Hiring Deepfakes?A company interviews a candidate for a remote position. The resume is strong. The person appears on camera, answers technical questions competently and has documentation supporting the identity on the application. The company completes its hiring process, ships a computer to a U.S. address and provides the new employee with access to corporate systems.

Everything about the process looks like hiring.

That is precisely what makes a growing form of employment fraud so difficult to recognize.

The FBI has warned U.S. businesses about overseas information technology workers using stolen or fabricated identities to obtain legitimate remote employment. In some cases, the agency says, North Korean IT workers have used artificial intelligence and face-swapping technology during video interviews to conceal their identities. Other parts of these operations have included false websites, pseudonymous accounts, stolen identities, proxy computers and people physically located in the United States who help make overseas workers appear to be working domestically.

These are not hypothetical demonstrations of what generative AI might someday make possible.

In April 2026, the U.S. Department of Justice announced prison sentences for two U.S. nationals who helped facilitate a scheme in which North Korean IT workers posed as U.S. residents and obtained employment at more than 100 American companies. According to the Justice Department, the multi-year operation used the stolen identities of at least 80 Americans and generated more than $5 million in illicit revenue for North Korea. The facilitators operated what investigators called “laptop farms,” helping create the appearance that the workers were physically located in the United States.

For business leaders, the important lesson isn't that every remote candidate should suddenly be treated with suspicion. Nor is it that companies need software capable of identifying every deepfake.

The more important issue is that many companies designed their hiring procedures when seeing someone's face, checking identification and shipping a laptop to a domestic address seemed like independent forms of verification.

Technology has weakened all three assumptions.

THE PROBLEM IS LARGER THAN DEEPFAKE VIDEO

The term “deepfake interview” attracts attention because the technology is easy to visualize. Someone alters a face or voice during a video call and attempts to convince an interviewer that he or she is someone else.

But focusing too heavily on the video risks misunderstanding the attack.

The FBI's descriptions of remote-worker schemes show that successful operations can involve several pieces working together: stolen or falsified identities, fabricated employment histories, online accounts, U.S.-based addresses, remote-access software and third parties who assist with equipment or verification. The agency has warned that some overseas workers have reused phone numbers and email addresses across applications and changed addresses or payment information during onboarding.

In other words, the attacker does not necessarily need to create one perfect fake.

He needs to create a collection of facts that appear consistent enough to survive the company's hiring process.

That distinction matters because it changes the defensive question. Trying to train an HR manager to become an expert in detecting artificial faces is unlikely to provide much assurance as the technology improves. A process that requires several meaningful facts to agree with one another is considerably harder to defeat.

Identity, employment history, location, payment information and the person appearing in the interview should tell a consistent story.

When they don't, somebody should investigate before corporate access is granted.

HIRING IS NOW PART OF THE CYBERSECURITY PERIMETER

Most companies do not think of the recruiting department as part of their cybersecurity infrastructure.

They may need to.

A successful phishing attack attempts to persuade an employee to give an outsider access. Fraudulent remote employment can accomplish something more direct: persuade the company to give the outsider access intentionally.

The distinction is significant.

Once hired, a fraudulent employee may receive a company-managed computer, an email account, VPN or cloud access, collaboration tools and whatever permissions are considered appropriate for the position. The individual may be introduced to coworkers and vendors. Activity originating from that account initially looks less like an intrusion because, from the company's perspective, the person is an authorized user.

The FBI has warned that North Korean remote IT workers have used their access to exfiltrate proprietary and sensitive information and, in some cases, extort companies. The Bureau has also warned businesses about unauthorized remote-access software appearing on company-issued devices.

That turns a hiring decision into an access-control decision.

Manufacturers should pay particular attention to that distinction. A new employee or contractor may eventually receive access to ERP information, customer records, supplier information, engineering files, pricing, intellectual property or other systems that would never be made available to an unknown person on the Internet.

The fact that the person passed through Human Resources does not reduce the value of that information.

It merely changes the route by which access was obtained.

THE NUMBERS SUGGEST THIS WILL NOT REMAIN AN EDGE CASE

Employment fraud existed long before generative AI. Candidates have exaggerated qualifications, substituted interviewees and falsified credentials for years.

What has changed is the cost and sophistication required to create a convincing false presence.

Gartner reported in 2025 that 6% of 3,000 surveyed job candidates acknowledged participating in interview fraud, either by posing as someone else or having another person pose as them. The research firm predicts that by 2028, one in four candidate profiles worldwide could be fake.

That forecast should be interpreted carefully. It does not mean Gartner expects one-quarter of people sitting across from employers to be international cybercriminals. “Fake” can encompass different kinds of candidate and profile fraud.

But the direction is difficult to dismiss.

AI can help create resumes, professional photographs, websites, written work and online personas at very low cost. Voice cloning and face-swapping technology continue to improve. Remote interviews have eliminated the physical presence that once accompanied most professional hiring.

At the same time, businesses have spent years making remote onboarding more efficient.

Efficiency usually means removing friction.

Fraud prevention often requires putting some of the right friction back.

A VIDEO CALL IS NOT IDENTITY VERIFICATION

One of the more dangerous assumptions is that requiring cameras during interviews solves the problem.

It helps. It does not establish identity.

