Why Fake Candidates Stopped Standing Out in Your Pipeline

AI agents flooded your funnel with real applicants, which is exactly what gives fabricated ones somewhere to hide. Here is where the check has to move to.
Lauren Furey
September 23, 2026
Why Fake Candidates Stopped Standing Out in Your Pipeline

A recruiter reading 40 applications for a role develops a feel for the one that is wrong. The history does not quite hang together, the writing shifts register halfway down, something about the phrasing belongs to a different person than the one described at the top. That instinct is real, it took years to build, and it worked.

That same recruiter is now reading 400 applications, and all of them read as equally plausible.

The fraud itself has improved, and it will keep improving, because synthetic identities are getting more convincing and deepfakes are getting cheaper every quarter. What changed the detection problem, though, is scale. 

Candidates with entirely legitimate intentions started using the same tools, which raised the quality floor of the whole pile, so a fabricated applicant that once looked conspicuous now sits inside a crowd of perfectly reasonable submissions. Gartner found that 39% of candidates had already used AI in the application process as of late 2024, and that is the noise floor. In a separate Gartner survey of 3,000 candidates, 6% admitted to interview fraud, meaning they had posed as someone else or arranged for someone else to pose as them. Gartner projects that by 2028, one in four candidate profiles worldwide will be fake.

The volume is what makes the small percentage dangerous, because volume is where it hides.

Key takeaways

  • Fake candidates became harder to spot because genuine applicants started using the same AI tools, which raised the plausibility of the whole pile and removed the contrast a fabricated application used to stand out against.
  • Gartner projects one in four candidate profiles worldwide will be fake by 2028, and 6% of 3,000 surveyed candidates have already admitted to posing as someone else or having someone pose for them.
  • Human review was the detection layer that worked, and application volume has exceeded what human review can calibrate against.
  • Proof's own recruiting team, handling more than 100,000 applications a year, estimated the annual cost of interviewing people who were not who they claimed to be at over $650,000, almost all of it recruiter and interviewer hours rather than fraud loss.
  • Moving identity verification ahead of the first interview saved Proof's People Ops team an estimated $270,000 a year and settled the identity question before a recruiter ever joined a call.

Why does volume work in the fraudster's favour?

Because most of the flood is honest, and that is precisely what provides the cover.

If the extra 360 applications were obviously junk, the problem would be trivial. Filter the junk, review what remains, carry on. What actually arrived is a large number of real people, genuinely looking for work, using tools that produce competent and well-targeted applications. Their submissions deserve consideration, and they look almost exactly like the fabricated ones.

A reviewer calibrated on 40 applications has no calibration for 400. The instinct does not scale, and it was never going to, because it depended on having enough attention per application to notice something subtle. That attention has been divided by ten. The reason it matters for identity is that it destroyed the informal detection layer your team had been relying on without ever writing it down.

What does candidate fraud cost your recruiting team?

Proof receives more than 100,000 applications a year, with more than 1,000 candidates for every open role. As that volume grew, impersonation grew with it, and the recruiting team experienced it as a time problem well before anyone described it as a security problem. Dana Dimodica, a recruiter on that team, put it plainly: "The shift to remote-first hiring opened up vulnerabilities we hadn't seen before, where it became increasingly difficult to ensure that the person interviewing for a role was actually the person they claimed to be on their application."

Without a way to settle identity early, the team was on course to spend many hours per cycle interviewing people who were not who they claimed to be, and the estimated annual cost of that reached more than $650,000. Almost none of that figure is fraud loss in the conventional sense. It is recruiter and interviewer hours, plus the legitimate hires those hours were being taken away from.

That is the shape of the cost for most teams. A fabricated candidate who clears initial screening consumes coordination time first, then interviewer time across several rounds, drawn from people who have other jobs to do. The requisition stays open throughout, the hiring manager loses patience with a pipeline that keeps producing finalists who evaporate, and the shortlist gets rebuilt from scratch.

None of that appears in a fraud statistic. It appears in your time-to-fill, in recruiter capacity, and in your team's credibility with the hiring managers you serve.

Why is the interview too late to catch this?

The interview is where fraud becomes visible and also where it becomes expensive, which makes it a poor place to put your only check.

Catching a fabricated candidate in round three means you have already paid for rounds one through three. Catching them at intake costs nothing beyond the check itself. The economics only work in one direction, and they point at the top of the funnel, where the constraint is that no team can manually review at the volume now arriving.

This is the change Proof's own People Ops team made. Rather than a manual ID request somewhere in the middle of the process, candidates received a secure link to verify a government ID and biometric before the first-round technical interview, which meant that by the time a recruiter joined a call, the identity question was already settled and the conversation could be entirely about the candidate's skills. The team estimated the saving at $270,000 a year.

How Proof restores the detection layer

Proof's candidate fraud solution is built for exactly this shape of problem, with a passive layer that reads every applicant and real verification reserved for the ones that warrant it.

Defend runs the moment an application arrives, evaluating the submitted details against risk signals that surface synthetic identity patterns, high-risk contact data, and behavioural anomalies, drawing on device fingerprinting, location risk data, email age, and behavioural analytics among others. A risk score writes back into your applicant tracking system, so your recruiters see it in the workflow they already live in and can filter on it without learning a new tool. The candidate experiences nothing and your process does not change. This is the layer that does at 400 applications what your team used to do at 40.

Identify handles the applicants those signals single out, confirming a government ID and running a liveness check to establish that the person is real and matches whoever submitted the application. Depth is configurable by role, team, or risk level, which matters because a seasonal coordinator and an engineer with production access carry very different exposure. Results write back to your ATS natively.

For high-stakes roles the verified identity travels with the candidate through the interview loop, so your team is working from an established record, and before an offer is signed a trained Proof identity agent can join the session with the full picture of prior signals and verifications, with deepfake detection running live.

Proof connects to the tools your team already uses, including Greenhouse and Lever, deploys in hours through no-code EasyLinks and ATS webhooks with no engineering work, and is NIST IAL2 compliant.

And about the candidate experience - since that’s the first objection to any verification step. When our own People Ops team moved Identify to the front of the process, the effect on candidates ran the opposite direction to what they expected. As Dana Dimodica described it, "Integrating Identify into our recruitment workflow didn't just add a layer of security; it actually gave our candidates more confidence in us as a company," replacing what she called "manual, awkward ID requests" with something that felt like a natural part of the brand. Ashley Bird, who leads People Operations and Experience at Proof, framed the result this way: "In a world where remote work is the standard, you can't afford to guess who you're hiring."

The one thing that cannot be generated

An agent can produce a resume, a cover letter, a work history, a portfolio, and a well-judged answer to every screening question you ask, and it will keep getting better at all of it. What it cannot produce is a specific human being, confirmed as themselves, at a moment you can point to afterward.

Every signal that lives inside the content of an application has become cheap to manufacture, which is why the durable check is the one that asks whether a real person is present and whether they are who they claim to be. Your recruiters used to answer that question by instinct across 40 applications. At 400, they need it answered before the pile reaches them.

Book a demo to see passive screening and triggered verification on your funnel >

graphic of envelop on a square

Subscribe to our newsletter

Related Articles