Interviewer conducting a video call interview with a candidate.

The AI Fake Candidate Problem in IT Hiring (and What to Do About It)

Quick answer: AI candidate fraud ranges from fabricated résumés and work samples to identity theft and fraudulent remote workers. IT employers face greater exposure because technical hires may receive access to source code, infrastructure, credentials, and sensitive data. The practical defense is layered verification that becomes more rigorous as a candidate gets closer to system access.

Hiring managers are interviewing candidates who aren’t who they claim to be. In a 2025 survey, Gartner found that 6% of candidates had participated in interview fraud by posing as someone else or having another person interview for them. Gartner predicts that one in four candidate profiles worldwide will be fake by 2028.

That’s a serious hiring problem in any department. In IT, it can become a security incident. A DevOps engineer, cloud administrator, or software developer may receive access to production systems, source code, customer data, and company devices within days of starting work.

Most companies have people watching both ends of that process. HR manages hiring, and IT security manages access. The trouble starts when nobody owns identity verification between the two.

Gartner: one in four candidate profiles fake worldwide by 2028.

What AI Candidate Fraud Looks Like

Someone who uses AI to improve the wording of a résumé presents a very different risk from someone who steals an identity to get inside a company network. Hiring teams need to know what they’re dealing with before they decide how far to investigate.

What AI Candidate Fraud Looks Like

Type of fraudWhat it can includeWhy it gets throughWhat the employer risks
Fabricated application materialsInvented experience, credentials, references, or work samplesAutomated screening and high application volumeHiring decisions based on work the candidate cannot reproduce
Interview impersonationAnother person appears, or the applicant alters their voice or appearanceRemote interviews with weak identity checksHiring someone other than the person who was evaluated
Organized employment fraudStolen identities, false companies, laptop farms, or fraudulent remote accessDisconnected hiring, onboarding, and security processesUnauthorized access to systems, source code, data, or funds

One applicant can now tailor a résumé, cover letter, writing sample, and assessment response to each opening before a recruiter reviews the application. Gartner found that 39% of candidates used AI during the application process in late 2024. Among those users, 36% generated writing samples and 29% generated assessment answers.

Those numbers don’t mean everyone using AI is cheating. They do mean a hiring team can’t assume that an application or work sample shows what a candidate can produce independently.

Interview fraud goes further. Another person may complete the technical screen, feed answers to the candidate from off camera, or alter the candidate’s voice or appearance during a video call. By the time someone notices an inconsistency, the hiring manager may have spent several hours evaluating a person who was never really in the process.

Organized employment fraud carries much higher stakes. In June 2025, the Department of Justice described North Korean IT workers using stolen and fabricated identities to obtain jobs at more than 100 U.S. companies. Facilitators operated laptop farms that allowed workers outside the country to access employer-issued computers through U.S.-based connections.

Once hired, some of these workers gained access to sensitive data and source code, including export-controlled military technology. Others stole more than $900,000 in virtual currency.

They didn’t have to break through the company’s network defenses. The hiring process gave them access.

Table of AI candidate fraud types, methods, and employer risks.

Why IT Hiring Is Especially Exposed

Remote hiring is now routine for technical roles. Interviews, assessments, onboarding, equipment delivery, and daily work may all happen without the employee ever entering a company facility.

That removes many of the ordinary moments when identity gets confirmed. Nobody checks an identification card at reception. The hiring manager may never see the candidate outside a video window. A laptop can be shipped and activated before the employee meets anyone in person.

The access attached to technical roles raises the cost of a mistake. A cloud administrator may receive privileged credentials. A developer may work with proprietary source code. A security engineer may learn exactly how the company protects its systems.

An applicant-tracking system can confirm that the same name appears throughout an application. It can’t confirm that the same person wrote the résumé, completed the assessment, attended the interview, and reported for work.

Background checks can create another false sense of certainty. A completed check may confirm that the identity exists and has a particular history. It doesn’t automatically prove that the person on the video call owns that identity.

The answer isn’t to treat every applicant like a suspect. A résumé may need a few consistency checks. A finalist who will receive production credentials needs verified identification, employment history, and a confirmed delivery address.

How to Detect Candidate Fraud Without Driving Away Real Candidates

Qualified candidates shouldn’t have to run an obstacle course because fraud exists elsewhere in the market. Early conversations can check whether the candidate’s story holds together. More formal identity checks belong later, when the person is approaching an offer, a company device, or access to sensitive systems.

At the Application Stage

Start with the claims that matter most to the job. Ask candidates to explain a specific project, name the systems involved, describe what went wrong, and give the measurable result. Someone who performed the work can usually provide context that never made it onto the résumé.

A vague answer isn’t proof of fraud. Strong candidates sometimes interview poorly, work under confidentiality restrictions, or need a moment to recall an older project. What matters is whether the details remain consistent across the résumé, conversation, references, portfolio, and technical assessment.

