1 in 4 Candidates Could Be Fake by 2028. Remote Hiring Needs Proof, Not Paperwork

On this page
By CloudHire Editorial · 8 October 2026 · 12-minute read
Quick answer: Candidate fraud is now common enough to plan for. In a 2025 Gartner survey of 3,000 job candidates, 6% admitted to interview fraud, either impersonating someone or having someone impersonate them, and Gartner predicts that by 2028 one in four candidate profiles worldwide will be fake. To verify a remote candidate, check a government ID, match it to a live face with a liveness check, and keep that same verified face attached to every interview round. Do it before the first interview, not after the offer.
For most of the history of hiring, nobody had to ask whether the person across the table was real. The table took care of it. A handshake, a shared room and a face that matched the name on the badge – did the identity work before a single question was asked.
Remote hiring removed the table, and with it the check nobody knew they were running. What is left is a quiet assumption buried in every video interview: that the face on the screen belongs to the name on the résumé. That assumption is now being tested at scale, by people with good reasons to break it and better tools to do so.
This article explains what candidate fraud is, how common it has become, why the usual safeguards miss it, and what a working fix looks like. CloudHire’s position is simple. Background checks verify a history. Remote hiring now has to verify a person, live, at the interview. Verification belongs at the top of the funnel, not the end.
What is candidate fraud, and why should hiring teams care?
Candidate fraud is any attempt by a job applicant, or someone acting for them, to misrepresent who they are or what they can do in order to get hired. In remote hiring it takes four main forms: proxy interviews, deepfake video, stolen or synthetic identities, and AI-scripted answers delivered live.
It is different from résumé embellishment. An inflated job title exaggerates a real person’s history. Candidate fraud puts the wrong person, or no real person at all, in the seat.
Why it matters: a fraudulent hire does not just underperform. They receive a laptop, system credentials, access to customer data and source code, and a salary. The cost of getting it wrong is no longer a bad quarter with a weak engineer; it is a security incident with a payroll attached.
Who it is for: hiring managers, talent acquisition leads, HR operations teams and founders who hire remotely, and especially those hiring across borders, where the candidate and the interviewer may never share a city, let alone a room.
What counts as candidate fraud?
Candidate fraud covers four distinct tactics, and each one defeats a different safeguard. Treating them as one problem is why most fixes only catch one of them.
| Type of fraud | What it is | How it shows up in a remote interview |
| Proxy interview | A different, more qualified person attends the interview in the candidate’s place, or answers for them off-camera. | Lip movement out of sync with audio, a voice that changes between rounds, a candidate on day one who cannot do what “they” did in the interview. |
| Deepfake candidate | AI-generated or face-swapped video and cloned voice present a person who is not the one speaking. | Blurring or warping when the face turns or a hand passes in front of it, flat lighting, unnatural blinking, audio that lags. |
| Stolen or synthetic identity | The applicant uses a real person’s identity, or a fabricated one assembled from real fragments. | Documents that look right but do not match the live face, thin or recently created online profiles, contact details that point to different places. |
| AI-scripted answers | A real candidate reads answers generated live by an AI tool or fed by a helper. | A steady pause before every answer, eyes tracking a second screen, polished answers that collapse under a simple follow-up. |
What is a proxy interview?
A proxy interview is a job interview in which someone other than the actual candidate answers the questions, either by appearing on camera in their place or by feeding answers from off-screen. The person who interviews is not the person who turns up for work. It is the oldest form of interview fraud, and remote hiring has made it cheap: a proxy no longer needs to travel, only to log in.
What is a deepfake job candidate?
A deepfake job candidate is an applicant whose face, voice or both are generated or altered by AI during a video interview. The technology that once needed a studio now runs on a laptop in real time. As we covered in identity verification in the age of AI, human eyes and ears are no longer a reliable test of what is real on a screen.
If your only identity check is “the interviewer saw their face,” you have no identity check against two of these four tactics.
How common is candidate fraud in 2026?
Candidate fraud is common enough to show up in an ordinary hiring pipeline, and the trend is moving in one direction. The most cited numbers come from Gartner’s candidate research and from the FBI.
