You already know something has shifted in remote hiring. The candidate on the video call answers a little too smoothly. The camera stays off “for bandwidth reasons.” The person who shows up on day one doesn’t quite match the person who interviewed three weeks earlier. For years those were odd exceptions, the kind of thing you’d mention to a colleague over coffee and forget by lunch.
Not anymore. Recruiters this year are naming fraudulent or AI-assisted candidates as their single biggest hiring headache, ahead of the usual complaint about not finding enough qualified people. And it’s not paranoia. Nearly two in five companies say they’ve unknowingly hired someone who wasn’t who they claimed to be.
Three Kinds of Fraud, Not One
It helps to stop thinking of “candidate fraud” as a single problem, because the people doing it want very different things.
Some are just trying to get through the interview. AI-generated answers whispered through an earpiece, or a second screen feeding responses in real time, that’s the low end. A Greenhouse survey found 91% of US hiring managers have caught, or strongly suspected, this happening on a live call. It’s cheap to pull off and it’s spreading fast; one vendor tracked deepfake attempts in hiring jumping over 1,000% in a single year.
Some want the paycheck without the identity attached to it. This is where it gets serious. North Korean IT workers have been quietly applying for remote roles under stolen or fabricated identities, then routing their wages back to state agencies. One security firm found signs of this in roughly 1 out of every 47 applicants it screened this year, up sharply from about 1 in 343 the year before. The money adds up too, an estimated $500 million a year flowing back to the regime, and researchers believe nearly every Fortune 500 company has brushed up against it without realizing.
And some are just lying, the old-fashioned way, on the resume. Sixty-four percent of US adults admit to it now. Among candidates in their early twenties, that number climbs past 80%. AI didn’t invent this problem. It just made fabricated work samples and polished cover letters a lot easier to mass-produce.
There’s a fourth pattern worth naming too: someone sharp handles the interview, and a completely different, far less capable person shows up for the actual job. Picture two developers who look nothing alike on camera but somehow give near-identical answers to the same technical prompts, weeks apart, for two different roles at two different companies. That’s not a coincidence, that’s a team running a playbook. It works at scale because the volume overwhelms review before a human ever gets involved; security researchers have watched automated tools submit hundreds of applications a day on a fraud ring’s behalf, far more than any recruiter could ever manually vet.
Why the Old Screening Process Misses All of This
Think about what hiring used to rely on. A phone screen. An in-person interview. A gut sense that you were talking to one consistent, real person across every step. None of that assumption survives remote hiring intact.
There’s no reliable way to confirm someone’s location or identity over a video call unless you build a check for it on purpose. A candidate can say they’re calling from Denver while sitting anywhere on earth, and short of asking them to walk to a landmark, most recruiters have no way to push back on that. Voice cloning and real-time video manipulation used to require a production studio. Now it’s a free download and a decent laptop. Add a fraud operation that can automate hundreds of applications a day, and the bottleneck isn’t what a recruiter happens to notice anymore. It’s whether anything gets verified before a human even opens the file.
What Recruiters Are Doing Right Now
The most common fix so far is actually a step backward: bringing back in-person interviews specifically to counter this. Nearly three-quarters of recruiting leaders have already done it. It works, in the sense that it’s hard to fake a physical room, but it doesn’t scale for a distributed or global team, and it quietly undoes years of building a more flexible hiring model. A company that spent five years arguing for remote-first hiring is now flying candidates in for a first round interview because the alternative feels riskier. That’s a real signal about how badly the trust in video calls has eroded.
A better long-term answer is verifying identity at the point it actually matters instead of trusting a recruiter’s read of a screen. That means three things in practice:
- Confirming the person on the call matches a government-issued ID
- Checking for liveness, so a static photo or looped video can’t pass as a real participant
- Doing it early enough that it isn’t just cleanup after an offer has already gone out
The Legal Tightrope
Here’s the part that makes this harder than “screen more.” Push too hard on identity checks and a company opens itself up to a different kind of risk.
Flag a candidate because of an accent, a work history gap, or a name that doesn’t fit an assumed pattern, and that’s a fast route to a discrimination claim, whatever the recruiter actually intended. Whatever check gets added has to apply the same way to everyone at a given stage, not just to the people who happen to raise an eyebrow.
But there’s real liability on the other side too. Legal teams tracking the North Korean IT worker problem specifically flag OFAC sanctions exposure as its own risk, separate from the data security concerns everyone talks about. That’s a big part of why identity verification is starting to get treated as a compliance requirement rather than a nice-to-have, especially at fintech and crypto companies that already think in KYC terms.
The middle ground is consistency. A verification step applied the same way to every candidate, at the same stage, holds up a lot better if a hiring decision ever gets challenged, from either direction, than a recruiter’s gut instinct does.
A Practical Way to Screen for This
Not every role needs the same scrutiny, and treating every remote applicant like a suspect creates its own mess since most of them are exactly who they say they are. What tends to work better in practice is triage based on actual risk, not a blanket policy applied to everyone the same way.
Start with the cheap signals: a camera that conveniently fails during technical questions, a voice that doesn’t match lip movement, answers that are correct but oddly generic. None of these prove fraud alone, but stacked together, they’re worth a second look instead of an automatic pass.
For roles with access to sensitive data or source code, confirm identity before credentials go out, not somewhere in parallel with a background check that wraps up after onboarding has already started. By the time that check flags something, a fraudulent hire has often had system access for weeks.
This is where ID verification software actually earns its place, at the exact gap a resume check or a LinkedIn scan can’t close. A photo of a stolen ID is enough to fool a system that only checks whether a document looks legitimate. Liveness detection, confirming a real person is present and matches that document right now, is what closes it.
Route anything inconclusive to a human, not to an automatic rejection. Older documents, unfamiliar name formats, and bad lighting all produce false positives against people who are entirely legitimate, and an overzealous system that auto-rejects on the first mismatch will quietly filter out good candidates alongside the fraudulent ones.
And check the whole pipeline, not just one checkpoint. The name on the application, the ID used to verify, and the identity eventually provisioned for payroll should all match. Fraud rings count on nobody comparing those three names side by side.
What This Actually Costs
A single bad hire runs 30 to 50% of that role’s annual salary once you count recruiting, onboarding, and lost productivity, and industry-wide losses from hiring fraud now sit around $600 billion a year. For a fabricated resume, that’s an expensive mistake. For a state-sponsored infiltration, it’s a different category of problem: data exfiltration, sanctions exposure, and system access a standard background check was never built to catch.
So ask the blunt question before this year’s hiring plan gets locked in. Does the process confirm who someone actually is before they’re sitting behind a laptop with live credentials? Or does it only confirm what they typed on a resume? Those used to be close enough to the same question. They aren’t anymore.




