← Back to blog
Adrian PascualBy Adrian PascualHiring insightPublished
Why Interview Fraud Is Increasing: What HR Needs to Know

Why Interview Fraud Is Increasing: What HR Needs to Know

Interview fraud is rising because accessible AI tools, remote hiring norms, and organized criminal and nation-state actors have converged to make deception cheaper, faster, and harder to catch than at any previous point in hiring history. Standard resume screens, phone calls, and even video interviews no longer provide reliable verification on their own. Here is what you can do in the next 24–72 hours:

  • Require verified government ID for any high-risk or remote-access role before advancing a candidate past the screening stage.
  • Enable liveness checks in virtual interviews: ask candidates to pan the camera to show their surroundings, or use a platform that captures liveness metadata automatically.
  • Flag remote-only applicants for additional verification steps, particularly for roles with system access, financial authority, or sensitive data.
  • Audit your ATS filters for signs of mass-generated applications: near-identical phrasing, suspiciously high keyword density, or application timestamps clustered within seconds of each other.

The sections below cover the full picture: how large the problem is, what forms it takes, why it is accelerating, how to detect it, and exactly what to do when you find it.

Key Takeaways

Interview fraud is rising because AI tools, remote hiring, and organized actors have simultaneously lowered the cost of deception and expanded the attack surface, making layered identity and behavioral verification a necessity for any organization hiring at scale.

PointDetails
Scale of the threatGartner projects 1 in 4 candidate profiles could be fake by 2028; 6% of candidates already admitted impersonation.
Most dangerous fraud typeNation-state and organized schemes use deepfakes and impersonation to gain system access, not just employment.
Detection requires layersNo single check is sufficient; combine ATS fraud scoring, identity verification, liveness checks, and behavioral review.
Verify early, not lateIdentity verification must happen before the first live interview, not after an offer is extended.
Evy's role in the stackEvy's real-time eye tracking and automated scoring address both volume screening and behavioral fraud detection.

Table of Contents

How big is the problem? Key statistics and trends HR should know

The numbers are striking enough that several major research and advisory organizations have issued formal warnings. Gartner projects that by 2028, one in four candidate profiles worldwide could be fake. That is not a distant threat: the same reporting notes that a significant share of surveyed candidates already admitted to impersonation or having someone else pose for them during an interview.

Gartner projects that a substantial share of candidate profiles worldwide could be fake in the coming years — a trajectory that makes identity verification a strategic priority, not an administrative one.

The Checkr survey of 3,000 hiring managers adds operational texture to that projection. High shares of managers reported suspecting AI use in applications, encountering fake identities, and discovering third-party interview takers. These are not edge cases; they are patterns managers are seeing repeatedly across industries and role types.

MetricFindingWhat it means for HR
Fake candidate profiles by 2028Gartner projects 1 in 4 profiles could be fakeIdentity verification must be built into standard process now
Candidates admitting impersonationa notable proportion in Gartner-cited surveyActual rates likely higher; self-reporting understates the problem
Managers suspecting AI in applicationsHigh share in Checkr's 3,000-manager surveyATS-level fraud scoring is no longer optional for volume hiring
Managers encountering third-party interview takersDocumented in Checkr surveyLiveness checks and ID verification are necessary at interview stage
Synthetic voice fraud trendSharp year-over-year rise per PindropVoice-only screening is no longer a reliable identity signal

Pindrop's 2025 Voice Intelligence and Security Report documents a sharp year-over-year rise in synthetic voice activity, which directly undermines phone screens and audio-only interviews. Organizations that rely on voice as a single authentication factor are exposed.

What forms does candidate fraud actually take?

Understanding the taxonomy matters because each fraud type requires a different detection and prevention response. The categories below are not mutually exclusive; they often escalate from one to the next.

  • Resume and credential exaggeration. The most common form: inflated job titles, fabricated degrees, or overstated tenure. A recruiter signal is a LinkedIn profile that doesn't match the resume's timeline, or a reference who can't confirm the role described.
  • Fake portfolios and fabricated work samples. Candidates submit AI-generated code, writing, or design work as their own. The signal: they cannot explain their methodology or answer follow-up questions about their own submitted work.
  • Third-party interview takers. Someone other than the applicant completes the screening or live interview. The signal: voice, appearance, or communication style shifts noticeably between screening stages, or the candidate struggles to recall details from a previous conversation.
  • Deepfake video and synthetic avatars. AI-generated video or audio is used to impersonate a candidate in real time. Signals include unnatural blinking patterns, slight lip-sync delays, lighting that doesn't respond to movement, and avatar behavior inconsistencies such as a face that stays unnaturally still.
  • Mass AI-generated applications and bot pipelines. Automated tools submit hundreds of applications with near-identical phrasing, flooding ATS pipelines and making genuine candidates harder to surface. The signal: application timestamps clustered within seconds, keyword saturation that reads as machine-generated, and no meaningful customization across roles.
  • Synthetic identity fraud. Entirely fabricated identities, sometimes combining real and invented personal data, used to pass background checks. This is the most dangerous escalation path: a synthetic identity can survive a standard background check and then gain system access under a false persona.

