
No, it is increasingly normal, especially for remote roles. Expect a request to turn your camera on, occasionally share your screen, and confirm your identity with a government ID before an offer becomes final. Confirm the request comes from the company's official recruiter, be cautious about sending ID images over unofficial channels, and ask how the copy will be stored and for how long. A legitimate employer will answer plainly.
Key takeaways
- Gartner predicts one in four candidate profiles worldwide could be fake by 2028, and about 6% of 3,000 surveyed candidates admitted to interview fraud.
- Candidate fakery is a spectrum: AI-polished paperwork is common and mostly harmless, skill inflation costs you a bad hire, and identity fraud puts data and systems at risk.
- Real cases, including a security company that hired an operative using a stolen identity, show that background and reference checks alone don't verify who someone is.
- People detect deepfakes by eye only slightly better than chance, so don't rely on spotting glitches; build verification into the process instead.
- Verify at three checkpoints: the application, the live interview, and before day one, so the person who applied, interviewed, and starts are the same person.
- Never ask "are you a deepfake?" Ask for a small movement, switch to a phone call, or dig two levels deeper into their real work.
- A weak connection, cheap webcam, stutter, accent, or thoughtful pause are not fraud signals. Judge patterns and apply the same checks to every finalist.
- Treat detection tools as one input with a human in the loop, watch for bias and biometric-privacy rules, and document your process.
- Write a clear AI-use policy and ship hardware only to verified addresses, starting remote hires with limited access until they are established.
Frequently asked questions
What does it mean when analysts say one in four candidates will be fake by 2028?
It is a prediction from the research firm Gartner, reported in mid-2025, that by 2028 one in four candidate profiles worldwide could be fake. The important word is profiles, and the important caveat is that it is a forecast rather than a measured rate today. It also covers a wide spectrum of behavior, from AI-polished wording on a real person's resume all the way to a completely invented or stolen identity, so it should not be read as one in four applicants being criminals.
What is the difference between an AI-polished resume and a fake candidate?
An AI-polished resume belongs to a real person with real experience whose wording was smoothed by a tool, which is now common and largely harmless. A capability-inflated candidate claims skills they don't have and may use AI to generate convincing answers live. An identity-fraud candidate is a different person entirely, using a proxy interviewer, a stolen identity, or real-time face and voice swapping. Each needs a different response, and treating the first like the third is how good candidates get rejected.
How common is interview fraud right now?
In a Gartner survey of 3,000 job candidates, about 6 percent admitted to interview fraud, meaning they either posed as someone else or had someone else pose as them. That is a self-reported figure from people willing to admit it, so the true rate may differ, but it shows the behavior is no longer a rounding error. Fraud is most attractive in fully remote roles, where no one on the hiring team ever meets the person in the same room.
Can you really tell a deepfake on a video call?
Sometimes, but not reliably by eye. One meta-analysis of studies on human deepfake detection found people identify them only slightly better than chance, around 56 percent. That is why the strongest defenses do not depend on spotting a glitch. They depend on verifying identity at the offer stage, testing real ability with unscripted follow-ups, and confirming that the person who interviewed is the person who starts.
What are the most common red flags of a fake candidate in a video interview?
The signals worth a second look include lip movement that lags behind the audio, blur or warping around the edge of the face when the person turns, lighting on the face that does not match the room, the same long pause before every answer, eyes fixed off-screen as if reading, and repeated refusals to share a screen, show ID, or move a hand near the face. None of these proves fraud on its own. A weak connection or a cheap webcam can cause several of them, so look for patterns and verify rather than accuse.
What should I say if I suspect the person on camera is not real?
Do not ask whether they are a deepfake. Ask for something small that is hard to fake in real time and easy for a real person to do: turn your head side to side, wave a hand in front of your face, or share your screen and walk me through a task. If video quality is the issue, offer to switch to a phone call or an in-person final round. Real candidates comply without offense. If someone repeatedly refuses every reasonable check, pause the process and escalate to security or HR rather than confronting them yourself.
What was the KnowBe4 case, and why does it matter?
In 2024 the security awareness company KnowBe4 disclosed that it had hired a remote software engineer who passed background checks, reference checks, and four video interviews. The person turned out to be a North Korean operative using a stolen US identity and an AI-enhanced photo, and the company's security tools flagged suspicious activity soon after a laptop was shipped. It matters because the company that was fooled sells security training for a living, which shows that standard hiring steps, on their own, do not verify who someone actually is.
What are laptop farms and why do they matter for hiring?
A laptop farm is a location, often a private home in the United States, where company-issued laptops are received and kept running so that a remote worker located somewhere else appears to be working from a local address. The US Department of Justice has prosecuted operators tied to North Korean IT worker schemes, including coordinated actions in mid-2025 that involved searches at 29 suspected laptop farms across 16 states. For employers, the lesson is to verify where hardware is shipped and to be cautious about last-minute shipping-address changes.
Is it legal to ask a candidate to show ID on camera?
In general, verifying identity for a candidate you are about to hire is legal and standard, since you already have to verify identity and work authorization for every new employee in the United States. The care needed is in how you do it: apply the same check to every finalist for the role, do not single out people by accent, appearance, or name, store any copies securely, and be aware that some states regulate biometric data if you use facial recognition or liveness scans. Have counsel review your process before you roll it out.
Do AI liveness or deepfake-detection tools solve the problem?
They can help as one layer, but they are not a complete answer. Detection tools produce false positives and false negatives, and biometric systems have documented accuracy differences across demographic groups, which can create disparate-impact risk. A defensible process keeps a human in the loop for any consequential decision, documents how the tool performs, and combines it with non-technical checks such as verified references and an ID match at the offer stage.
How do I avoid rejecting real candidates while screening for fraud?
Separate the three kinds of fakeness and respond proportionally. Do not penalize AI-polished wording, because that describes a large share of honest applicants. Test real ability with specific, unscripted follow-ups. Save identity verification for finalists and apply it identically to everyone. And never treat a poor webcam, a stutter, an accent, or a thoughtful pause as evidence of fraud. The goal is to verify, not to profile.
I'm a real candidate and was asked to verify my identity. Should I be worried?
No, it is increasingly normal, especially for remote roles. Expect a request to turn your camera on, occasionally share your screen, and confirm your identity with a government ID before an offer becomes final. Confirm the request comes from the company's official recruiter, be cautious about sending ID images over unofficial channels, and ask how the copy will be stored and for how long. A legitimate employer will answer plainly.