In a nutshell
- Hidden AI help and identity fraud are different problems. AI help is a real candidate getting assistance. Identity fraud is the person on the call not being who they say they are, or not being the person who'll do the job.
- This is documented, not a moral panic. The FBI has warned about face-swapping in video interviews and helpers who sit interviews on someone else's behalf. The DOJ has prosecuted schemes that placed workers at hundreds of US companies.
- The single most useful habit is free: make sure the same person on your side sees the candidate at more than one stage, and use the earlier conversation as a check.
- Verify in proportion to risk. Cheap consistency checks for everyone, a live ID check before any offer, and stronger checks only for roles with access to production, money or customer data.
- Deepfake checks like a hand wave catch crude tools, not good ones. Consistency across documents, people and time is the stronger defence.
- The signal is inconsistency, never origin. Accents, non-local universities and far-away time zones are not fraud indicators.
How big is the fake candidate problem?
Bigger than most hiring teams assume, though the best numbers are surveys and forecasts rather than audits.
Gartner's 2025 survey of 3,000 job candidates found 6% admitted to interview fraud: posing as someone else, or having someone else pose as them. That's people admitting it, so the real figure is unlikely to be lower. In the same release, Gartner predicts that by 2028 one in four candidate profiles worldwide will be fake. That's a forecast, not a measurement, and it's about profiles, not people who reach interviews.
Pindrop, which sells deepfake detection, analysed applicants to its own remote roles and reported that for one US software engineering role, 6% of candidates had a different person show up for the technical interview than for the first interview. That's one vendor's own funnel, but it's exactly the pattern a proxy interview produces.
CoderPad's 2025 survey adds a recruiter-side view: among recruiters who had seen cheating, 15.5% had seen someone impersonate the candidate. Vendor data again, and it points the same way.
What kinds of identity fraud am I actually defending against?
| Pattern | What happens | Where it tends to show |
|---|---|---|
| Proxy interviewer | A more skilled person takes some or all interviews in the candidate's name | Voice, face or fluency changes between stages; the hire can't do what the interviewee did |
| Bait-and-switch | The real candidate interviews; someone else does the job | Day-one person differs from the interviewee; work patterns shift by time of day |
| Face or voice deepfake | Real-time manipulation hides who is on the call | Lip sync drift; artefacts when they move |
| Stolen or synthetic identity | Someone applies with another person's details | ID doesn't match the face; footprint is thin or recently created |
| Organised fake-worker scheme | A group places workers under false identities, with local helpers receiving laptops and pay | Shipping, payroll and access anomalies after the offer |
These overlap. One scheme can use a stolen identity, a proxy for the interview, and a different person for the work.
What have the FBI and DOJ actually said?
The government record is specific, and worth knowing before you dismiss this as rare.
- In January 2025 the FBI said North Korean IT workers "have been observed using artificial intelligence and face-swapping technology during video job interviews". It recommended identity verification throughout hiring and doing as much of the hiring and onboarding process as possible in person.
- In July 2025 the FBI described US-based facilitators who provide "attendance at virtual interviews and meetings on behalf of North Korean IT workers". Its listed mitigations include in-person meetings where possible, video with an unobscured background, asking the person to wave a hand in front of their face, and capturing images to compare against later meetings, because a different person may do the job than passed the interview.
- In July 2025 the DOJ announced the sentencing of an Arizona woman whose laptop-farm operation helped North Korean workers get jobs at 309 US businesses, using 68 stolen identities and generating more than $17 million. She received 102 months.
- A December 2024 DOJ indictment of 14 North Korean nationals described two front companies employing at least 130 IT workers, with tactics including "paying U.S. persons to attend job interviews and work meetings remotely under fake identities".
Most fake candidates aren't state-sponsored. But those cases show the playbook clearly, and the same checks work for the ordinary proxy too.
How do I spot a proxy interviewer?
Don't look for a face that seems wrong. Look for continuity that breaks.
Rule one: the same person on your side sees the candidate at more than one stage. Ideally the hiring manager joins the first technical conversation and the final round. It costs nothing and it's the most useful habit in this whole article.
At each stage, the interviewer adds one line to their notes:
"Same person as the earlier stage? Yes / Not sure / No. If not sure, what differed: voice, appearance, fluency, memory of the earlier conversation?"
Rule two: use the earlier conversation as a natural check.
"Last time you told me about the rate limiter you built at your last company. I've been thinking about it since. How did you end up handling bursts?"
The real person remembers the conversation and picks it up. A proxy who wasn't there has to bluff, or steer away.
Rule three: ask for detail that a stand-in wouldn't have. Proxies are usually strong on technique and weak on biography. Ownership questions ("What was the table called? Who reviewed that PR? What did they push back on?") are where they thin out. That's the same follow-up method I describe in technical interview follow-up questions.
How do I check for a deepfake on a live call?
Ask for movement and occlusion. Real-time face swaps have historically struggled with profile views, objects crossing the face, and lighting changes.
