Candidate Fraud in Remote Hiring: How to Spot Fake Candidates Without Treating Everyone as a Suspect
How common fake candidates, proxy interviewers and deepfake video are, the warning signs at each hiring stage, and proportionate checks that stay fair.
By the HireRabbit.AI team · Published · Last updated
On this page
This article is general information for HR teams and hiring managers, not legal advice. Identity checks, background checks, recording and the handling of ID documents are regulated differently by country, state and sometimes city. Check your plan with employment counsel and your privacy lead before you roll it out.
The problem often surfaces a few weeks after a start date, when a manager messages HR: the person on the team calls sounds different from the person they interviewed, can't do things they explained clearly in the technical round, and keeps their camera off. Sometimes it turns out to be a nervous new hire with a bad microphone. Sometimes the person who interviewed and the person doing the job really are two different people, and occasionally neither of them is the name on the offer letter.
This guide covers how often this happens, the warning signs at each stage of a remote hiring process, proportionate checks, and how to run them without making honest candidates feel accused.
What the evidence says about scale
In a July 31, 2025 release, reported by HR Dive in August 2025, Gartner predicted that by 2028, one in four candidate profiles worldwide could be fake. The same research included a survey of 3,000 job candidates in which 6% said they had taken part in interview fraud, either posing as someone else or having someone else pose as them. Present the 2028 figure as a forecast. The 6% figure is self-reported, which probably makes it an undercount.
Greenhouse's AI in hiring report, published November 19, 2025, surveyed 4,136 people across the US, UK, Ireland and Germany, including 1,236 recruiters and hiring managers. Among its findings: 91% of US recruiters said they had spotted candidate deception, 65% of hiring managers had caught applicants using AI deceptively, and 18% had seen candidates appear as deepfakes. On the candidate side, 36% of US job seekers said they had altered their appearance, voice or background during video interviews. That last figure covers everything from a blurred kitchen to a voice filter, so read it as a measure of how common video filters are. It is not a fraud rate.
The FBI's Internet Crime Complaint Center (IC3) first warned about this in a public service announcement on June 28, 2022. It reported an increase in complaints about deepfakes and stolen personal information being used to apply for remote roles, mostly in IT, programming and database work. In some cases pre-employment background checks found that the details an applicant supplied belonged to someone else. The same PSA described a visible sign: the actions and lip movement of the person on camera did not fully line up with the audio.
The best-documented schemes involve North Korean workers using stolen or borrowed US identities to get remote jobs. On June 30, 2025, the US Department of Justice announced coordinated actions that included searches of 21 suspected "laptop farms" across 14 states. According to the DOJ, the workers involved had obtained jobs at more than 100 US companies using more than 80 stolen US identities. A month later, on July 24, 2025, the DOJ announced that an Arizona woman, Christina Chapman, had been sentenced to 102 months in prison for running a laptop farm from her home. That scheme reached more than 300 US companies, used 68 stolen identities and generated more than $17 million for her and for North Korea. She also shipped 49 company laptops overseas.
Organized schemes aimed at remote technical roles are proven and prosecuted. Smaller deception, such as an inflated work history or a stand-in for a technical round, is common enough that 91% of US recruiters in the Greenhouse survey reported spotting deception of some kind. Nobody has a reliable figure for how many hires overall are fraudulent, and you should be suspicious of anyone who claims one.
Who is most exposed
You don't need the same controls for every job. The FBI and DOJ material points to the same risk profile again and again: fully remote roles, technical work, access to source code, customer data, financial systems or internal networks, and a company laptop shipped to a home address. Contractor roles filled through third-party staffing firms appear often too, because the employer never meets the worker directly. A fully remote senior engineer with production access needs more checks than a hybrid office coordinator.
Warning signs at each stage
A single sign rarely means fraud. People move, change phone numbers, have thin LinkedIn profiles, and freeze in interviews. What should get your attention is a cluster of signs, or a sign that contradicts something the candidate told you earlier.
At application
The FBI's January 23, 2025 PSA on North Korean IT workers suggests checking your applicant tracking system for applicants who share resume content or contact details, and reviewing resumes for typos and unusual naming. In practice that means near-identical project descriptions across applications, the same phone number under different names, or a portfolio link that points to someone else's work. A stated location that never matches the time zone the candidate replies from is worth noting too. None of these justify rejection by themselves. They justify a normal follow-up question, such as which team the person worked on at a named employer.
