In February 2026, Jason Rebholz — co-founder and CEO of the security company Evoke Security, a former incident responder and CISO who has spent years researching deepfakes — nearly hired one. A contact messaged him on LinkedIn recommending a candidate for an open security researcher role. The candidate looked professional on camera, answered technical questions competently, and made it through multiple interview rounds. Rebholz did notice red flags along the way: the candidate tended to repeat questions back before answering, and some answers were near word-for-word echoes of things Rebholz himself had written or said publicly. He didn't act on them. What finally broke the illusion was mundane — the hiring team asked the candidate to turn his head to the side, and the AI-generated face glitched (The Register; ITBrew).
That story circulated widely in HR-tech and security circles for a reason: if a deepfake nearly got past a CISO who studies deepfakes for a living, it will get past almost anyone whose day job is filling requisitions, not detecting synthetic media. And the Evoke Security case is not an isolated curiosity — it's a data point in a trend that has hiring teams, security researchers and regulators converging on the same conclusion at the same time: candidate identity is now a live attack surface, and most hiring processes were never built to defend it.
This piece separates what's actually documented from what's vendor-marketed hype, and lays out where we think the industry's response is currently mis-aimed.
The state-actor end of the problem: North Korea's fake IT workers
The most thoroughly documented version of this fraud isn't a lone opportunist — it's a state-run operation. Okta's threat intelligence team has tracked more than 130 distinct identities operated by facilitators and workers tied to a North Korean IT-worker scheme, linking them to more than 6,500 job interviews across more than 5,000 companies going back to 2021 (Okta Threat Intelligence). Okta is explicit that the 130 tracked identities are a sample, not a census, of total activity. The scheme has also broadened past its original target: nearly half of the companies it hits now sit outside the IT sector entirely, in finance, healthcare, public administration and professional services (The Register; The Record / Recorded Future News). In July 2026 the U.S. State Department issued a formal alert to companies and governments about the scheme's continued operation (U.S. Department of State).
The mechanics are almost boringly procedural once you see them written down: a stolen or fabricated identity, a facilitator running the laptop physically inside (or near) the target country, and a worker overseas doing the actual job once hired — sometimes with real technical skill, which is what makes the scheme sustainable rather than a one-time con. What's changed in 2026 isn't the scheme's existence — security researchers have tracked it since well before this year — it's that generative AI now touches every stage of it, from synthetic résumés and LinkedIn histories to real-time face-swap during the interview itself, rather than AI being a bolt-on to an otherwise manual fraud.
The volume end of the problem: a spectrum, not one thing
State-sponsored infiltration is the extreme case. Underneath it is a much larger, murkier layer that analyst firm Gartner has usefully framed as a spectrum rather than a single behavior, in a 2025 study on candidate fraud (cited consistently across multiple industry summaries of the Gartner report, including StaffingHub and gomokka.com):
- Cosmetic enhancement — AI-polished language that makes an ordinary candidate's resume or written answers sound stronger than the underlying substance. Nothing is fabricated, but the signal recruiters are trying to read is degraded.
- Capability inflation — claiming proficiency the candidate doesn't have, with an AI tool generating a plausible-sounding technical narrative to back the claim up in the moment.
- Identity fraud — a different person entirely sitting the interview, sometimes via deepfake video, sometimes via real-time AI prompting feeding answers to someone who cannot otherwise do the job.
Gartner's own projection, based on that study, is that one in four candidate profiles worldwide could be fake in some form by 2028 — a figure now widely cited across recruiting and staffing publications, though it's worth being precise that it spans the whole spectrum above, not identity fraud alone. Collapsing "AI helped me phrase my cover letter" and "someone else is answering for me" into one number is exactly the kind of blur that leads to bad screening design: a company that reacts to the headline figure by treating every AI-assisted sentence as fraud will burn recruiter time on the wrong end of the spectrum while state-actor infiltration continues undetected at the other end.
The most granular real-world dataset we found comes from Fabric, a vendor that sells AI-interview screening and therefore has a direct commercial interest in a large "cheating" number — a caveat worth stating plainly, and one that also cuts the other way: it's also the closest thing to actual measured interview data at scale, rather than a survey of hiring managers' impressions. Across an initial sample of over 50,000 candidates, Fabric's detected cheating rate more than doubled in six months, from 15% in June 2025 to 35% in December 2025. A more granular pass, across 19,368 first-round interviews, flagged 38.5% of candidates for AI-assisted cheating behavior — and, in the detail that actually matters for hiring outcomes, more than 61% of those flagged candidates still cleared the platform's own pass bar. Technical roles were flagged at roughly four times the rate of sales roles (48% versus 12%), and junior candidates were flagged at nearly double the rate of experienced hires (SocialTalent's analysis of the Fabric data; Fabric's own published dataset). Read plainly, that last point is uncomfortable for the industry that produced it: a majority of the candidates a cheating-detection tool itself flagged would have advanced anyway without a human catching it.
