The candidate who doesn’t exist, and what imposter hiring fraud looks like from inside a software firm

The candidate who doesn’t exist, and what imposter hiring fraud looks like from inside a software firm

/ /

There is a category of security threat that doesn’t arrive through your firewall. It arrives through your careers page, passes two rounds of interviews, and gets handed credentials on day one.

Imposter candidates are not new. Engineering teams have dealt with proxy interviewees and padded CVs for years. What has changed is the scale and the quality, and the recent reporting bears this out. Gartner now predicts that by 2028, one in four candidate profiles worldwide will be fake. Researchers at Palo Alto Networks demonstrated that a convincing deepfake job applicant, with a synthetic face capable of holding a live video interview, can be assembled in about 70 minutes by someone with no prior image manipulation experience. This capability is no longer niche, and it is no longer expensive.

From padded CVs to state-sponsored employees

The most organised version of this threat is well documented. Microsoft’s threat intelligence team has tracked North Korean remote IT workers who secured jobs at more than 300 US companies, including Fortune 500 firms, using stolen identities, AI-enhanced profile photos, and laptop farms run by facilitators who keep company-issued hardware on home soil while the actual worker logs in from abroad. The US Department of Justice has brought indictments and seized the websites used to launder the proceeds.

It would be a mistake to file this under somebody else’s problem. The same playbook, minus the sanctions angle, is used by ordinary fraudsters who want a salary they cannot earn, contractors quietly outsourcing their role to a third party, and candidates who simply are not the person who sat the technical interview. Those are the cases most companies encounter, and we encounter them regularly.

AI has moved the problem from the CV to the interview itself

For a long time, the live video interview was the backstop. A CV can be fabricated, but a face-to-face conversation, even over a webcam, was assumed to be hard to fake, but that assumption no longer holds.

We now see live AI avatars sitting interviews in real time. The person on screen is a rendered face, lip-synced over someone else’s voice, sometimes over someone else’s answers entirely. Alongside the avatars there is real-time coaching, where a candidate reads AI-generated answers from a second screen a beat after each question lands, and voice-changing software that lets one skilled interviewee sit assessments for many identities. Industry analysis suggests around 6% of candidates already admit to some form of interview fraud, and that figure only counts the ones willing to say so.

For a software engineering business this lands somewhere specific. Engineering roles are the primary target, because they come with the most valuable thing an attacker can obtain, which is legitimate, credentialed access. A fraudulent hire will always end up inside the repository, the CI pipeline, and the customer data with permissions you gave them.

AI in Software Engineering report cover

AI in Software Engineering

Making sense of the noise.

How 100+ engineering and technology leaders are turning AI investment into measurable delivery, and where it still falls short.

PDF · 4.2 MB · Free, no commitment required

What handling it daily has taught us

We deal with this in our own hiring pipeline as a matter of routine, and we have had to change how we work as a result. A few things have proven their worth.

The first is treating identity verification as a security control rather than an HR formality. Government ID checked against the person on camera, across more than one session, before any offer is made. The old tricks for catching deepfakes, such as asking someone to turn their head or pass a hand in front of their face, are already becoming unreliable as the tooling improves, so we would not advise depending on them, though they can catch unsophisticated attempts at infiltrating your business. We use multiple third-party identity verification services and perform deep reference checks, ideally going back to the earlier points in their career.

The second is interviewing for lived experience rather than rehearsed knowledge. Scripted candidates and coached candidates handle prepared ground well. They handle specifics poorly. Asking what went wrong on a project, which trade-off they regret, or why they chose one approach over another at a particular employer produces a very different texture of answer from someone who was actually there. Unpredictable, conversational follow-ups remain one of the cheapest and most effective filters available.

The third is refusing to let the process be fully remote. An in-person checkpoint at some stage, whether an office visit, a meeting at a co-working space, or equipment collection with ID in hand, removes an entire class of imposter at a stroke. Where geography makes that impractical, it may be worth weighing whether the role should be filled that way at all.

The fourth is accepting that some imposters will get through anyway, and designing onboarding accordingly. New starters get least-privilege access that expands with tenure. We watch for the technical tells that follow a fraudulent hire, such as remote-management tools like AnyDesk or TeamViewer appearing on a company laptop, logins from unexpected locations, and mismatches between claimed working hours and actual activity. The first 90 days are treated as a verification period in practice.

The uncomfortable truth

Ultimately, none of this is free and verification adds friction for honest candidates, who are still the overwhelming majority, and every additional hoop costs you some of the good candidates. The judgement that has to be made is where to place that friction so it discriminates against fraud rather than against talent. In our experience the answer is to concentrate it early, around identity, and keep the rest of the process human.

The hiring pipeline is now an attack surface, and it deserves the same engineering attention as any other one. Companies that treat interviews purely as a talent question, with security bolted on after the start date, are solving last decade’s version of the problem.

Thinking of hiring more engineers?

30-minute intro call. No commitment or cost.

  • We were impressed by how proactive their team was at all levels with high velocity, easy reviews and an ability to avoid issues before they happened.

    Engineering Leadership

    Peppermint Technology

  • I can safely say it’s been the best working environment I’ve ever experienced! Everyone is really friendly and supportive, there really is a great team spirit.

    Project Manager

    Freelancer

  • HI’s engagement model is tangibly different. We were impressed by how proactive their team was at all levels with high velocity, easy reviews and an ability to avoid issues before they happened. The ethos, expertise and commitment of the HI team meant this really felt like a relationship, not just a supplier arrangement.

    Engineering Leadership

    Peppermint Technology

  • The team at HI enabled Lightfoot to rapidly scale development with minimal support from internal dev resources.

    Calum Roke

    CTO at Lightfoot

  • HI’s engagement model is tangibly different. The ethos, expertise and commitment of the HI team meant this really felt like a relationship, not just a supplier arrangement.

    Engineering Leadership

    Peppermint Technology

  • HI led well-controlled stakeholder engagement to capture product requirements, applying extensive technical experience to shape the solutions, whilst maintaining consideration of other business criteria.

    Calum Roke

    CTO at Lightfoot

  • The team at HI enabled Lightfoot to rapidly scale development with minimal support from internal dev resources. They led well-controlled stakeholder engagement to capture product requirements, applying extensive technical experience to shape the solutions, whilst maintaining consideration of other business criteria such as budget. Agile projects were then run by the HI project and development teams, with stakeholder reviews along the way. A secondary benefit was working with them to improve internal development and DevOps workflows.

    Calum Roke

    CTO at Lightfoot

  • Agile projects were run by the HI project and development teams, with stakeholder reviews along the way. A secondary benefit was working with them to improve internal development and DevOps workflows.

    Calum Roke

    CTO at Lightfoot

We’d love to learn more about your business and explore how we can help. Book a meeting with us, and let’s talk through your ideas.