For hiring teams

Fake job applicants and candidate fraud: what hiring teams can check

Published Updated 12 min read By the Career1 team

Candidate fraud runs from AI-written applications that overstate experience to proxy interviewers and deepfaked video from people using stolen identities, which the FBI has warned employers about since 2022. Hiring teams make it much harder with ordinary checks at each stage: contact details, a live follow-up question, a recording to compare later, and identity checks before any system access.

What counts as candidate fraud?

Two different problems travel under one name, and mixing them up leads to the wrong checks. Cheating misrepresents what somebody can do: reading answers from a chatbot, or a friend feeding lines. Fraud misrepresents who somebody is: a borrowed identity, a stand-in at the interview, a face that is not theirs. Using AI to tidy up a resume is neither, and treating it as fraud punishes the ordinary applicant.

Swipe the table sideways to see every column.

KindWhat it looks likeWhere it shows upThe check that catches it
Inflated applicationA real person claims experience they do not have, often in polished AI-written proseResume screenQuestions about specifics, followed up
Hidden instructionsInvisible text in a resume aimed at an AI screenerResume screenRead the plain text your software read
Scripted answersAnswers read from a chatbot during the interviewFirst interviewA follow-up the script did not anticipate
Proxy interviewerSomebody else sits the interview; the applicant turns up laterInterview to day oneCompare the person in every round
Deepfake or voice spoofingAltered video or voice on a live or recorded callVideo interviewsLip sync, interruptions, a hand across the face
Stolen or synthetic identityReal personal details that belong to somebody elseBackground checkDocuments checked against the person
Sanctioned remote workersOperatives hired for remote tech roles through intermediariesRemote hiring and onboardingIdentity checks and where the laptop goes

The rows get rarer and more serious as you go down. Most hiring teams meet the first three every week and may never meet the last. The ones that do are overwhelmingly hiring remote technical staff, which is where the official warnings below are aimed.

How common are fake job applicants?

Nobody publishes a reliable rate, and the most quoted forecast is one we could not check: the analyst's page refused the connection on the day this was written, so its figure is not repeated here. What can be opened says the problem is real and reported, not how large it is.

  • Law enforcement. On 30 June 2025 the Justice Department announced searches of 29 known or suspected "laptop farms" across 16 states, and said the schemes behind them had obtained employment with more than 100 US companies using stolen and fake identities.
  • A vendor survey. In Greenhouse's 2025 AI in Hiring survey of 4,136 job seekers, recruiters and hiring managers in the US, UK, Ireland and Germany, 65 percent of US hiring managers said they had caught applicants using AI deceptively: reading AI-generated scripts (32 percent), hiding prompt injections in resumes (22 percent) or appearing as deepfakes (18 percent). 41 percent of the 1,200 US job seekers admitted using prompt injections, and 39 percent of US hiring managers said they were holding more interviews in person.

Read the survey for what it is. Greenhouse sells hiring software, the answers are self-reported, and "caught" means the manager believed it. The same survey found 36 percent of US job seekers had used AI to alter their appearance, voice or background on video, mostly to look more professional. A blurred background is not a deepfake, and a check that cannot tell the two apart will insult honest people.

What has the FBI told employers about fake remote applicants?

Three public service announcements from the FBI's Internet Crime Complaint Center are the primary sources, and they are short enough to read in full.

June 2022. The first warning reported "an increase in complaints reporting the use of deepfakes and stolen Personally Identifiable Information (PII) to apply for a variety of remote work and work-at-home positions", mostly in IT, programming, database and software roles. It describes interviews where "the actions and lip movement of the person seen interviewed on-camera do not completely coordinate with the audio", and background checks that found the details given belonged to somebody else.

January 2025. The second concerns North Korean IT workers, who "have been observed using artificial intelligence and face-swapping technology during video job interviews to obfuscate their true identities", and who have extorted employers after being discovered. It notes they reuse phone numbers, particularly voice-over-IP numbers, and email addresses across resumes under different names, and advises employers to "Complete as much of the hiring and onboarding process as possible in person."

July 2025. The third describes people in the United States attending "virtual interviews and meetings on behalf of" those workers, and gives the most practical advice of the three: require video with an unobscured background, ask the candidate to "wave their hand in front of their face as it may prompt a malfunction in AI generated video", and "Capture images for comparison with future meetings", because "Sometimes an individual is employed to pass the initial interview, but the on-the-job work is completed by a different individual."

What checks catch fake applicants at each stage?

No single check is enough, and the expensive ones belong late, on the few people you intend to hire. Apply the same checks to every finalist, not to the ones who seem unusual: consistency is fairer, and it is how you avoid singling people out by accent or name.

