How to Prevent Hiring Fraud and Candidate Impersonation With Identity Verification

‍Fraud is becoming more common in the hiring and employment space. With Proof's Identify solution, you can ensure that the person who accepted your position is the same person who shows up for work on the first day.
Gayle Weiswasser
July 25, 2024
How to Prevent Hiring Fraud and Candidate Impersonation With Identity Verification

Updated August 20, 2026

Hiring fraud is no longer a fringe problem. Gartner projects that by 2028, one in four job candidates worldwide will be fake. The FBI has issued multiple warnings about state-sponsored actors using fabricated identities to infiltrate U.S. companies. And the tools required to build a convincing fake candidate, including AI-generated resumes, deepfake video, and stolen credentials, now cost less than $100.

The threat has a specific shape: candidates apply using someone else's identity, pass interviews using AI-assisted video, and show up on day one as a completely different person. Or they never show up at all, having already established remote access to your systems. Traditional hiring controls, background checks, video interviews, reference calls, were built for a different era. They cannot catch this.

Proof Identify is an identity verification solution that can be deployed into recruiting and onboarding workflows without writing a single line of code. It verifies that the person who applied is the person who interviewed, and that the person who interviewed is the person who shows up on day one.

Key takeaways

  • Gartner projects one in four job candidates will be fake by 2028, and the FBI has documented state-sponsored actors using fabricated identities to infiltrate U.S. companies.
  • Video interviews, background checks, and reference calls cannot reliably detect AI-assisted impersonation or deepfake candidates.
  • Hiring fraud prevention requires identity verification at multiple stages: application, pre-interview, and day-one onboarding, not just post-offer background screening.
  • Proof Identify runs government ID checks, biometric matching, and liveness detection in under five minutes, producing an auditable identity report your team can act on.
  • The solution requires no code to deploy and integrates with existing applicant tracking systems via API, EasyLink, or QR code.

The threat landscape: what hiring fraud actually looks like

Hiring fraud takes several distinct forms, and each one exploits a different weakness in the standard recruiting process:

  • Candidate impersonation is the most operationally dangerous. A fraudster applies using a real or fabricated identity, passes screening, and then either sends a proxy to do the actual work or establishes remote access and outsources the role entirely. The hiring team never realizes the person they interviewed is not the person on payroll.
  • AI-assisted interview fraud has made impersonation significantly harder to detect. Candidates now use real-time AI tools to alter their appearance on video, generate answers to technical questions, and lip-sync responses. One documented case involved a candidate who maintained a convincing deepfake persona through a 70-minute technical interview before being caught.
  • Resume and credential fabrication has become industrialized. Generative AI can produce a perfectly formatted resume tailored to a specific job description in seconds, including fabricated employers, titles, and skills. Recruiting teams at some companies report that 78% of engineering applicants show signs of coordinated fraud.
  • State-sponsored infiltration represents the highest-stakes variant. The FBI has documented North Korean nationals using fake identities costing less than $100 to secure remote IT roles at U.S. companies. Once hired, they build security backdoors, exfiltrate intellectual property, and funnel earnings to sanctioned entities. One VP of recruiting reported catching 200 state-sponsored actors attempting to infiltrate their company in a single year.
  • Fraud rings compound the problem further. When one fraudulent hire gets through, they use insider knowledge of your hiring process to coach additional fake candidates. A single bad actor inside a large remote workforce can map your defenses and share that map with an organized network.

Why traditional hiring controls fail

Standard hiring controls were designed to verify credentials, not identity. That distinction matters enormously now.

Background checks happen too late. Most background screening occurs post-offer, after the hiring decision has already been made. By that point, the fraudster has already passed every human-facing stage of your process. And background checks verify that a name and Social Security number match a record. They do not confirm that the person sitting in the interview is the person attached to that record.

Video interviews are no longer trustworthy. Seeing a face on a screen is no longer sufficient confirmation of identity. Deepfake tools can generate convincing video in real time. Liveness checks, where a recruiter asks a candidate to wave or cover one eye, can detect some deepfakes but are not reliable against more sophisticated tools. Recruiters are not fraud analysts. Expecting them to catch AI-assisted impersonation through visual inspection is not a strategy.

