Skip to main content

Morning Overview

Deepfake job applicants are tricking companies into hiring people who don’t exist

Companies that hire remote workers have run into a strange new hazard: the person on the video interview may not be who they claim to be, or may not be an independent applicant at all. Federal investigators and corporate security teams have spent the past several years documenting scams in which artificial intelligence is used to fabricate voices, photos, and even live video well enough to clear interviews and background checks. Some of the fraud is opportunistic; some of it is run by state-linked operations using the salaries to fund weapons programs. The problem sits at the intersection of two trends: a labor market that normalized fully remote hiring without in-person verification, and AI tools cheap and realistic enough to fabricate a passable digital identity in an afternoon.

A 2022 Warning From The FBI

The Federal Bureau of Investigation’s Internet Crime Complaint Center first raised the alarm in a June 2022 public service announcement, warning of a rise in complaints describing deepfakes and stolen personally identifiable information used to apply for remote technology jobs. The bureau noted that many of the targeted positions involved access to customer records, financial systems, or proprietary corporate data, the kind of access that turns a hiring scam into a data-theft opportunity. The advisory came at a moment when video interviews had become the default for entry-level and mid-level technology roles, especially in software development, IT support, and database administration, precisely the fields the bureau said were most targeted. Employers were urged to treat inconsistent facial expressions, unusual blinking patterns, and mismatched audio timing as warning signs rather than dismissing them as a poor internet connection.

When The Lips Don’t Match The Voice

According to the FBI’s advisory, victims and hiring managers reported technical tells that gave the fraud away: coughs, sneezes, and other sounds that did not line up with what was shown on screen, or lip movements that trailed slightly behind the audio. Some applicants used voice-spoofing software that altered pitch and cadence in real time. Some hiring platforms have since added liveness-detection prompts that ask a candidate to move or speak an unscripted phrase, though adoption remains inconsistent across small and mid-sized employers who rely on off-the-shelf video tools. Security researchers have also noted that voice-cloning tools require only a short sample of a target’s real speech, meaning a scammer can impersonate a legitimate reference or manager during a supposed verification call.

The Real People Whose Identities Get Borrowed

Behind many of these schemes are real people who have no idea their information is being used. The FBI’s advisory noted that some individuals whose identities were used for job applications and background checks did not learn their information had been compromised until an employer’s human resources department tried to contact them. In practice, that means a real driver’s license number, a real employment history, and sometimes a real photo lifted from social media are combined with an AI-generated voice or face to build a composite candidate. Victims can be left untangling credit inquiries, background-check flags, or even tax paperwork tied to a job they never held, a burden that can take months to resolve even after a company discovers the fraud.

How One Cybersecurity Firm Hired North Korea By Accident

The risk is not hypothetical. Security-awareness company KnowBe4 disclosed in a 2024 blog post that it had unknowingly hired a software engineer who turned out to be a fictitious persona controlled by a North Korean operative. The applicant passed a background check, verified references, and four rounds of video interviews using a stock photo altered with artificial intelligence and a stolen U.S. identity. Malicious software began loading onto the company laptop within about 25 minutes of the new hire receiving it. The episode became one of the most cited case studies in corporate security circles precisely because KnowBe4 sells security-awareness training for a living, underscoring how convincing the fraud had become even for a company built to spot it. The firm said no sensitive data was stolen before its security team severed the connection.

A Multi-Year Pipeline Tied To Pyongyang

The KnowBe4 case fits a pattern federal prosecutors have been unwinding for years. The Justice Department has indicted more than a dozen North Korean nationals and the facilitators who allegedly helped them, describing a scheme in which operatives posed as remote information-technology workers at U.S. companies, often relying on so-called laptop farms run by American accomplices to make it look like the workers were logging in from inside the country. Investigators have said the funds were funneled through shell companies and cryptocurrency exchanges before reaching accounts tied to Pyongyang, and several of the American facilitators charged in related cases have pleaded guilty to identity theft and money-laundering counts. The Treasury and State Departments have separately sanctioned individuals and entities accused of facilitating similar schemes.

Why The Fakes Keep Getting Harder To Catch

The underlying technology has only gotten more convincing and more accessible since the FBI’s first warning. Deepfake software, which uses machine learning to graft one person’s face and voice onto another’s likeness, no longer requires specialized expertise or expensive hardware. Industry analysts at Gartner have projected that as many as one in four job candidate profiles worldwide could involve some form of AI-assisted misrepresentation by 2028, ranging from a touched-up résumé photo to a fully synthetic interview performance. Companies are responding with countermeasures such as requiring candidates to turn their heads or hold up a handwritten sign mid-interview, cross-checking government-issued identification against biometric databases, and mandating at least one in-person or live unscripted verification step before extending an offer. Some employers have begun requiring a final in-person meeting or a notarized identity check before issuing equipment, treating the video interview as a useful first filter but no longer a sufficient one.

This article was produced with the assistance of AI and reviewed by Morning Overview editors.


More from Morning Overview