At the application

  • Search your own records for repeats. The FBI's January 2025 notice says to cross-check "for other applicants with the same resume content and/or contact information". An inbox search on the phone number takes seconds.
  • Look at the trail. A profile created last month, a portfolio with no history, photos that appear under other names. The July 2025 notice suggests cross-referencing photographs and contact details with social media, portfolio sites and payment platforms.
  • Read the resume as plain text. Hidden instructions for an AI screener show up the moment you paste the document into a plain editor.
  • Do not penalise polish. Clean writing is not evidence of anything.

At the first interview

  • Ask for specifics, then follow up. Names, numbers, what broke, what they would do differently. Borrowed experience and read-aloud answers usually run out at the second question.
  • Keep a recording or an image. It is what you compare the person against in every later round.
  • On live video, watch whether lips match the audio, ask a question that needs a moment's thought mid-answer, and ask the candidate to pass a hand in front of their face.

Before the offer

  • Verify employment and education directly with the employer or institution, using contact details you find yourself.
  • Meet in person, or on live video, and compare the person with the first recording.
  • Run identity and background checks through your normal, lawful process, the same one for everybody. Ask counsel what applies where you hire.

At onboarding

  • Send equipment only to the address on the identity documents, and grant no system access until the background check is complete, as the July 2025 notice advises.
  • Watch the first weeks: remote access software, logins from several countries, a bank account that keeps changing. All three appear in the FBI's notices.

What does a recorded AI interview prove, and what does it not?

An AI first-round interview is not a fraud check, and nobody should sell it as one. It does produce two things the checks above rely on, which is why it is worth being exact about the line.

What it gives you. On Career1, every applicant has a spoken interview of about eight minutes with the AI interviewer, camera and microphone on, recorded as video with audio and transcribed. The interviewer asks about the projects named on the resume and follows up on vague or suspiciously polished answers, which is where inflated claims and scripted answers tend to come apart. And it leaves exactly what the FBI suggests keeping: a recording of the person who sat the first round, to compare with whoever turns up to the second. The report quotes the transcript, so a reviewer can see where an answer went thin; the sample interview report shows the shape.

What it does not do. Career1 does not check identity documents. It does not confirm that a new applicant owns the email address they applied with before the interview starts. It does not recognise anyone by face or voice, as its privacy policy says, and it does not look for deepfakes, cloned voices or a second person in the room. It does not watch the screen, count windows or claim to detect a second device. A convincing stand-in could sit the whole interview, and the recording would faithfully show the stand-in.

Other vendors sell integrity tooling for their recorded interviews. HireVue's cheating and fraud page lists "browser-focus tracking, controls that limit copy-and-paste behavior, and image capture during eligible OnDemand hiring experiences", and adds that "A single behavior should not automatically be treated as proof of fraud." If you need those controls in the first round, Career1 does not have them.

The sensible split is to let the interview test the claims and keep the evidence, and to put identity checks where the FBI puts them: before the offer and before any access. How the recordings themselves are protected is on Career1's security page.

What should you do when you suspect a candidate?

Suspicion is not proof, and the false positives are real people: a bad connection makes lips drift from the audio, nerves make answers sound rehearsed, and plenty of honest candidates blur their background.

  1. Write down what you observed, with the time in the recording, before you discuss it with anyone.
  2. Ask for the next step you would ask of any finalist, a live video call or an in-person meeting, rather than an accusation.
  3. Run your standard identity and reference checks, the same ones every finalist gets.
  4. Decide on the evidence. On Career1 the decision is yours in any case: it ranks and recommends, and rejects nobody.
  5. Report a suspected scheme. The FBI's 2022 notice asks companies to report to IC3 at ic3.gov with any subject information available, such as IP or email addresses, phone numbers and names.

When is Career1 the wrong tool for this problem?

  • You need identity verification or proctoring in the first round. Use a vendor or service that sells it; Career1 does neither.
  • The role handles classified, financial or customer data and is fully remote. Put identity checks and an in-person step before anything else.
  • You hire contractors through a staffing firm. The fraud risk sits with whoever hires them. The FBI's July 2025 notice advises educating the third party about these warnings.
  • Your main problem is volume, not fraud. Then an interview for every applicant is the point, and the process is in what is an AI interviewer and how to screen 200+ applicants.

Where Career1 does fit, its AI recruiter gives every applicant the same eight-minute interview and your team a ranked shortlist with the recording, the transcript and a report behind every score. Plans run from free for two interviews a month to $199 for 150, on the pricing page.