Reference checks and employment verification are gameable. Fraudsters set up fake employer websites, use burner phones to pose as references, and coach accomplices to confirm fabricated work histories. KnowBe4, a security awareness training company, conducted video interviews, confirmed the candidate matched their application photo, ran background checks, and followed up with references. They still hired a North Korean IT worker who immediately began loading malware onto a company workstation. The fraud was only discovered after the hardware was shipped.

The identity gap is structural. There is no standard checkpoint in most hiring workflows where a candidate's government-issued identity is verified against their face in real time. That gap is exactly what organized hiring fraud exploits.

How to prevent hiring fraud at every stage of the process

Hiring fraud prevention requires layered identity verification across the recruiting lifecycle, not a single check at one point in the funnel.

Verify identity before the first interview

The highest-leverage intervention is identity verification before any recruiter time is invested. Running a government ID check and biometric comparison at the application or initial screening stage eliminates fake and duplicate applicants before they consume interview capacity.

Proof Identify handles this with a five-step flow: the candidate receives a QR code or EasyLink, captures their government-issued ID, takes a selfie, completes a liveness check, and submits. Proof runs credential analysis, biometric matching, and fraud signal detection automatically. The result is an identity report your team can review before scheduling a single call.

If a candidate fails automated verification, the flow escalates to a live Proof agent for human review. No code is required on your side.

Authenticate candidates before high-stakes interviews

For roles with access to sensitive systems, financial data, or intellectual property, a second verification checkpoint before the final interview round adds a critical layer of assurance. This confirms that the person progressing through your funnel is the same person who passed initial screening.

Red flags that warrant additional scrutiny at this stage include:

  • Slight video lag or audio that does not sync with lip movement
  • Unnatural blinking patterns or facial artifacts in video
  • Reluctance to perform simple liveness tasks (covering one eye, holding up fingers)
  • IP address that does not match the candidate's stated location
  • Email or LinkedIn account created within the past 30 days
  • Resume language that mirrors the job description verbatim
  • Multiple applications from different names with identical contact details

Detect deepfakes in live video

Proof's Defend layer analyzes live video sessions for deepfake signals, including synthetic face detection, facial artifact analysis, and behavioral anomalies. This runs in the background during verification sessions and flags risk indicators for human review.

Recruiters should not be expected to catch deepfakes through observation alone. Automated detection closes that gap.

Confirm identity on day one

The final verification checkpoint is onboarding. Running a Proof Identify transaction on the first day confirms that the person who shows up is the same person who completed verification during recruiting. This is the check that catches proxy candidates who pass the interview process and then send someone else to do the work.

This step takes under five minutes and can be completed remotely. The identity report from onboarding is stored alongside the recruiting-stage report, creating an auditable chain of identity evidence across the full hiring lifecycle.

Integrating identity verification into your hiring workflow

The most common reason hiring teams skip identity verification is workflow friction. Adding a separate system, managing a new vendor, and asking candidates to complete an unfamiliar step all create resistance.

Proof Identify is designed to eliminate that friction. Deployment options include:

  • QR code: Generate a QR code that candidates scan with their phone to complete verification. No app download required.
  • EasyLink: Send a direct link via email or your ATS that opens the verification flow in a browser.
  • API: Embed Proof Identify directly into your existing applicant tracking system for a fully integrated experience.

Proof now integrates directly with Lever, enabling hiring teams to trigger identity verification from within their existing ATS without managing a separate system. The identity report surfaces inside the recruiter's existing workflow.

For high-volume recruiting operations, Proof provides dashboards that aggregate identity reports across all candidates, flag risk signals, and give hiring managers a clear view of verification status at every stage of the funnel.

The business case for hiring fraud prevention

The cost of a fraudulent hire extends well beyond the salary paid to someone who was not who they claimed to be.

A single North Korean IT worker who gains access to your systems can exfiltrate intellectual property, install persistent backdoors, and compromise customer data. The remediation costs, legal exposure, and reputational damage from a single incident can run into the millions. The KnowBe4 incident, where the company caught the fraud before significant damage occurred, still required a full forensic investigation, hardware replacement, and public disclosure.

For companies processing high volumes of applications, the economics of fraud prevention are straightforward. Proof Identify costs a fraction of the recruiter time wasted on fake candidates who consume screening, interviewing, and onboarding resources before the fraud is discovered.

graphic of envelop on a square

Subscribe to our newsletter

Related Articles