The Candidate Isn't Real: AI Fake Applicants Have Arrived — and Small Employers Are Not Exempt

bsmith@westernverify.com 7 min read

Gartner predicts 1 in 4 candidate profiles will be fake by 2028. Deepfake interviews, fabricated resumes, and stolen identities are no longer a big-tech problem. Here's how verification catches what the interview can't.

In 2024, the security awareness training company KnowBe4 — a firm whose entire business is teaching people to spot scams — hired a software engineer who aced the interviews, passed four video calls, and cleared a background check. The photo matched the person on camera. The resume checked out.

He was a North Korean operative using a stolen American identity. The company caught him only after he loaded malware onto his company laptop on day one — and then went public with the story as a warning to everyone else.

If it can happen to a security company that screens for a living, it can happen to anyone. And the everyday version of this problem — less cinematic, far more common — is already sitting in your applicant pool.

The Numbers: Fake Applicants Are Going Mainstream

The research firm Gartner made headlines with a prediction that would have sounded like science fiction five years ago: by 2028, 1 in 4 candidate profiles worldwide could be fake, as reported by HR Dive.

The supporting data is just as uncomfortable:

  • 6% of job candidates admitted to participating in interview fraud — posing as someone else, or having someone else interview in their place (Gartner survey of 3,000 candidates)
  • 40% of candidates are using AI during the application process, primarily to write resumes, cover letters, and assessment answers
  • 76% of hiring managers say AI has made it harder to assess candidate authenticity, per a Resume Genius survey
  • Researchers at Palo Alto Networks found that someone with no technical experience can build a convincing deepfake job candidate in about 70 minutes, ready for live video interviews

"It's getting harder for employers to evaluate candidates' true abilities, and in some cases, their identities." — Jamie Kohn, Senior Research Director, Gartner HR Practice

Kohn adds a point every employer should sit with: "Candidate fraud creates cybersecurity risks that can be far more serious than making a bad hire."

This Is Not Just a Fortune 500 Problem

It's tempting to file deepfake applicants under "things that happen to Google." The Justice Department's own cases say otherwise. In its 2025 nationwide enforcement action against North Korean remote-worker schemes, the DOJ documented infiltration of more than 100 U.S. companies, using more than 80 stolen American identities, with U.S.-based "laptop farms" hosting company equipment so overseas workers could appear to be logging in from Ohio or Texas.

Were they all Fortune 500 firms? No — and that's the point. Fraud rings target companies that hire remotely and verify lightly. A 40-person company with a busy hiring manager, no dedicated security team, and a one-click ATS background check is an easier mark than a tech giant with an insider-threat program.

And you don't need a nation-state actor to get burned. The routine version looks like this: a fabricated resume with AI-polished job history, a reference phone number that rings to the applicant's friend, a diploma from a degree mill, and an interviewee getting real-time AI coaching through an earpiece — or simply a different person than the one who shows up on day one. Every piece of that is cheap, easy, and increasingly common.

Why Interviews and Instant Checks Can't Catch It

Hiring managers trust their gut, and the gut is exactly what AI defeats. Polished answers, flawless documents, and a face on video that matches the ID photo — all of it can now be manufactured.

The instant database check bundled into your hiring software doesn't help much either. A database search runs on the identity the applicant gave you. If that identity is stolen or synthetic, a clean result is meaningless — you've verified that someone else has no criminal record. And database checks do nothing to confirm that the work history, education, or references are real, which is where most application fraud actually lives.

Interviews measure presentation. Databases measure the name you typed in. Neither one verifies the person.

What Actually Works: Verify the Human, Then the History

The defense against manufactured candidates isn't a smarter gut — it's independent verification at every point where fraud can enter:

  • Identity verification that goes beyond a glance at an ID. An SSN trace cross-checked against a real address history surfaces mismatches — a "local" candidate whose identity trail lives in another state, or a Social Security number attached to a different name. That address history then drives everything else.
  • County-level criminal searches based on where the applicant has actually lived. Searching real jurisdictions from a verified address history — rather than a database query on a possibly borrowed name — is what ties the check to the actual human.
  • Employment and education verification by a live person. A verifier who independently finds the employer's number — instead of calling the one the applicant provided — dismantles fake references and shell-company job histories in a single phone call. Degree-mill diplomas fall apart the same way.
  • Structural friction fraud avoids. Gartner's survey found 62% of candidates were more likely to apply when a role required in-person interviews — honest applicants don't mind showing up. Even one in-person or camera-on, gesture-verified step (Palo Alto Networks recommends asking video candidates to turn in profile or pass a hand in front of their face, which breaks most real-time deepfakes) filters out remote impostors before you spend a background check on them.
  • Human review of the whole picture. Fraud rarely trips one big alarm. It shows up as small inconsistencies — dates that almost line up, an employer no one can reach, an address that doesn't fit the story. A trained analyst connects dots that automated systems pass through.

None of this requires abandoning your ATS or slowing every hire. Best practice is tiered: keep the fast bundled check for low-risk roles, and run full identity-anchored verification — alongside the bundled tool, not instead of it — for remote roles, roles with system access, finance, and anyone who touches customers or sensitive data.

A Quick Compliance Note

Fraud defense has to stay inside the lines. Apply identity and verification steps consistently to all candidates for a given role — singling out individuals invites discrimination claims. If verification surfaces information that leads to a rejection, the FCRA adverse action process still applies, and remote-hiring rules (including I-9 verification requirements) vary by circumstance, so you may want to confirm current requirements before overhauling your process. A screening partner that handles this workflow keeps the protection from becoming its own liability.

The Bottom Line

The KnowBe4 incident ended without damage for one reason: layered controls caught what four video interviews missed. Most employers don't have those layers — they have an interview, a gut feeling, and a one-click database check running on whatever name the applicant supplied.

AI has made the fake candidate cheap to manufacture. The response is to make your process expensive to fool: verify the identity, verify the history at the source, add one step a deepfake can't survive, and put a human analyst behind every report.

Hiring for roles you can't afford to get wrong? Visit westernverify.com to see how identity-anchored, county-level screening with human review confirms your next hire is exactly who they say they are.

Sources

Blaine Smith
Posted by Blaine Smith

Blaine is the Co-Founder and COO of Western Verify, and spends his free time hosting parties or traveling with his amazing family.

Connect on LinkedIn.

© 2026 Western Verify, LLC. All rights reserved.