Your Hiring Process Has a Fraud Problem. Most Organizations Don't Know It Yet.
- mracine61
- Jun 17
- 5 min read
Candidate fraud is not new. People have always stretched the truth on resumes. What is new is how much easier AI has made it, how many forms it now takes, and how serious the consequences have gotten for organizations that are not paying attention.
The threat landscape in hiring has quietly shifted from individual dishonesty to something more systematic. Automated bots are flooding applicant tracking systems at scale. Job seekers are using AI to fabricate credentials they do not have. Deepfake technology is showing up in live video interviews. And in documented cases, nation-state operatives have been sitting inside U.S. companies for months, collecting salaries and stealing data.
These are not hypothetical risks. They are happening now, across organizations of every size, and most hiring teams have not updated their processes to account for any of it.
The Bot Flooding Problem
Before a single human even looks at an application, the volume problem has already arrived.
Automated tools can generate and submit job applications at a scale no recruiter can match. The result is applicant tracking systems clogged with low-quality or entirely fabricated submissions, recruiters drowning in volume, and the hiring funnel collapsing.
This is not always malicious. Some of it is candidates using aggressive automation tools to maximize their application volume. But it creates a structural problem either way. When your ATS is processing thousands of applications for a role that realistically has a few dozen qualified candidates, the filtering logic starts making decisions that no one has actually reviewed.
The downstream effect is that legitimate candidates get lost, recruiting time expands, and organizations start relying more heavily on automated screening tools that introduce their own bias risks, as covered in a previous post on this blog.
AI Resume Fraud: The Credential Gap
Separate from bots, there is a growing category of fraud that is harder to see and more personal. People are using generative AI to write resumes that describe skills, experience, and accomplishments they do not actually have.
This goes well beyond polishing language or improving formatting. Candidates are generating descriptions of projects they did not lead, technical skills they have not used, and quantified achievements that have no basis in reality. The output looks professional and often passes initial screening, precisely because AI-generated content reads like well-written human content.
A 2025 Greenhouse survey of more than 4,000 hiring managers found that 91% had encountered or suspected AI-generated interview answers during online interviews. Checkr's 2025 Hiring Hoax survey found that hiring fraud in this broader sense, including misrepresented credentials, touched a significant share of organizations. The resume is no longer a reliable proxy for what a candidate can actually do, and the interview is increasingly unreliable too when candidates are feeding scripted AI-generated answers in real time.
The practical consequence is that organizations are hiring people who do not have the skills the role requires, discovering the mismatch after onboarding, and absorbing the cost of the bad hire. For roles with real technical requirements, that cost can be substantial.
Deepfake Impersonation: When the Interview Itself Is Faked
The fraud escalates from credential exaggeration to full identity manipulation when deepfake technology enters the picture.
Deepfake video tools can alter a person's appearance and voice in real time during a live video call. A candidate can present as a different person entirely while the interviewer believes they are conducting a normal screen. In some cases, a more qualified person conducts the interview, and a different person is hired and shows up for the job.
The numbers on this are striking. A 2025 Greenhouse survey found that 31% of hiring managers had personally interviewed a candidate they suspected or confirmed was using a fake identity via deepfake technology. Gartner estimates that by 2028, one in four job candidates globally will be a synthetic or fake persona. A separate Gartner survey of 3,000 job candidates found that 6% admitted to participating in interview fraud.
These are not edge cases in specialized industries. They are showing up across tech, finance, and professional services roles at a meaningful rate.
The Nation-State Layer: North Korean IT Workers
At the extreme end of the spectrum sits a threat that most HR leaders still treat as someone else's problem. It is not.
The U.S. government has spent years building criminal cases against North Korean nationals who infiltrate U.S. companies under false identities. The mechanism is specific: they use stolen American identities, AI-generated professional profiles, and U.S.-based facilitators who receive company-issued laptops at residential "laptop farms," then allow the overseas workers to access them remotely. Once hired, the workers collect salaries that are funneled back to the North Korean regime's weapons programs.
In June 2025, the Justice Department announced coordinated enforcement actions across 16 states: searches of 29 suspected laptop farms, seizure of 29 financial accounts and 21 fraudulent websites, and multiple indictments. One scheme alone generated over $88 million across approximately six years. The U.S. State Department estimates the broader program generates up to $800 million annually for the regime.
Amazon reported blocking more than 1,800 suspected North Korean job applications since April 2024, with the volume growing roughly 27% per quarter.
CrowdStrike's 2025 Threat Hunting Report identified the North Korean adversary group FAMOUS CHOLLIMA as responsible for 304 incidents in 2024. Forty percent of those were insider threat operations, carried out by workers who had successfully obtained legitimate employment.
The legal exposure for organizations that unknowingly hire these workers is serious. The FBI documented in a January 2025 advisory that after being discovered, these workers have extorted companies by threatening to release stolen code and proprietary data unless a ransom is paid. Beyond that, paying salary to someone operating on behalf of a North Korean designated entity is a potential OFAC sanctions violation, and the government has been clear that being deceived is not an automatic defense. For organizations with government contracts or export-controlled technology, the exposure includes potential ITAR violations as well.
What All of This Has in Common
Bot flooding, AI resume fraud, deepfake impersonation, and nation-state infiltration are different problems with different threat actors and different levels of severity. But they share a root cause: hiring processes that were built for a different era.
The verification steps most organizations rely on, resumes, video interviews, and automated background checks, are the exact layers these schemes are designed to defeat. That is not an accident. The fraud has evolved specifically to pass the screens that were put in place.
Fortune 500 companies with sophisticated HR teams are in the documented victim lists alongside smaller organizations. Weak processes are a risk factor, but they are not the only one. Well-resourced, well-designed processes are also being beaten, because they were not designed with this threat in mind.
How Practical AI Advisor Can Help
Closing these gaps starts with understanding where they are in your specific workflow.
At Practical AI Advisor, we work with HR and talent acquisition leaders to map out how candidates move through their hiring process and identify where the exposure to fraud actually exists. That means looking at both the technology layer and the human review layer, and making practical recommendations that reduce risk without creating unnecessary friction for legitimate candidates.
If candidate fraud is something your organization has not formally assessed, it is worth a conversation. Reach out at mracine@practicalaiadvisor.com.
Comments