During interviews
The IC3's 2022 PSA described audio and lip movement that don't line up, and coughs or sneezes that don't appear on screen. Its May 16, 2024 PSA added two more practical signs: applicants who can't answer basic questions about where they are located, and background noise that sounds like the person is surrounded by others doing similar work. The 2025 PSA also mentions the use of face-swapping technology during video interviews.
Proxy interviewing leaves different traces. The person in the technical round may sound different from the person on the recruiter screen, and a proxy asked to walk through a decision on a listed project tends to give a generic answer, because they didn't do the work.
Be careful here. Pauses, a flat delivery and poor video are also what you get from someone who is nervous, neurodivergent, speaking a second language, or on a weak connection. Treat interview signs as reasons to add a verification step, and never as a finding in themselves.
At offer and onboarding
This is where the FBI's advice gets most specific. The May 2024 PSA tells employers to watch for changes of address after a person is hired but before the laptop is delivered. The January 2025 PSA adds changes to payment platforms during onboarding. Other late signs include a request to ship equipment to a freight forwarder or a "relative's" address, a new hire who wants pay sent to an account in another name, and bank or payroll details that change within the first few pay cycles.
After the start date, the FBI's signs shift to IT: logins from several countries within a short time, and remote desktop tools the company didn't install.
Proportionate checks by stage
The goal is to add friction where fraud is most expensive and least likely to hurt honest candidates. Identity verification at the offer stage, for example, costs a genuine candidate ten minutes and happens after you have already decided you want them. Demanding a passport scan before a first screening call asks strangers to hand over sensitive documents for a job they may never be offered.
| Stage | Warning sign | Proportionate check |
|---|---|---|
| Application | Duplicate resumes, shared phone numbers or emails across different names | Deduplicate in your ATS; ask a normal follow-up question about a listed employer or project |
| Recruiter screen | Location answers that don't match time zone or earlier messages | Confirm city and work authorization verbally, and note the answer for later comparison |
| Technical interview | Voice or knowledge noticeably different from the earlier screen | A live exercise where the candidate talks through their own reasoning, with the same interviewer across two rounds where possible |
| Video interviews generally | Audio and lip movement out of sync; coughs or sneezes that don't appear on screen | A camera-on policy stated in the invitation, with accommodations offered; a short in-person or verified video step for high-risk roles |
| References | References reachable only by personal email or messaging apps | Contact references through the company's main switchboard or a verified work address |
| Offer | Identity details that don't match earlier information | Identity document check against a live person before the offer is final, using a consistent, disclosed process |
| Pre-start | Shipping address changes after the offer; freight forwarder addresses | Ship only to the verified home address, or require in-person pickup for high-risk roles |
| Payroll setup | Account in another person's name; early changes to bank details | Verify bank account ownership matches the employee; add a callback step for any payroll change |
| First weeks | Logins from several countries; unexpected remote desktop software | IT monitoring under your existing acceptable use policy; least-privilege access until probation checks are done |
Live skills exercises. A take-home test tells you someone produced a correct answer. A live exercise, where the candidate shares their screen and talks through a small problem, tells you the person in front of you can do the work. Tell candidates the format in advance. If the same interviewer runs the technical round and a later conversation, a swap between rounds becomes much harder.
Camera and ID policies stated up front. If you require cameras on for interviews, say so in the interview invitation, along with the reason and who to contact about accommodations. The same applies to ID checks at offer: tell candidates when it happens, what documents are accepted, who sees them and how long they are kept. Stating the rule up front means you never have to single anyone out in the moment.
References done properly. A call to a number the candidate supplied reaches whoever the candidate chose. For high-risk roles, find the previous employer's main number yourself and ask for the named manager, or at least confirm dates and title through their HR team.
Employment eligibility and background checks. In the US, the FBI's 2024 PSA points employers to E-Verify for remote workers' identity details. Background checks run through a screening company usually come with notice and consent requirements, and the rules differ by state and outside the US.
Device and payroll checks at onboarding. These are often the cheapest controls and the most effective against organized schemes, because laptop farms depend on company equipment being shipped somewhere the worker is not. Ship equipment only to an address you have verified, match the payroll account holder to the employee, and treat an early request to change either one as a reason for a phone call.
How to avoid treating honest candidates as suspects
Almost everyone who applies to your jobs is who they say they are. A fraud program that treats all of them as suspects will cost you good candidates, and it creates its own legal risk if checks land more heavily on people with foreign names, accents or non-US education. The FBI lists claims of non-US education as a red flag in the North Korean context. That doesn't make every internationally educated applicant a risk, and a process that acts as if it does will hurt real people.
