Home
Blog
Deepfake Job Candidates: How AI Is Being Used to Fake Remote Interviews

Deepfake Job Candidates: How AI Is Being Used to Fake Remote Interviews

Reviewed by
Table of Contents

Key Takeaways

Picture this: a candidate shows up to a video interview, answers every question well, and looks exactly like their LinkedIn photo. You move them to the next round. Later, you find out that person was never really there.

This is the new face of hiring fraud. Scammers are now using AI-generated video and voice tools to impersonate other people in real time during remote job interviews. The technology isn't theoretical. It's already inside hiring pipelines at companies of all sizes, and most hiring managers aren't trained to spot it.

According to Checkr's 2025 Hiring Hoax Survey of 3,000 hiring managers, 31% have already unknowingly interviewed a fake candidate. GetReal Security found the problem goes further: 41% of organizations have unknowingly hired one.

This isn't just a headache for HR. It's a security problem.

What are deepfake job candidates?

A deepfake job candidate is someone who uses AI to change how they look and sound during a video interview. The technology, called a face swap or real-time deepfake, overlays a different person's face onto the scammer's webcam feed. More advanced setups also clone the voice of the person being impersonated, using just a few minutes of sample audio.

The fraudster shows up on your Zoom or Teams call looking and sounding like whoever they claim to be. They've got a matching LinkedIn profile and a polished resume. On a standard video call, the result can be convincing enough to fool a trained recruiter.

The tools to do this aren't expensive or hard to find. Some are free. Most require zero technical skill.

Motives vary, but they fall into a few clear categories. Some people fake their identity to land a role they're not qualified for. Others are part of organized fraud rings targeting companies for financial gain or data theft. The most alarming cases involve state-sponsored operations, with North Korean IT workers using stolen American identities to infiltrate US tech companies, earning salaries that fund the regime and exfiltrating sensitive data in the process.

How serious is this problem?

The scale has grown fast. Pindrop's 2025 Voice Intelligence and Security Report, which analyzed over 1.2 billion calls, found that deepfake fraud attempts rose by more than 1,300% in 2024, jumping from an average of one attempt per month to seven per day.

Gartner has issued an even sharper warning about where this is headed. The research firm predicts that by 2028, one in four job candidate profiles worldwide will be fake.

The FBI saw this coming. In June 2022, the FBI's Internet Crime Complaint Center (IC3) issued its first public warning about the use of deepfakes and stolen personally identifiable information (PII) to apply for remote jobs. Complaints spiked shortly after the warning was published, and the problem has grown steadily since.

Remote work is the fuel here. When interviews happen over video instead of in person, there's no physical presence to anchor identity. That gap is exactly what fraudsters are exploiting.

What's at stake if a fake candidate gets hired?

A bad hire is always costly. A fraudulent one can be catastrophic for your data.

Once inside, a fake employee has the same access as a legitimate one: internal systems, customer data, source code, financial records. A scammer hired for an IT or software engineering role can move laterally through a network, steal intellectual property, or plant vulnerabilities for later use.

The North Korea angle illustrates the stakes clearly. The US Department of Justice has brought multiple cases against networks of DPRK operatives who used fake identities to get hired at American technology companies. Once inside, they sent portions of their salaries back to North Korea and used their access to steal data.

This isn't abstract. Companies that hired these workers had no idea until federal investigators showed up.

Beyond data risk, there's also direct financial exposure. If a fake employee commits fraud using company systems, the liability trail leads back to the organization that hired them.

How to spot a deepfake in a video interview

Current face-swap technology has real limitations. Knowing what breaks it gives you practical tools to catch fakes before they get through.

Watch for visual glitches. Deepfake overlays struggle with edges. Look for blurring around the hairline or jaw, unnatural skin texture, or lighting that doesn't match the background. If the face seems to "float" slightly off the body, that's a signal.

Listen for audio inconsistencies. A cloned voice can sound slightly robotic or show a lag between lip movement and sound. Ask the candidate to say something unexpected and watch whether their mouth and the audio stay in sync.

Ask them to move. This is one of the most reliable tests. Ask the candidate to place a hand in front of their face, turn their head fully to one side, or lean toward the camera quickly. Current face-swap tools have trouble tracking fast or unusual movement. A genuine candidate does this without hesitation. A fake one often freezes, pixelates, or produces a distorted image.

Go off-script. Deepfake operators are often working from scripts. Ask something spontaneous that requires a real, unrehearsed answer. If the candidate gives a polished, generic response to a question like "what did you do last weekend?" that's worth noting.

Require government ID verification. Video interviews should be paired with verified identity documents, not just a LinkedIn profile. Cross-reference the name, face, and credentials independently before making any offer.

Check the technical setup. Deepfake tools sometimes create unusual CPU load or require specific video software. Asking candidates to share their screen briefly or switch to a different video tool can disrupt the overlay.