The escalation path from resume fraud to impersonation to insider access is well-documented. A candidate who fabricates credentials may also use a third party for the interview, and once hired, that person has legitimate system credentials tied to a false identity.

Why interview fraud is increasing now: the root causes

Several structural forces have converged simultaneously, which is why the growth of hiring fraud has accelerated rather than simply persisted.

AI tools have lowered the technical bar to near zero. Generating a polished resume, a compelling cover letter, or a synthetic voice clone no longer requires technical skill. Tools available to any consumer can produce convincing fabrications in minutes. The academic literature on interview faking shows that faking has always been common; AI has simply removed the effort barrier.

Remote hiring expanded the attack surface. When interviews moved online, the in-person identity check disappeared. A candidate can now complete an entire hiring process, including background check submission, without ever being physically present or visually verified by a human who knows what to look for. The role of video interviews in remote hiring creates genuine efficiency, but it also creates a verification gap that bad actors exploit.

  • Recruiting speed pressure rewards surface polish. High-volume hiring metrics push recruiters to move fast. AI-generated applications are optimized for ATS keyword filters, so they score well and advance quickly, while genuine candidates with less polished formatting get filtered out. The result is a pipeline that has been gamed at the top.
  • Economic pressure and skill gaps create motivation. Candidates facing unemployment, wage stagnation, or credential gaps have stronger incentives to misrepresent themselves. This is not a new dynamic, but the tools to act on that motivation are now widely accessible.
  • Organized and nation-state actors have entered the space. This is the factor most hiring teams underestimate. Criminal enterprises and state-sponsored actors now run coordinated schemes to place fraudulent workers in roles that provide system access, data, or financial resources. This is not opportunistic individual fraud; it is structured and resourced.

Pro Tip: When setting hiring SLAs, build a verification checkpoint into the process before any offer is extended, not after. Tying time-to-hire metrics to offer acceptance rather than to first-screen completion gives your team room to verify without creating pressure to skip steps.

What's at stake if fraud slips through

The consequences of a fraudulent hire extend well beyond a bad performance review.

  • Operational risk: Lost productivity, team disruption, and the cost of restarting a search. A role that takes six weeks to fill and then requires termination within 90 days represents a significant resource loss.
  • Security risk: A fraudulent hire with system access can exfiltrate data, install malware, or create backdoor credentials. This is the scenario that has prompted FBI and IC3 advisories on fraudulent remote employment schemes.
  • Nation-state risk: The FBI's advisory on North Korean IT worker schemes documents cases where impersonation and deepfakes were used in virtual interviews to place workers who then funneled earnings to sanctioned programs. The DOJ has indicted individuals involved in multi-year schemes using fraudulent remote hiring to circumvent sanctions.
  • Legal and compliance exposure: Hiring a person who misrepresented credentials for a regulated role creates liability. If that person causes harm, the organization's due-diligence process will be scrutinized.
  • Reputational damage: A publicized fraud incident, particularly one involving data breach or sanctions violations, carries lasting reputational cost.

From a security perspective, candidate fraud now creates cyber risk that can be more severe than a bad hire — forcing HR to coordinate with security teams and treat identity fraud as enterprise risk, not just a recruiting problem.

The hidden downstream costs are often larger than the direct ones: investigation time, legal review, compliance remediation, and the distraction cost to the hiring team and affected business unit.

How to detect interview fraud: behavioral, documental, and technical red flags

Detection works best when it is layered across multiple signals rather than relying on any single check. Here is what to look for at each stage.

Behavioral signals during interviews:

  • Answers that sound scripted or read from a screen, with unnatural pauses before each response.
  • Inability to elaborate on their own submitted work samples or resume claims under follow-up questioning.
  • Inconsistencies between what was said in a phone screen and what is said in a video interview.
  • Eye movement that doesn't match natural thinking patterns: consistent off-screen glances at a fixed point, or eyes that track text rather than move in the irregular way associated with genuine recall. Spotting dishonest interview responses often comes down to these subtle attention signals.

Documentary and profile checks:

  • LinkedIn profile creation date that postdates claimed employment history.
  • References who cannot confirm specific details of the role, or who share contact information that traces back to the same domain as the candidate.
  • Metadata on submitted documents showing creation dates inconsistent with the claimed timeline, or authorship fields that don't match the candidate's name.

