Guide

The candidate on your video call might not exist

38.5% of interviews now show AI-cheating behavior and 41% of companies have hired a fake. How to verify candidates at every stage, from sourcing to offer.

In early 2025, Pindrop posted a single opening for a developer and watched what came in. Out of 827 applications, roughly one in eight was fake, including a candidate the team nicknamed "Ivan X," whose face on the video call was stitched together by deepfake software (Fortune, April 2025). Pindrop detects voice fraud for a living. They caught Ivan. Most hiring teams would not have.

That is the uncomfortable baseline for 2026: candidate fraud stopped being an edge case and became a volume problem. This guide covers what the fraud actually looks like, the numbers behind it, and a verification playbook that works at each stage of your funnel.

The numbers, as of mid-2026

Across 19,368 live interviews analyzed between July 2025 and January 2026, 38.5% of candidates were flagged for AI-cheating behavior, and the rate tripled from 9% to 45% in a single three-month stretch (Fabric, 2026). Software engineering interviews hit 48%, against 12% in sales. Worse: 61% of the flagged candidates still cleared the assessment bar and would have advanced with no detection at all.

Identity fraud is rarer but growing faster. Deepfake attempts in hiring jumped 1,300% year over year, per Pindrop's 2025 Voice Intelligence Report. In a Greenhouse survey of 4,136 respondents, 31% of hiring professionals said they had already interviewed someone they suspected or confirmed was using deepfake technology (People Management, 2025). In a Gartner survey of 3,000 job seekers, 6% admitted to full identity fraud, either impersonating someone or having someone interview in their place. Gartner now projects that by 2028, one in four candidate profiles worldwide will be fake.

The defense side is not keeping up. Only 31% of companies run any deepfake detection software and 48% of HR professionals have had zero training on AI-driven hiring fraud, per a Software Finder survey of 874 HR professionals (StudyFinds, 2025). The result: 41% of organizations have unknowingly hired a fraudulent candidate, according to GetReal Security.

One more number, because it kills the most common objection. In a 2025 meta-analysis of 56 studies, humans detected deepfakes with 55.54% accuracy. Your gut is a coin flip.

The four layers of candidate fraud

Not all of this is the same crime, and each layer needs a different response. It helps to sort what you are facing into four escalating layers.

Layer What it is Scale in 2026 Main risk
1. Assisted answers A real candidate feeding your questions to an AI tool live 38.5% of interviews flagged (Fabric) You assess the AI, not the person
2. Fabricated credentials Invented employers, degrees, portfolios, AI-generated work samples 72% of recruiters have seen AI-fabricated resumes (Software Finder) Wasted funnel, bad hires
3. Proxy interviews A different person takes the interview, the hire shows up on day one Part of the 6% admitting identity fraud (Gartner) Skills gap surfaces after start
4. Synthetic identity Deepfake video, cloned voice, invented persona, often for infiltration or wage fraud Attempts up 1,300% YoY (Pindrop) Security breach, sanctions exposure

Layer 4 deserves its own paragraph, because it is not hypothetical. In December 2024 the US Justice Department indicted 14 North Korean nationals who spent six years working US remote jobs under false identities and funneled at least $88 million to the regime. Pindrop's research puts deepfake use at one in four North Korean IT applicants. Gartner's advice to clients hiring for remote IT roles is blunt: assume at least half the applications are not real.

Treat fraud as a funnel problem

The mistake most teams make is treating fraud as an interview problem. By the time a fake is on your video call, they have already cost you sourcing effort and pipeline slots. Verification works better as a filter at each stage.

At sourcing: choose candidates, don't collect applicants

Everything in the fraud data points one direction: fraud rides the inbound flood. Pindrop's fake applicants came through a job posting. The North Korean operations blanket remote listings at industrial scale. Outbound sourcing flips the exposure, because you pick the profile first, and a profile with a decade of consistent history is far harder to counterfeit than one resume PDF.

Cross-source consistency is the cheapest verification you will ever run. A real senior engineer leaves a long, coherent trail: employment history that matches across platforms, conference talks, code contributions, colleagues who overlap at named companies. A synthetic persona is usually thin in exactly this way, a profile that exists in one place, created recently, with no third-party corroboration. This is one reason sourcing from aggregated profiles beats screening inbound resumes right now: Glozo builds each profile from 30+ independent sources, so contradictions and thin trails surface before you spend a minute on outreach.