What this means for everyday people

Most coverage of this topic focuses on employers. But there's a consumer angle worth paying attention to.

The stolen identities used by deepfake candidates belong to real people. If your personal information, your name, photo, professional history, has been exposed in a data breach, it can end up powering someone else's fake job application. You might have no idea your identity is being used to interview for jobs across the country.

This is one reason why monitoring what's exposed about you online matters. Knowing what personal information is out in the open gives you a chance to act before someone else uses it against you.

What companies can do right now

The detection steps above help during an interview. But the most effective filters happen before the video call even starts.

  • Source from verified platforms. Candidates from verified professional databases carry an established identity baseline. That filters out many fraudulent applicants before anyone opens a video link.
  • Run background checks that include identity verification. Traditional background checks verify employment history. Identity verification confirms the person is who they say they are.
  • Train hiring managers. Most recruiters have never heard of deepfake interviews. Brief awareness training on what to look for dramatically improves detection rates.
  • Build in a live-interview requirement. Async video interviews, where candidates submit pre-recorded answers, can't be tested with the movement-based techniques above. For any sensitive role, require a live synchronous call.
  • Flag anomalies in the technical setup. Any candidate who refuses to share a webcam, cites persistent "connection issues," or insists on a text-only format for video-capable interviews is worth a second look.

Conclusion

The hiring process has always had gaps. Remote work widened those gaps considerably, and AI tools have made them easy to exploit. Deepfake job candidates aren't a future risk. They're already in your pipeline.

The good news is that the technology still has detectable weaknesses. A few deliberate steps during an interview, combined with identity verification before the call, catch most fakes. The organizations getting blindsided are the ones that haven't updated their process to account for the fact that seeing is no longer the same as believing.

Get a free security scan with Guardio today and stay protected.

CMS-based CTA:
Add Guardio to BrowserTake Security Quiz
Default CTA:
Smart protection, built for how you live online
Stay ahead of threats with real-time insights and proactive protection.
Add Guardio to BrowserTake Security Quiz
CMS-based "Did you know?" block
Did you know?
Default "Did you know?" block
Did you know?

Make sure you have a personal safety plan in place. If you believe someone is stalking you online and may be putting you at risk of harm, don’t remove suspicious apps or confront the stalker without a plan. The Coalition Against Stalkerware provides a list of resources for anyone dealing with online stalking, monitoring, and harassment.

Guardio Security Team
Guardio’s Security Team researches and exposes cyber threats, keeping millions of users safe online. Their findings have been featured by Fox News, The Washington Post, Bleeping Computer, and The Hacker News, making the web safer — one threat at a time.
Tips from the expert

Related articles

FAQs

How can you tell if someone is using a deepfake in a job interview?

Ask the candidate to place a hand over their face, turn their head sideways, or respond to a sudden unexpected question. Current deepfake face-swap tools struggle with fast or unusual movement, often producing blurring, distortion, or a freeze frame. Other signals include lip-sync delays, blurry edges around the hairline or jaw, and overly scripted answers to spontaneous questions.

Are deepfake job interviews actually happening?

Yes. Checkr's 2025 Hiring Hoax Survey of 3,000 hiring managers found that 31% have already interviewed a fake candidate. GetReal Security reports that 41% of organizations have unknowingly hired a fraudulent candidate. The FBI issued its first public warning about this tactic in June 2022, and the problem has grown significantly since.

What do deepfake job candidates want?

Motives vary. Some fake their identity to land a job they're not qualified for. Others are part of organized fraud rings targeting access to company data or financial systems. The most serious cases involve state-sponsored schemes, including North Korean IT workers who use stolen American identities to infiltrate US technology companies and channel earnings and stolen data back to the regime.

How common will fake job candidates become?

Gartner predicts that by 2028, one in four job candidate profiles worldwide will be fake. Deepfake fraud attempts already rose 1,300% in 2024 according to Pindrop's 2025 Voice Intelligence and Security Report, jumping from an average of one attempt per month to seven per day. The pace shows no sign of slowing.

Can my identity be used in a deepfake job application without my knowledge?

Yes. Many deepfake job scams rely on stolen personal information from data breaches, including names, photos, and professional histories. The real person whose identity was taken often has no idea their details are being used to interview for jobs at other companies. Monitoring your digital exposure can help you catch this early and take action.

What should companies do to prevent hiring a deepfake candidate?

Combine live video interviews with movement-based tests, government ID verification, and background checks that confirm identity rather than just employment history. Source candidates from verified platforms where possible, and train hiring managers to recognize the visual and behavioral signals that deepfake tools produce.

Table of Contents
Can You Spot a Scam Text Message?
Test your skills and learn how to protect yourself from online scams.
Take the quiz now
Can You Spot a Scam Text Message?
Test your skills and learn how to protect yourself from online scams.
Take the quiz now