- 1 in 4 by 2028. Gartner predicts that by 2028, one in four candidate profiles worldwide will be fake. [1]
- 6% admit it. In a Gartner survey of 3,000 candidates in the second quarter of 2025, 6% admitted to participating in interview fraud, either posing as someone else or having someone else pose as them. [1]
- 39% use AI to apply. In a Q4 2024 survey of 3,290 candidates, 39% said they used AI during the application process. Of those, 54% used it to generate résumé text and 29% used it to generate answers to assessments. [1]
- 62% would welcome in-person rounds. In the same Q2 2025 research, 62% of candidates said they were more likely to apply if the employer required in-person interviews. [1]
- A national-security problem, not just an HR one. The FBI has publicly warned that North Korean IT workers use stolen identities, US-based facilitators and AI tools in interviews to get hired into remote roles at US companies. [2] In late July 2026, an FBI official disclosed that a North Korean remote IT worker had been found working for a US federal agency, a case reported widely in August 2026. [3]
Two points of context matter. First, 6% is the share of candidates who admitted fraud in a survey. Self-reported dishonesty is a floor, not a ceiling. If that rate held across your pipeline, a slate of 50 interviewed candidates would include about three people who were not who they said they were.
Second, AI use is not the same as fraud. A candidate who uses AI to tidy a résumé is simply using a writing tool. A candidate who reads AI-generated answers in a live technical interview, or lets a cloned voice speak for them, is misrepresenting what they can do. The line is the moment the tool stops helping the candidate and starts replacing them.
The question is no longer whether fraud reaches your pipeline, but at which step you find it.
Why are remote roles the main target?
Remote roles are the main target because, for many employers, the video interview is the only point at which anyone checks who the candidate is, and a screen is far easier to fake than a room. Three things make remote roles attractive to fraud.
- Access without presence. A remote engineer receives credentials, code and data without ever entering a building, so the payoff of a successful impersonation is high.
- Distance hides the swap. When interviewer, candidate and manager are in different countries, the person who interviewed and the person who works are rarely compared side-by-side.
- The process was built for trust. Most remote hiring processes were designed in a period when nobody expected an applicant to be synthetic. They check skills carefully, but identity barely at all.
The FBI’s guidance on the North Korean scheme describes exactly this pattern: facilitators who receive company laptops, US addresses that mask overseas workers, and interview impersonation, with advice that interviewers ask a candidate to wave a hand in front of their face because it can make AI-generated video glitch. [2]
Is forcing in-person interviews the answer?
No. Forcing in-person interviews treats the symptom and taxes the talent pool. It is an understandable reaction. Several large employers, including Google, Cisco and McKinsey, were reported in August 2025 to be bringing back in-person rounds because of AI cheating and impersonation. [4] Gartner’s finding that 62% of candidates would welcome in-person interviews makes the move look popular.
But the cost falls on exactly the people remote hiring exists to reach. A mandatory flight for a 45-minute round shuts out the strong engineer in Pune, Manila or São Paulo who was never going to relocate, and it rewards whoever happens to live near your office. It also moves the fraud rather than ending it: a candidate verified in-person in round three of the interview process, can still hand the laptop to someone else in week one of the job.
The better fix keeps hiring global and makes identity checkable remotely. Verify identity remotely, at the start, and keep verifying it.
Location is not a red flag. A mismatch between the verified person and the person on screen is.
Why do background checks miss candidate fraud?
Background checks miss candidate fraud because they verify a history, not a person. A background check confirms that a name has a clean record, real past employers and a real degree. A stolen identity has all three. That is what makes it worth stealing.
Timing is the second problem. Background checks usually run after the offer, when the interview hours are already spent and the hiring manager is emotionally committed to the candidate. If you verify last, you have already paid for the fraud.
| Background check | Forcing in-person interviews | Identity verification before the interview | |
| What it verifies | That a name’s history is real | That someone physically attended | That the live person matches a real, verified identity |
| When it happens | After the offer | Usually after a few interview rounds | Before the first live interview |
| Catches a stolen identity? | Rarely; the stolen history checks out | Only if ID is checked in person | Yes; the ID must match a live face |
| Catches a proxy interview? | No | Only for the in-person round | Yes, if the verified face is bound to every round |
| Catches a deepfake? | No | Yes, for that round | Yes, with liveness detection |
| Cost to genuine candidates | Low | High: travel, time off, excludes distant talent | Low: a few minutes online |
| Works across borders? | Varies by country | Poorly | Yes |
This is why we at CloudHire say, an interview you didn’t verify is a conversation, not evidence. It may be a good conversation. It may even be with the right person. But you cannot prove it, and a hiring decision built on unproven inputs is, as we argued in false-positive hires are usually an evidence problem, a decision built on a performance.