Sources, checked 29 September 2026

Every page below was opened and read on 29 September 2026. Career1 is not affiliated with any company named here.

Left out because the source could not be opened on the day: the widely quoted analyst forecast of the share of fake candidate profiles.

Questions people ask

How do you spot a fake job applicant?

Look for repeats and gaps before the interview: the same phone number or email on several applications, a thin or brand-new profile, photos that appear under other names. In the interview, ask for specifics and follow up. Before the offer, verify employment directly, meet on live video or in person, and compare the person with the first recording. Apply the same checks to every finalist.

What is candidate fraud?

Candidate fraud is an applicant misrepresenting who they are, not just what they can do: a stolen or synthetic identity, a proxy who sits the interview, deepfaked video or a cloned voice. It differs from cheating, such as reading answers from a chatbot, and from ordinary polish. Using AI to tidy a resume is not fraud; inventing experience or an identity is.

What is a proxy interview?

A proxy interview is one where somebody other than the applicant answers the questions, either in their place on camera or by feeding lines. The FBI's July 2025 notice warns that sometimes one person passes the interview and a different person does the job. Keeping a recording or image of the first round and comparing it with every later round is the simplest counter.

How can you tell if a candidate is using a deepfake in a video interview?

The FBI describes lip movements that do not match the audio and coughs or sneezes that are out of step with the picture, and suggests asking the candidate to wave a hand in front of their face. Interrupt with a question that needs thought. None of these is conclusive, because a poor connection produces similar glitches, so confirm with a live call or an in-person meeting.

What did the FBI say about deepfake job applicants?

In June 2022 the FBI's Internet Crime Complaint Center reported an increase in complaints about deepfakes and stolen personal information used to apply for remote jobs, mostly in IT and software. In 2025 it warned that North Korean IT workers use AI and face-swapping in video interviews, and advised identity checks, in-person steps and capturing images to compare across meetings.

What are the warning signs of North Korean IT workers applying for jobs?

The FBI lists reused phone numbers, especially voice-over-IP numbers, and emails across resumes under different names; requests to ship a laptop to an address that is not on the identity documents; frequent bank account changes; remote access software on company devices; and logins from several countries in a short time. Remote technical and contract roles are the usual target.

Are AI-written resumes candidate fraud?

No. Using AI to organise or polish a resume is ordinary now, and treating it as fraud penalises honest applicants. It becomes fraud when the experience, qualifications or identity are invented. That is why the useful check is a question about specifics with a follow-up, not a detector that guesses whether a machine wrote the prose.

Can an AI interview detect a fake candidate?

Not on its own. A conversational AI interview can expose inflated claims, because follow-up questions about a named project are hard to answer from borrowed experience, and a recording lets you compare the person across rounds. Career1 does not verify identity, recognise faces or voices, look for deepfakes or monitor the screen. Identity checks belong before the offer and before access.

Does Career1 verify candidate identity?

No. Career1 does not check identity documents, does not confirm that a new applicant owns their email address before the interview, and does not recognise anyone by face or voice. It records the interview as video with audio and keeps the transcript, which your team can compare with later rounds. Run identity checks through your normal process before an offer.

What should you do if you suspect a fake candidate?

Write down what you saw, with the time in the recording, then ask for the step you would ask of any finalist: a live video call or an in-person meeting. Run your standard identity and reference checks and decide on the evidence. If you suspect an organised scheme, the FBI asks companies to report it to IC3 with any details such as emails, phone numbers and IP addresses.

How common is candidate fraud?

Nobody publishes a reliable rate. In Greenhouse's 2025 survey, 65 percent of US hiring managers said they had caught applicants using AI deceptively and 18 percent reported deepfakes, though the figures are self-reported by a software vendor's respondents. The Justice Department reported schemes that placed North Korean workers with more than 100 US companies.

Should you hold in-person interviews to stop candidate fraud?

For remote roles with access to sensitive systems, at least one in-person step before the offer is the FBI's advice: complete as much of hiring and onboarding as possible in person. For most other roles, a live video call with a finalist, compared against the first-round recording, plus normal identity and reference checks, is proportionate and far cheaper.

Try it on a real role, free

Post a role and every applicant gets an eight-minute spoken interview in the browser, with no scheduling. You get a score, strengths, risks, a recommendation, the transcript and the recording for each one.

The free plan vets two candidates a month and needs no card. Candidates never pay.

Keep reading

All articles

Career1 help

Answers in seconds, any time

Ask anything about Career1. Leave your email so we can reply if the answer needs a person.

Thinking…

Passed to a person. We will reply to .