Why the industry's default response is aimed at the wrong layer
The reflexive fix being sold right now is a single new checkpoint: a deepfake-detection or "liveness" module bolted onto whichever stage already involves video. That's a reasonable component, but treating it as the fix misreads the Gartner spectrum above. A liveness check addresses identity fraud. It does nothing for capability inflation, and it does nothing for cosmetic enhancement — which, per Fabric's own numbers, is the layer producing most of the flagged volume, not the rare deepfake. A hiring process that adds one detection tool at one stage and calls the problem solved has patched the most dramatic failure mode and left the more common ones untouched.
Our reading, stated as our own view rather than as settled industry consensus: the more durable response is architectural, not tooling. A hiring flow where a candidate must clear several independent, differently-vulnerable checkpoints — a resume/qualification screen, a separate AI screening conversation, and a separate live human interview, each producing its own record before the next stage even begins — is structurally harder for any single fraud technique to walk through end to end than a process where one AI-mediated interaction is the whole gate. This is exactly the shape NiceHire's own hiring pipeline is built in: applicants advance through resume vetting, an AI screening interview and live interviews as distinct, sequential stages, each requiring the previous one to complete before the next stage record is even created, rather than a single pass/fail AI interaction deciding the outcome. We're not claiming this pipeline detects deepfakes or AI-assisted cheating — it doesn't have a fraud-detection feature, and we're not going to pretend it does. The claim is narrower and, we think, more honest: spreading the decision across independently-vulnerable stages reduces how much a single successful fraud attempt at any one stage actually buys the fraudster, because a deepfake that clears one interview still has to clear whatever comes next.
That has a direct implication for where organizations should actually spend their limited screening budget: not "which single AI tool stops fraud," but "which stage in our specific pipeline is the one weakest link a fraud attempt could ride all the way to an offer." For a process with only one screening interaction and no subsequent human check, that single interaction is the entire perimeter, and a bolt-on detector on it is the entire defense. For a process with multiple sequential, differently-mediated stages, the same detector is one layer among several rather than the whole wall.
What this doesn't change, and what teams should actually do this quarter
Detection tooling still matters, and we're not arguing against it — a liveness or consistency check at the video-interview stage is a legitimate layer, not a distraction, provided it's understood as one layer rather than the fix. Beyond that, three things follow directly from the data above rather than from generic advice:
- Separate the two problems in your own metrics. If you track "AI-flagged interviews," break it down by the Gartner spectrum — cosmetic, capability, identity — rather than one aggregate cheating rate. Fabric's own data shows those three categories behave completely differently by role seniority and function; a single number hides that.
- Don't let a passed screening stage substitute for a later human check, especially for remote, IT-adjacent and finance roles, which is precisely where the North Korean IT-worker scheme has concentrated. Okta's own data shows this problem has already moved well outside the technology sector; "we don't hire remote developers" is no longer a reason to consider yourself out of scope.
- Verify identity as its own step, separate from evaluating skill. The Evoke Security case is instructive precisely because the interview itself went fine on substance — the fraud was caught by an identity check (turn your head), not a competence check. A hiring process that only ever tests "can this person do the job" has no mechanism to catch "is this the person they claim to be," and those are different questions with different fixes.
None of this is solved by a single feature, ours or anyone else's. It's solved by treating verification as a distinct design problem from evaluation, and by recognizing that a hiring pipeline's resistance to fraud is a property of its shape — how many independent stages a candidate has to clear, and how different those stages are from each other — as much as it is a property of any one tool inside it.
Sources consulted directly for this piece: Okta Threat Intelligence, The Register, The Record (Recorded Future News), the U.S. Department of State, ITBrew, SocialTalent's analysis of Fabric's published interview dataset, Fabric's own blog, and secondary summaries of Gartner's 2025 candidate-fraud study (StaffingHub, gomokka.com). Figures attributed to Gartner and Fabric are those organizations' own reported findings, cited here rather than independently re-derived.
Ready to transform your hiring?
See how NiceHire's AI-powered hiring platform works for your team.
Get Started