Deepfake Interview Fraud Is Up 1,300%. In-Person Hiring Won't Fix It.
In-person mandates raise the cost of faking a face on a webcam. They do nothing for the identity fraud that gets paid at onboarding.
A hiring manager at an Australian healthcare company ran a routine background check in February 2026 and flagged three IT hires within days of each other. All three had cleared video interviews months earlier. All three had passed reference checks. What caught them wasn't a deepfake detector: it was a shared VPN pattern, near-identical identity paperwork, and a utility bill with formatting errors a genuine one never has. The case is a clean illustration of a pattern showing up across the industry: deepfake interview fraud is real and growing fast, but the fraud that actually costs a company money rarely gets caught in the interview. It gets caught in payroll.
The panic, in numbers
Lloyd Staffing, a US staffing firm, put the rise in deepfake hiring-fraud attempts at roughly 1,300% between 2023 and 2024. Experian's 2026 Future of Fraud Forecast named deepfake job applicants one of its five biggest fraud threats for the year, alongside agentic-AI scams and account takeovers. A 2025 Checkr survey of IT, cybersecurity, risk and fraud leaders found 41% said their organisation had unknowingly hired and onboarded a fraudulent candidate. Gartner's own projection is the starkest: by 2028, it expects one in four candidate profiles submitted worldwide to be fake in some way, whether that's a fabricated resume, a stolen identity, or a live deepfake overlay during the interview itself.
None of that is exaggerated. Face-swap and voice-clone tools that used to need a discrete GPU and hours of training footage now run inside a browser extension, in real time, on an ordinary laptop. The barrier to running a deepfake in a video call has fallen about as fast as the barrier to writing a convincing cover letter with an LLM did two years earlier.
What in-person interviews actually test
Recruiting teams reacted the way you'd expect. Surveys of recruiting leaders through 2025 found a majority now run at least one interview in person specifically to counter fraud, with in-person final rounds going from a rare exception in 2024 to a standard step for a meaningful share of hires by 2025.
That is a real defence against one specific failure mode: a candidate who cannot physically show up because the person on the video call and the person applying for the job are not the same human. It closes the highest-profile version of the problem, the one that makes headlines when a company discovers, three months in, that the engineer it hired was never who the resume said.
It does nothing for the version of fraud that doesn't depend on a live deepfake at all. A candidate can walk into an office, answer every question well, shake the interviewer's hand, and still be operating under a stolen or synthetic identity that was never checked against anything more rigorous than a resume and a LinkedIn profile. The interview room was never where identity got verified. It was where competence got verified. Those are different checks, and only one of them moved when the industry brought people back into a room.
Where deepfake interview fraud actually gets paid
The Australian case from the opening is worth walking through because it shows the mechanics, not just the headline number. Three employees at the healthcare company were flagged not because a deepfake detector caught anything during their interviews, but because a pattern surfaced months into employment: all three connected through the same VPN provider and a residential proxy service, their identity documents shared formatting quirks that don't occur in genuinely independent paperwork, and the utility bills submitted as proof of address during onboarding carried copy-paste artefacts consistent with one template reused across multiple fake personas. Two of the passports had details that lined up too closely to be a coincidence.
Every one of those signals showed up after the interview. None of them would have been visible to even a sophisticated real-time deepfake detector running during a video call, because the interview stage produces almost no identity evidence to check in the first place. A resume, a face on a screen and answers to a behavioural question are not identity documents. They're a performance.
The North Korean playbook is the clearest version of this
The most documented version of this fraud is the North Korean IT-worker scheme, and it maps the same pattern almost exactly. Internal coaching material described in threat-intelligence and law-firm write-ups this year walks operatives through resume formatting, which job boards to target, and how to source a phone number that matches the region they're claiming to be from. Interviews happen over ordinary platforms, Teams, Zoom, Webex, using a real-time deepfake overlay or, increasingly, a hired stand-in who does the talking while someone else does the work later.
