Remote hiring quietly removed every moment where identity used to confirm itself — the lobby, the handshake, the badge photo. Into that gap moved an ecosystem of candidate fraud: real-time face swaps on video interviews, professional proxy interviewees, and covert-worker operations that place salaried employees inside companies under assumed identities. The prize isn't the job; it's the paycheck routed abroad, the credentials, and the access.
How a deepfake interview actually works
Commodity face-swap tooling runs in real time over a webcam feed; voice conversion matches the persona; a skilled operator answers while the "candidate" performs. Alternatively the fraud is analog — the person on the call is simply not the person who shows up — and the deepfake only bridges rounds where continuity might be checked.
The covert-worker dimension
Security agencies have repeatedly warned about state-linked schemes — most prominently North Korean IT-worker operations — that use fabricated identities to obtain remote roles at Western companies, routing salaries to sanctioned programs while holding insider access. For the employer this converts a hiring mistake into a sanctions and security problem simultaneously.
The tells that still work
- Lighting and edge artifacts around the face under movement.
- Audio-video desync under fast speech.
- Refusal to perform simple liveness actions (turn, hand near face).
- Capability discontinuities between rounds or between interview and day one.
- Histories that fail triangulation across platforms.
The fix is continuity, not vibes
Interviewers shouldn't be forensic analysts. The durable control is procedural — verified identity at final round, at offer, and at day-one enrollment, tied to the same human each time, with liveness checks doing the technical lifting (see liveness detection and hiring fraud prevention). Announce it in the job post and fraudulent pipelines route elsewhere.