Technical checks:

  • Liveness metadata from your interview platform: device location, IP address, and whether the video feed shows signs of virtual camera software.
  • Audio artifacts consistent with synthetic voice: slight robotic cadence, absence of natural breath sounds, or audio that doesn't degrade naturally with background noise.
  • ATS traffic signals: multiple applications from the same IP range, or application patterns that suggest automation.

Sample probing questions to reveal coached or non-authentic responses:

  1. "Walk me through a specific decision you made on that project that you would change today, and why." A genuine candidate can name the decision and the reasoning. A coached or AI-assisted candidate typically gives a generic improvement narrative.
  2. "Your resume mentions [specific tool]. Describe a time it produced an unexpected result and how you handled it." Fabricated experience collapses under specificity.
  3. "I'd like you to share your screen and show me one piece of work from that role." This single request eliminates most AI-generated portfolio fraud immediately.

Detection has real limits. False positives are a genuine risk: a nervous candidate may show behavioral signals that look like deception, and a non-native English speaker may pause in ways that resemble scripted responses. Any detection signal should be treated as a prompt for further verification, not as a standalone disqualifier.

Practical prevention: process changes HR teams should implement now

Prevention requires changes at the process level, not just the tool level. Here is a prioritized approach.

For high-risk roles, implement these first:

  1. Identity verification before any interview. Require government-issued ID verification through a service like Persona, Jumio, or a comparable provider before the first live interaction.
  2. Live-proctored screening interviews. Use a platform that captures liveness metadata, records the session, and flags behavioral anomalies for human review.
  3. Validated work-sample assessments. Assign a task that must be completed live or under observed conditions, not submitted asynchronously. This is the single most effective filter for fabricated skills.
  4. Strengthened reference protocols. Call references on numbers you source independently, not numbers provided by the candidate. Ask for specifics about the candidate's work that only a direct manager would know.
  5. Background check with identity cross-reference. Confirm that the identity on the background check matches the identity verified at the interview stage.

For scale: process and technology changes:

  • Deploy ATS-level fraud scoring to flag application patterns consistent with automation or mass generation.
  • Standardize your candidate AI-use policy in writing and communicate it at the application stage. Candidates should know what AI assistance is acceptable and what constitutes disqualification.
  • Use structured interview formats with standardized questions across all candidates for the same role. This makes coached or scripted answers easier to identify by comparison.
  • Record all screening interviews with candidate consent, and retain recordings as part of the audit trail.

Implementation guidance: Start with a pilot on your highest-risk role category, typically remote technical or financial roles. Measure your baseline fraud-detection rate before and after adding each layer, and document the cost per verified hire. Bring legal, security, and hiring managers into the design process early; verification technology that hasn't been reviewed for compliance with applicable employment law creates its own risk.

Pro Tip: Automation handles volume well: ATS fraud scoring, metadata analysis, and liveness checks can process thousands of applications without adding recruiter hours. Human review remains essential for ambiguous cases and for any decision to disqualify a candidate, where the reasoning must be documentable and defensible.

Practical prevention: process changes HR teams should implement now — overview diagram
Practical prevention: process changes HR teams should implement now — overview diagram

Research and security perspective: what the evidence actually says

The guidance in this article draws on a convergence of law-enforcement advisories, enterprise research, and academic literature. Understanding the source of each claim helps HR teams make the case internally for investment.

FBI and IC3 on nation-state activity. The FBI's advisory on North Korean IT worker schemes is specific: these schemes have used impersonation and deepfakes in virtual interviews to evade identity and location controls. The FBI recommends asking candidates to point the camera out a window and show unobscured backgrounds as a basic liveness check. The IC3 and DOJ have documented prosecutions of facilitators who helped place fraudulent workers in US companies over multi-year periods.

The FBI recommends that organizations conducting virtual interviews ask candidates to show their physical surroundings on camera — a simple, zero-cost liveness check that synthetic-media tools cannot easily defeat in real time.

Gartner and enterprise survey data. The Gartner projection covered by HR Dive frames candidate fraud as an enterprise risk management issue, not just a recruiting quality problem. When one in four profiles could be fake by 2028, the downstream security and compliance implications require coordination between HR, IT security, and legal.

Academic research on interview faking. The review by Levashina, Campion, and colleagues shows that interview faking is common across many samples, that detection is genuinely difficult, and that no single intervention reliably eliminates it. The implication is clear: layered defenses are necessary because no single control is sufficient.

Pindrop on synthetic voice. Pindrop's research documents the rapid rise in synthetic voice fraud and warns that organizations should pair voice biometrics with deepfake detection rather than relying on voice authentication alone.