Background checks are a must and should continue. It addresses a different challenge. Add a process check that answers “is this the person?” before anyone from your team spends an hour interviewing candidates.
What does verification before the interview look like?
Verification before the interview means three checks, in order: a government ID, a live face matched to that ID, and a profile that keeps the verified identity attached to every interview that follows. Each layer closes a gap the previous one leaves open.
Layer 1: Government ID verification
The candidate submits a government-issued ID, which is checked for authenticity. On its own this proves only that a valid document exists, which is why it cannot be the only or last step. For India-based candidates, CloudHire cross-matches Aadhaar and PAN against the identity presented, a level of national-ID confirmation that, as our data verification guide explains, has no clean equivalent in the US verification ecosystem.
Layer 2: Liveness check and face match
A liveness check confirms that a real human is in front of the camera, not a photo, a replayed video or a synthetic face. A face match then compares that live face with the ID photo. This is the step that defeats most stolen identities: the documents may be real, but the face holding them is not the face on them.
Layer 3: An interview-attached profile
The verified identity must travel with the candidate into every round. If the face is checked at onboarding but never again, a proxy simply joins after verification. The fix is persistence: the same face, checked continuously, at minute zero and minute sixty of every interview, with the recording attached to the candidate’s profile so the hiring manager sees exactly who was assessed.
How CloudHire does this with Cloud-ID
At CloudHire, all three layers sit inside Cloud-ID, the verified credential record behind every CloudHire candidate. Cloud-ID combines government ID verification with live facial capture and biometric persistence across every assessment session, plus verified employment history, education and right-to-work status, so the employer sees one verified record rather than a stack of claims.
During the AI interview itself, the Integrity Engine checks that the face on screen at the start is still the face on screen at the end and looks for signs of off-screen help such as reading patterns, a second voice in the room or answers that do not match the candidate’s own rhythm. Candidates who trip multiple signals are removed before they reach a hiring manager.
The difference is timing. Everyone else detects fraud after a suspicious candidate turns up; we verify before the shortlist exists.
Verification is the new top of the funnel. Every hour of interviewing that happens before it is an hour you may have spent on someone who does not exist.
How do you stop candidate fraud? A 5-step checklist for hiring managers
You can cut most remote candidate fraud with five changes to where and how you verify, without forcing anyone onto a plane.
- Move identity verification to the top of the funnel. Require government ID, a liveness check and a face match before the first live interview, not after the offer. If you verify last, you have already spent the interview hours.
- Bind the verified identity to every round. The person in round three must be checked against the same verified face as round one. Record interviews, with consent, and attach them to the candidate’s profile so the hiring manager can compare.
- Design interviews that are hard to outsource. Ask candidates to walk through code or decisions they claim as their own and follow every polished answer with a “why” and a “what would you change.” Scripted help is fast at first answers and slow at second ones.
- Re-verify at every handoff. Repeat a quick face match at offer, at onboarding and on the first day. Check that the laptop shipping address matches the verified address; the FBI has described facilitators who receive company laptops on behalf of overseas workers. [2]
- Treat signals as evidence, not accusations. Write down which signals trigger a second check, apply them to every candidate equally, and give genuine candidates a fair way to clear a false alarm. Poor bandwidth and old webcams are not fraud. Location is not a red flag; a mismatch is.
How do you detect a proxy interview that is already happening?
To detect a proxy interview, watch for a mismatch between the person, the voice and the answers. The most reliable signs are:
- Lip movement that lags or does not match the audio.
- A voice, accent or speaking pace that changes between rounds.
- A consistent pause before every answer, or eyes tracking a point off-screen.
- A camera that is “broken” or a background that stays heavily blurred when the candidate is asked to adjust it.
- Polished first answers that collapse under a simple, unscripted follow-up.