Four habits keep the checks fair:
- Disclose the checks. Put identity verification, camera expectations and reference methods in your job posts or interview invitations. Gartner's own recommendation, as reported by HR Dive, includes telling candidates about your fraud detection efforts. Honest candidates barely notice; people planning fraud often drop out.
- Apply them to everyone in the same role. Decide the checks per role and apply them to every candidate at that stage. Ad hoc checks triggered by a recruiter's gut feel are where bias gets in.
- Offer accommodations. Some candidates can't use a camera reliably, have a disability that affects speech or sight, or live somewhere without a good connection. Give a named contact and an alternative, such as a phone call followed by a verified ID check, or an in-person meeting.
- Separate a signal from a decision. When something looks off, the next step is a documented verification step, reviewed by a person who knows the role. Nobody should be rejected because a tool or a single interviewer flagged them.
The same applies to software: a tool's output should go to a person for review, with the candidate's knowledge. As one example, the AI Interviewer in HireRabbit.AI shows candidates a consent screen before a spoken first-round interview starts, and its integrity flags for eye, body or hand movement go to a person to review and never change the candidate's score. More detail is on the AI Interviewer page.
A short incident response plan
Write this plan before you need it, agree it with IT, legal and payroll, and keep it to a page.
- Don't confront the person yet. If this is an organized scheme, a warning gives them time to copy data or wipe devices.
- Bring in security and legal quietly. Security should review access logs, remote access tools and data movement on the person's accounts. Legal should advise on next steps before anyone acts.
- Limit access in a planned way. Reduce privileges, rotate shared credentials the person could reach, and secure code repositories and customer data. Coordinate the timing so it happens together.
- Preserve evidence. Keep interview recordings, application records, onboarding documents, shipping records, payroll changes and device logs. Don't delete anything, including the fraudulent identity documents.
- Freeze payroll changes for the account and review where payments have already gone.
- Report it. In the US, the FBI asks companies and victims to report this activity to the IC3 at ic3.gov. If you used a staffing firm, notify them. If a real person's identity was stolen, they may need to be told, and legal should advise on how.
- Review what failed. Look at which stage the person passed that should have stopped them, and whether a check existed but wasn't applied. Fix the process first and punish people last.
Onboarding checks are where the prosecuted schemes were most exposed. In the Chapman case, the DOJ says investigators seized more than 90 laptops from her Arizona home, sent there by companies that believed their new hires were working in the United States.
Sources
- FBI Internet Crime Complaint Center, Deepfakes and Stolen PII Utilized to Apply for Remote Work Positions (Jun 2022): https://www.ic3.gov/PSA/2022/psa220628
- FBI Internet Crime Complaint Center, DPRK Leverages U.S.-Based Individuals to Defraud U.S. Businesses and Generate Revenue (May 2024): https://www.ic3.gov/PSA/2024/PSA240516
- FBI Internet Crime Complaint Center, North Korean IT Workers Conducting Data Extortion (Jan 2025): https://www.ic3.gov/PSA/2025/PSA250123
- US Department of Justice, Justice Department Announces Coordinated, Nationwide Actions to Combat North Korean Remote IT Workers (Jun 2025): https://www.justice.gov/opa/pr/justice-department-announces-coordinated-nationwide-actions-combat-north-korean-remote
- US Department of Justice, Arizona Woman Sentenced for $17M Information Technology Worker Fraud Scheme (Jul 2025): https://www.justice.gov/opa/pr/arizona-woman-sentenced-17m-information-technology-worker-fraud-scheme-generated-revenue
- HR Dive, By 2028, 1 in 4 candidate profiles will be fake, Gartner predicts (Aug 2025): https://www.hrdive.com/news/fake-job-candidates-ai/757126/
- Gartner, Gartner Survey Shows Just 26% of Job Applicants Trust AI Will Fairly Evaluate Them (Jul 2025): https://www.gartner.com/en/newsroom/press-releases/2025-07-31-gartner-survey-shows-just-26-percent-of-job-applicants-trust-ai-will-fairly-evaluate-them
- Greenhouse, An AI Trust Crisis: 70% of Hiring Managers Trust AI to Make Faster and Better Hiring Decisions, Only 8% of Job Seekers Call it Fair (Nov 2025): https://www.greenhouse.com/newsroom/an-ai-trust-crisis-70-of-hiring-managers-trust-ai-to-make-faster-and-better-hiring-decisions-only-8-of-job-seekers-call-it-fair