The FBI recommends that companies verify identity during interviewing and onboarding and continue appropriate verification throughout remote employment. Its guidance includes scrutinizing identity documents, cross-checking photographs and contact information, verifying previous employment and education directly, and watching for inconsistencies in addresses, phone numbers, email accounts and payment information. The Bureau has also recommended in-person meetings when practical for certain remote hiring situations.

That approach is more useful than relying on a checklist of supposed deepfake giveaways.

Advice such as watching for strange blinking, poor lip synchronization or unusual lighting may identify an unsophisticated fake today. It is difficult to build a durable security process around artifacts that technology companies are actively working to eliminate.

The stronger control is corroboration.

If a candidate claims previous employment, can it be independently verified through the organization rather than only through a telephone number supplied by the candidate? Does the person's stated location agree with other information collected during hiring? Does the address where equipment will be shipped make sense? Does payment information change unexpectedly after hiring? Does the same phone number or email address appear in connection with apparently unrelated applicants?

No single inconsistency proves fraud.

Several inconsistencies deserve attention.

THE COMPANY LAPTOP DESERVES SPECIAL ATTENTION

One of the most revealing elements in the federal cases is what happened to employer-issued computers.

The Justice Department has described operations in which laptops were shipped to addresses in the United States, creating the impression that the employee was working domestically. People operating laptop farms then enabled overseas workers to access those machines remotely.

Consider what that means from the employer's perspective.

The company may see a computer it purchased, configured and shipped to an American address. Security systems may identify connections originating from that computer. Nothing about the device itself necessarily announces that the person controlling it is somewhere else.

This is why device management and monitoring matter after the hiring process ends.

Companies should know what remote-access tools are permitted on corporate equipment and be capable of identifying unauthorized ones. Unusual remote connections, unexpected software installations and other deviations from the company's normal configuration deserve investigation. Access should also correspond to the employee's actual responsibilities rather than being granted broadly because the individual has cleared onboarding.

The principle of least privilege is hardly new. Employment fraud gives companies another reason to take it seriously.

A newly hired employee should not receive access to information simply because that access might become convenient someday.

THIS IS NOT ONLY AN HR PROBLEM

Candidate fraud sits awkwardly between departments.

HR owns recruiting. Hiring managers evaluate competence. IT prepares equipment and accounts. Finance may establish payroll. Security monitors access. Management determines how much risk the organization is willing to accept.

A sophisticated fraudulent worker can exploit the gaps between those responsibilities.

HR may verify one set of information while IT assumes identity has already been established. IT may notice an unusual remote-access application without knowing that the employee changed his shipping address shortly before the laptop was sent. Finance may see a change in payment information without knowing that the hiring manager noticed something unusual during a video interview.

Individually, none of those events may look important.

Together, they may tell a very different story.

Businesses therefore need an escalation path for discrepancies during remote hiring and onboarding. Someone needs enough visibility to connect information that would otherwise remain isolated inside separate departments.

That does not require treating every remote hire like a criminal investigation. It requires recognizing that identity verification is a process rather than a moment.

BE CAREFUL ABOUT SOLVING AN AI PROBLEM WITH MORE AI

The original response to deepfake hiring often includes biometric verification systems, facial-recognition software and automated deepfake detection.

Those technologies may have a role, particularly for organizations with large remote workforces and substantial exposure. But businesses should be cautious about assuming that another piece of software can settle the identity question for them.

Biometric systems introduce their own questions involving privacy, data retention, accuracy, employment law and the protection of biometric information. Deepfake-detection technology is also engaged in an ongoing contest with the systems creating synthetic media.

For many mid-sized businesses, stronger fundamentals may provide more immediate value: independently verifying credentials, controlling where equipment is shipped, limiting access for new employees, requiring multifactor authentication, managing company devices, monitoring unauthorized remote-access software and establishing a clear process when information doesn't add up.

Those controls remain useful even when the fake video becomes impossible for a human being to recognize.

That is a much better characteristic for a security control to have.

THE PERSON INSIDE THE NETWORK MAY HAVE BEEN INVITED IN

Cybersecurity has traditionally devoted enormous attention to keeping unauthorized people outside the network.

Firewalls, endpoint protection, email filtering and multifactor authentication all remain important. But none addresses the underlying problem when a company deliberately creates an account for the wrong person.

That is what makes fraudulent remote employment different from a conventional intrusion.

The attacker may not have to break in.

The company may interview him, approve him, send him a computer, create his credentials and welcome him aboard.

The FBI's warnings and recent federal prosecutions are useful because they force businesses to reconsider where cybersecurity begins. In an environment where identity can be manufactured more convincingly and remote access is an ordinary part of work, the hiring process can no longer be viewed solely as an administrative function.

For positions that will receive meaningful access to company systems or information, hiring is also the first access-control decision.

The objective is not to eliminate remote hiring or to make every candidate prove that he or she is not a deepfake. It is to build a process in which one convincing video call is not enough to establish trust.

Because once the account is created and the laptop is shipped, the question is no longer whether the candidate can get into the company.

The company has already let the candidate in.

Data-Link Associates is an IT managed services provider specializing in cybersecurity, IT support and ERP systems for manufacturers, distributors and wholesalers. Our office is located in Sugar Grove, Illinois, and we manage manufacturing IT nationwide. At your service since 1983. Contact Angela Jamerson at ajamerson@datalinkmsp.com or (630) 406-8969.