At the screen: make the conversation unscriptable

AI assistance thrives on predictable questions. "Tell me about a time" prompts are exactly what an overlay tool answers well. What it handles badly is specificity and backtracking: ask which team the candidate sat on, who they handed work to, what broke in production and what they did at 2 a.m. Then loop back ten minutes later and ask the same fact from a different angle. Real memories are consistent; generated ones drift. The same probing logic behind interview questions that predict performance doubles as fraud detection, which is a nice two-for-one.

Keep cameras on from the first screen, and treat refusal as a data point. Not proof of anything, but a reason to add verification later, alongside the classic pre-interview red flags.

At the live interview: layer physical checks, don't worship them

The folk tests you have read about, asking a candidate to turn their head, wave a hand in front of their face, or hold up three fingers, exploit rendering glitches in older deepfake models. They still catch lazy fakes. They will not catch good ones, and the vendors building detection say the gap closes every quarter. Use them as one cheap layer, not as clearance.

Stronger signals live in behavior. Karat's analysis of technical interviews flags frequent screen-switching, long pauses followed by suspiciously polished answers, and code written perfectly with no iteration. Candidates who never think out loud, never make small errors, and never revise are performing, not solving. For high-stakes finals, do what Google, McKinsey, Deloitte and Cisco did and bring the round in person; in-person interview requests jumped from 5% of roles in 2024 to 30% in 2025 largely as a fraud response (Computerworld, 2025).

Before the offer: check identity and source references yourself

Reference checks still work, with one condition: source the referee yourself. A fraudulent candidate hands you a phone number attached to an accomplice. Find the claimed manager independently and the accomplice never enters the loop; the approach in our reference check guide for solo recruiters covers how to do this without burning confidentiality. For remote hires, add a documented identity check matching the person on the call to a government ID. It feels heavy until you remember that 41% of companies have already hired a fake.

One thing not to do: quietly hand the whole problem to an AI screening tool. Automated fraud detection sits inside the same legal constraints as AI resume screening, including notice requirements in several states, and a false accusation of fraud is a fast way to lose a real candidate. Keep a human decision at the end of every flag. The judgment call is one of the parts of this job that automation does not own.

The agency angle: you warrant the candidate

If you run a desk, a placed fake is not the client's problem alone. Your fee, your guarantee period, and your relationship absorb the hit, and in the North Korean scenario a placement can create sanctions exposure for the client you introduced. Two practical moves: write your verification steps into your client agreements as a differentiator, and when a placement is exposed as fraudulent, notify the client immediately and involve counsel before negotiating the fee. Agencies that can show a documented verification process will win business from the 48% of HR teams that have had no fraud training at all.

Frequently asked questions

How common are fake job candidates in 2026?
Common enough to plan around. 38.5% of 19,368 live interviews analyzed between July 2025 and January 2026 showed AI-cheating behavior, 31% of hiring professionals say they have interviewed a suspected deepfake, and 41% of organizations have unknowingly hired a fraudulent candidate. Gartner projects one in four candidate profiles worldwide will be fake by 2028.
What is the three-finger test for deepfake candidates?
It is a quick physical check where the interviewer asks the candidate to hold up three fingers, wave a hand in front of their face, or turn their head. Older deepfake models glitch when rendering occluded or fast-moving faces. It catches low-effort fakes but modern deepfake tools increasingly pass it, so treat it as one cheap layer in a broader verification process, not as proof.
Which roles do deepfake and fake candidates target most?
Remote technical roles. Software engineering interviews showed a 48% AI-cheating rate versus 12% in sales, and Gartner advises employers to assume at least half of applications for remote IT positions are false. Fully remote, high-salary, laptop-only roles are the primary target because the fraud never has to survive an in-person meeting.
Can you spot a deepfake just by watching the video?
Mostly no. A 2025 meta-analysis of 56 studies found humans detect deepfakes with 55.54% accuracy, barely better than chance. Behavioral signals are more reliable: screen-switching, polished answers after long pauses, no thinking out loud, and inconsistencies when the same fact is probed twice from different angles.
What should a recruiting agency do if it placed a fraudulent candidate?
Notify the client immediately, support terminating access fast (a fraudulent hire with system access is a security incident and should be handled like one), and involve legal counsel before settling fee questions, especially if there are signs of an organized scheme. Then fix the gap: document which verification step would have caught it and add that step for every future placement.