Where Evy fits in a layered defense. Evy's AI interview platform includes real-time eye tracking that monitors attention patterns during a live screen, flagging off-screen glances and attention shifts consistent with external AI assistance. Combined with automated scoring, video recording, and an audit trail, it addresses both the volume problem (screening at scale without adding recruiter hours) and the depth problem (behavioral signals that document-only checks miss). Any deployment of verification technology should be reviewed with legal counsel for compliance with applicable employment and privacy law, and candidates should be informed of monitoring practices before the interview begins.

Defense layerWhat it addressesHuman review still needed?
ATS fraud scoringMass-generated applications, bot pipelinesYes, for borderline flags
Identity verification serviceSynthetic identities, impersonationYes, for mismatches
Liveness check (camera/platform)Deepfake video, third-party takersYes, for ambiguous cases
Real-time eye tracking (e.g., Evy)AI-assisted responses, attention anomaliesYes, for final disqualification
Validated work-sample assessmentFabricated skills, AI-generated portfoliosYes, always
Structured reference checkCredential exaggeration, false employment historyYes, always
Research and security perspective: what the evidence actually says — overview diagram
Research and security perspective: what the evidence actually says — overview diagram

If you discover fraud: immediate steps and longer-term remediation

Discovering fraud mid-process or post-hire requires a consistent, documented response. Improvised handling creates legal exposure.

  1. Freeze the offer or suspend system access immediately. Do not allow the process to advance while the investigation is open. If the person is already employed, work with IT security to suspend access before any notification.
  2. Preserve all evidence. Secure interview recordings, ATS records, submitted documents, email correspondence, and any device or location metadata your platform captured. Chain of custody matters if the case escalates to law enforcement.
  3. Notify your legal and security teams before taking any further action. The sequence of notifications and the language used in candidate communications should be reviewed by counsel. Premature or poorly worded communication can create liability.
  4. Validate the fraud. Confirm that what you observed is fraud rather than a process error or a false positive. Review the evidence with at least one other person. Document your reasoning.
  5. Revoke the offer or initiate disciplinary proceedings per your organization's HR policy and applicable employment law. If the fraud involves potential sanctions violations, data theft, or criminal activity, coordinate with legal on whether to report to law enforcement.
  6. Conduct a lessons-learned review. Identify which control failed, at which stage, and why. Update your process before the next hiring cycle.

Template language for internal escalation (high-level, non-legal): "We have identified indicators of potential candidate fraud in [role/requisition]. Evidence has been preserved. Legal and security have been notified. The offer/process has been paused pending investigation. No external communication has been sent."

Template language for candidate communication (coordinate with legal before sending): "We are unable to proceed with your application at this time. If you believe this is an error, please contact [HR contact] within [X] business days."

What hiring teams are getting wrong

The most common mistake is treating interview fraud as a late-stage problem. Teams invest in background checks that run after an offer is extended, by which point a fraudulent candidate has already passed every human-facing screen. The verification happens at the wrong end of the funnel.

A second misstep is siloed controls. Background check vendors, ATS platforms, interview tools, and IT security systems each capture signals, but those signals rarely talk to each other. A candidate who raises a flag in the ATS may clear the background check because no one connected the two data points. Fraud detection works as a system, not as a checklist of independent steps.

The third mistake is measuring the wrong thing. Most hiring teams track time-to-fill and offer acceptance rates. Almost none track fraud-detection rate, false-positive rate, or the downstream cost of a fraudulent hire. Without measurement, there is no way to know whether your controls are working or whether you are simply getting lucky.

The practical priorities, in order: verify identity early (before the first live interview, not after the offer), layer technical and human review rather than choosing one, and treat interview fraud as an enterprise risk that requires HR, security, and legal to work from the same playbook. The security dimension of interview integrity is not a recruiting problem that happens to have security implications. It is a security problem that starts in recruiting.

Evy screens at scale and flags what standard interviews miss

Hiring teams dealing with high application volumes and remote-first processes face a specific challenge: the controls that work at low volume don't scale, and the controls that scale don't catch behavioral fraud. Evy addresses both sides of that problem.

Evy
Evy

Evy's AI interview platform uses real-time eye tracking to detect attention patterns consistent with external AI assistance during a live screen, combined with automated scoring that integrates resume signals and live responses into a single candidate record. Every session is recorded with a full audit trail, and the platform integrates with your existing ATS so verified results flow directly into your hiring workflow. Screening runs 24/7 without adding recruiter hours, which means you can apply consistent verification standards across every candidate, not just the ones who make it to a human interview.

Before deploying any verification or monitoring technology, coordinate with your legal team to confirm compliance with applicable employment and privacy law, and inform candidates of monitoring practices before their interview begins. To see how Evy fits your screening process, start a free trial or request a walkthrough of the platform.

Sources

Recommended