- Distortion around the face when the candidate turns their head or passes a hand in front of it, a check the FBI recommends. [2]
None of these signs proves fraud on its own. Together, they justify pausing the process and re-running identity verification before anyone invests another hour.
FAQ
What is a proxy interview?
A proxy interview is a job interview in which someone other than the real candidate answers the questions, either by appearing on camera in their place or by feeding answers off-screen. The person hired is then not the person who was assessed.
How common is candidate fraud in remote hiring?
In a 2025 Gartner survey of 3,000 candidates, 6% admitted to interview fraud, and Gartner predicts one in four candidate profiles worldwide will be fake by 2028. Because the survey figure is self-reported, the real rate is likely higher.
How do you verify a remote candidate’s identity?
Check a government-issued ID, confirm a live person is present with a liveness check, match that live face to the ID photo, then keep the verified face attached to every interview round. Do it before the first interview, not after the offer.
Can a background check detect a proxy interview?
No. A background check verifies a name’s history, such as records and past employers. It does not confirm that the person in the interview is the person named, and it usually runs after the offer.
Is using AI to write a résumé candidate fraud?
Not by itself. Using AI to improve wording is using a writing tool. It becomes fraud when AI or another person answers live interview or assessment questions in the candidate’s place, misrepresenting what they can do.
Should employers bring back in-person interviews to stop fraud?
In-person interviews stop impersonation for that round. However, they exclude strong remote and international candidates, and do not stop a swap after hiring. Remote identity verification with a liveness check protects the process without shrinking the talent pool.
How can you spot a deepfake candidate on a video call?
Look for warping around the face when the head turns, audio that lags the lips, flat lighting and unnatural blinking. Asking the candidate to pass a hand in front of their face can make AI-generated video glitch. A pre-interview liveness check is more reliable than spotting by eye.
What is Cloud-ID?
Cloud-ID is CloudHire’s verified credential record for each candidate. It combines government ID verification, live facial capture with biometric checks across every assessment, and verified work history, education and right-to-work status, so employers see who was actually interviewed.
Proof, not paperwork
The hiring process we inherited was built to answer one question: can this person do the job? Remote hiring has quietly added a second question that comes before it: is this the person? Paperwork cannot answer that. A clean background check, a well-written résumé and a confident interview can all belong to someone who is not on your call.
The answer is not to retreat to the office and give up the global talent remote work made reachable. It is to move proof to the front: verify the person live, keep that verification attached to every round, and let the interview do what it was always meant to do, which is to assess skill rather than guess identity.
One in four profiles may be fake by 2028. The firms that hire well over the next three years will not be the ones with the toughest interviews. They will be the ones that knew who they were interviewing.
Get a Cloud-ID verified shortlist
Author: CloudHire Editorial
About CloudHire Editorial: CloudHire Editorial is the research and writing team at CloudHire, the hiring platform that connects US companies with verified, interview-tested professionals in India. We write about remote hiring, candidate verification and AI in recruiting, using public data with every source cited.
Sources
- Gartner, “Gartner Survey Shows Just 26% of Job Applicants Trust AI Will Fairly Evaluate Them”, press release, 31 July 2025. https://www.gartner.com/en/newsroom/press-releases/2025-07-31-gartner-survey-shows-just-26-percent-of-job-applicants-trust-ai-will-fairly-evaluate-them
- FBI, “North Korean IT Worker Threats to U.S. Businesses”, public alert, 23 July 2025. https://www.fbi.gov/investigate/cyber/alerts/2025/north-korean-it-worker-threats-to-u-s-businesses
- Federal News Network, “FBI investigating North Korean remote IT staffer working for U.S. agency”, August 2026; TechCrunch, 11 August 2026. https://federalnewsnetwork.com/technology-main/2026/08/fbi-investigating-north-korean-remote-it-staffer-working-for-u-s-agency/ · https://techcrunch.com/2026/08/11/north-korean-remote-it-staffer-worked-for-us-government-agency-says-fbi/
- Reported by The Wall Street Journal, 12 August 2025; summarized by the OECD AI Incidents Monitor. https://oecd.ai/en/incidents/2025-08-12-0f22
Hire faster with CloudHire
Search 700M+ profiles, run AI interviews and launch outreach on one platform — free to start, no demo call required.