Candidates also need to know what the company considers acceptable AI use. Grammar help may be fine. Generating a work sample or receiving answers during a technical assessment may violate the rules. A company can’t fairly enforce a standard it never explained.

Hiring stage verification checklist: application, interview, finalist.

During the Interview

Remote interviews should give the hiring team enough information to confirm that the same person remains in the process. The FBI recommends requiring video, keeping backgrounds unobscured, asking questions about a candidate’s claimed location, and comparing the person with identification and later meetings.

The FBI also suggests asking a candidate to wave a hand in front of the face because the movement may disrupt AI-generated video. That’s a useful check, but it’s hardly conclusive. Video software keeps improving, and an ordinary connection problem can produce lag, blurred edges, or strange movement.

A visual anomaly is a reason to look closer, but it isn’t a verdict.

Unscripted follow-up questions often reveal more than a visual test. Ask why the candidate chose a particular architecture, which approach failed first, or what had to change after deployment. Those questions make it harder to stay inside a prepared answer and easier to hear how the person thinks.

For higher-risk roles, a live technical assessment adds another layer. A shared coding or systems environment lets the interviewer watch how the candidate interprets the task, uses tools, responds to an error, and explains a decision. A take-home assignment can still show useful work, but it can’t establish who completed it.

At the Finalist and Onboarding Stages

Before shipping equipment or granting access, confirm that the candidate, the verified identity, the payment information, and the delivery address belong together.

The FBI recommends cross-checking identification details against contact information, professional profiles, portfolio sites, and payment platforms. Employers should verify education and previous employment directly with the institution or company rather than relying only on documents supplied by the candidate.

The FBI also advises employers to ship devices only to the address shown on verified identity documents. When a candidate requests a different destination, the company should require additional documentation before sending anything.

HR and IT security need a clear handoff. A changed shipping address, repeated changes to payment information, inconsistent identity documents, or a different person appearing after hire should reach someone who can investigate before access expands.

New employees should start with the minimum access required for their work. Least-privilege access won’t catch a fake candidate, but it can limit the damage while the company confirms that everything is what it appears to be.

How GDH Detects Fake Candidates

GDH combines recruiter judgment with added verification throughout the hiring process. When something doesn’t add up, we look more closely before presenting the candidate to a client. A discrepancy may have an innocent explanation, so no single warning sign is treated as proof of fraud.

Cross-Check Candidate Information

Our recruiters compare the resume with details gathered during screening and interviews. Dates, locations, employers, and contact information should tell a consistent story. When they don’t, we ask follow-up questions and verify the information rather than relying on the resume alone.

Verify Experience and References

We contact references to confirm where the candidate worked and whether the experience described in the interview is accurate. We also check that the references are legitimate. A name and phone number are easy to provide, and fake candidates may use friends or fabricated contacts to support an invented work history.

Confirm Candidate Identity

We may also ask candidates to verify their identity with a government-issued ID and biometric matching. This confirms that the person completing the screening is the same person who applied and interviewed. The check carries particular value in remote hiring, where the candidate may never meet a recruiter or client in person.

Our recruiters review the results alongside everything they have learned from the candidate. When questions remain, we investigate them before the hiring process moves forward.

Hire With Greater Confidence

A strong hiring process should verify who a candidate is as carefully as it evaluates what that person can do. Contact GDH to learn how our recruiters can help you find qualified candidates whose identities and experience have been thoroughly reviewed.

Frequently Asked Questions

How do I know if a candidate is using AI to cheat?

One unusual answer or video glitch doesn’t establish fraud. Look for inconsistencies across the résumé, interview, technical assessment, references, identity documents, and later meetings. Ask specific follow-up questions about claimed work and use stronger identity checks as the candidate gets closer to an offer or access to sensitive systems.

Do smaller companies need deepfake interview detection?

Yes. Smaller organizations may hire fewer people, but one fraudulent technical hire can still receive valuable access. Their greater weakness is often limited recruiting and security capacity. A short, documented verification process is more useful than an elaborate fraud program designed for a global employer.

When does AI assistance become candidate fraud?

AI assistance becomes fraud when it materially misrepresents identity, experience, ability, or authorship. Grammar help and interview practice may comply with an employer’s policy. Fabricated experience, generated work submitted as unaided, hidden assistance during an assessment, and identity impersonation cross a different line. Employers should define that line before screening begins.

How can an IT staffing firm reduce fraud exposure?

An established staffing firm can provide structured sourcing, repeated candidate contact, documented screening, and continuity between application and recommendation. Employers should still examine the firm’s actual verification practices. A staffing relationship reduces exposure only when responsibilities, escalation procedures, and identity checks are clear.

Similar Posts