"Sorry, the video's a bit odd on my end. Could you turn your head to the side for a second? Great. And could you wave your hand slowly in front of your face? Thanks, that's sorted it."
| Check | What a crude deepfake may do | Innocent cause of the same artefact |
|---|---|---|
| Head turned fully to the side | Face edges warp or snap back to frontal | Background blur clipping the head |
| Hand passed in front of the face | Hand vanishes into the face, or face renders over it | Low frame rate, blur filter |
| Lighting change | Skin tone doesn't respond | Webcam auto-exposure |
| Cough or laugh | Lips and audio drift apart | Network lag, which delays everything equally |
Be honest about the limits. These checks catch crude tools, and the tools improve every year, so a pass tells you little. Background blur and weak bandwidth produce the same artefacts, so one glitch means nothing. And a real face can be paired with a proxied voice. Use these as hygiene when something looks off, and rely on consistency checks to establish identity.
What does proportional identity verification look like?
Match the check to the stage and to the access the role will have. Cheap checks early for everyone, stronger checks only once you're serious, strongest checks only where a fraudulent hire would do real damage.
Tier 0: everyone (minutes, no tools)
- [ ] Name, location and time zone match across application, CV, LinkedIn, GitHub and email
- [ ] Employers and dates on the CV match LinkedIn
- [ ] Search your applicant tracking system for duplicate CV text, phone numbers or emails across "different" applicants
- [ ] Five-minute footprint check: profile history older than a few months, work you can trace
- [ ] Same interviewer sees the candidate at two or more stages, with the "same person?" line in notes
Tier 1: every finalist, before an offer
- [ ] Live ID-on-camera check, announced in advance as routine, with no copy kept
- [ ] Location, time zone and contract address consistent
- [ ] Two references you found and verified yourself, not just the contact details supplied
- [ ] A signed statement that the candidate did their own interviews
Tier 2: roles with production, payments, customer data or admin access
- [ ] An in-person meeting, or third-party document and liveness verification
- [ ] Background check with the notice and consent your jurisdiction requires
- [ ] Laptop shipped only to the verified address, signed for in the hire's name
- [ ] Payroll into an account in the hire's legal name, no crypto or third-party accounts
- [ ] Least-privilege access until a 30-day validation period is complete
A thin footprint on its own is not a red flag. Plenty of excellent engineers have private GitHub accounts and dormant LinkedIn profiles. Thin footprint plus inconsistency is worth a closer look.
One legal note, and this isn't legal advice: anything that captures face geometry or other biometrics can trigger consent rules. Illinois' biometric privacy law, for example, requires written consent. Have counsel review any ID or face-matching tool before you use it.
For a live ID check, this wording keeps it routine rather than pointed:
"Before we make an offer, we do a quick identity check with every finalist. Could you hold your photo ID up to the camera, next to your face, for a few seconds? I'll just confirm the name and photo match. We don't screenshot or keep a copy."
What red flags show up after the offer?
Organised schemes are often easiest to see in logistics, not interviews:
- A last-minute change of address, especially for equipment delivery
- A request to ship the laptop to a friend, relative or freight forwarder
- A preference for a personal device over the company laptop
- A bank account in a different name, or a request for crypto payment
- Remote-access software on the company laptop, or logins from several countries in a short window
- Camera always off after joining, when it was on throughout interviews
Any one of these has innocent explanations. Several together deserve a pause.
What should I do if I suspect fraud?
Don't confront. Pause, preserve, verify, escalate.
- Pause with a neutral message.
"Thanks for your time on Tuesday. We're finalising a few internal steps before the next stage and will be in touch by Friday."
- Preserve records: application, emails, calendar invites, interviewer notes.
- Verify independently: call previous employers through their main lines, and check whether the CV appears under another name in your system.
- Request a verification step that's already in your published process, such as the Tier 1 ID check or an in-person meeting. Genuine candidates usually agree. Fraudulent ones often disappear.
- Escalate when you have more than a hunch. Talk to counsel before rejecting on fraud grounds, and ask them about reporting to law enforcement, such as the FBI in the US.
If the person already works for you, revoke access before any conversation that could tip them off.
How do I stay fair while doing this?
Apply every check to everyone at the same tier, and tell candidates up front:
"Because we hire remotely, we verify identity for every finalist. Before an offer, we'll ask you to show a photo ID on camera and we'll speak to two references. Everyone at the same stage goes through the same steps."
That last sentence tells strong candidates they aren't being singled out, and the consistency protects you if a decision is challenged. Never single someone out for an accent, a name, a university or a time zone. The signal is inconsistency, not origin.
What should I do next?
Put the verification steps into your written process and your AI interview policy, so they read as routine. Run the free cheat-risk audit to see where identity checks are missing from your loop. For the related problem of real candidates getting hidden help, see how to detect AI cheating in interviews, and for recruiters running first screens, how to screen developers as a non-technical recruiter.
The printable tiered checklist, candidate emails for verification steps, and a 30-day validation plan are part of Unscripted, the paid kit, if you'd like them ready to use.