None of that requires beating a fraud-detection product built for live video. It requires beating a hiring process that treats the interview as the finish line instead of the starting gate. Coverage this year of the scheme's expansion into new industries makes the same point from a different angle: the fraud follows wherever onboarding and payroll checks stay weaker than interview screening, not wherever video calls happen to be involved.
The part that keeps the scheme funded isn't the interview. It's that once someone is hired, the paperwork that actually binds a person to a bank account, a tax identity and building or system access is often weaker than the screening that got them the job in the first place.
Why real-time detection tools are fighting the wrong battle
A growing set of vendors now sell real-time deepfake and AI-cheating detection for live interviews: tools that watch for artefacts in a video feed, inconsistent lip-sync, or signs that a candidate is reading answers fed by an AI coaching tool off-screen. Some of this works, for now. Most of it is playing a game it cannot win outright, because every detection signal a vendor ships becomes a target for the next version of the tool it's trying to catch. Spam filtering, ad fraud and anti-cheat software in gaming spent two decades learning that lesson the hard way.
“A deepfake only has to survive one video call. A fabricated identity has to survive a tax form, a bank account and a background check, every single day it stays on payroll.”
That asymmetry is the whole argument. It doesn't make interview-fraud detection worthless; it makes it a speed bump rather than a gate. Treating a passed live-interview scan as proof of who a candidate is gives a company more confidence than the underlying check has actually earned.
Where the verification budget should actually go
The fix that shows up in almost none of the vendor marketing is the less exciting one: bind identity once, early, with a document and liveness check that's harder to fake than a resume, then re-verify it at the moments that matter for fraud rather than the moments that are easiest to sell a feature for.
In practice that means identity verification at the offer stage, tied to a government-issued document and a liveness check rather than a video call. It means matching that identity against the details used to set up payroll, tax withholding and direct deposit, since a fabricated identity that clears a background check often can't clear a bank's own know-your-customer process. And it means re-checking identity at the point where system or building access gets provisioned, because that's the actual moment a fraudulent hire gains something worth stealing. A standard background check assumes the identity behind it is already correct; it was never built to catch the identity itself being fake.
| Verification layer | What it catches | What it misses |
|---|---|---|
| In-person final round | A candidate who can't physically be the person on camera | A real person using a stolen or fabricated identity |
| Real-time interview fraud detection | Live face-swap artefacts and some AI-coaching tools mid-call | Anything that happens before or after the call itself |
| Standard background check | Criminal records and employment history tied to the ID given | Whether that ID itself is genuine |
| Identity binding at offer + payroll onboarding | Document and biometric mismatch, synthetic or stolen identities | Nothing upstream of the offer; still needs a decent interview process |
What this means for distributed teams
None of this is an argument for return-to-office as a fraud policy, whatever headlines do with these numbers this year. Fully distributed companies aren't more exposed to this fraud than companies with an office; they just have to solve the identity problem the way strong know-your-customer industries such as banking and fintech already do, independent of geography, at the point where money and access change hands rather than at the point where two people happen to sit in the same room. A company that already hires well at a distance has most of the discipline this problem requires. It just needs to point that discipline at onboarding and provisioning instead of leaning entirely on the video call.
The next wave of hiring-fraud reporting will likely track how many companies moved verification downstream to onboarding and payroll, not how many brought interviews back into a conference room.
Frequently asked questions
Related reading
The Four-Day Week Trials Report 90% Success. Almost None Involved Teams That Owe Continuous Coverage.
The UK's landmark trial and the 2025 Nature Human Behaviour study are the two data points every four-day week pitch cites. Both skew heavily toward marketing, consulting and non-profits.
Take-Home Coding Assignments Are Dying. The Replacement Isn't Better Cheating Detection.
Hiring teams built better cheating detectors. Candidates got better at beating them. The real fix is changing what a coding assignment is supposed to measure.
India’s GCC Hiring Hit a Record 510,000 Jobs in 2026, and the Work Looks Nothing Like Before
India’s GCCs are set to cross 510,000 jobs in 2026, but the real story is what those jobs have become: nearly two in three now need AI or data skills, and growth is shifting to tier-2 cities.